# Logstash Elasticsearch input plugin mTLS

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin-mtls/275098>\
**Category:** Logstash\
**Created:** [June 7, 2021, 5:22am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin-mtls/275098 "2021-06-07T05:22:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Armen\_Petrosyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/armen_petrosyan/32/80330_2.png) [@Armen\_Petrosyan](https://discuss.elastic.co/u/Armen_Petrosyan)\
**Post date:** [June 7, 2021, 5:22am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin-mtls/275098/1 "2021-06-07T05:22:04Z")

</div>

I have question related to mutual TLS authentication in case of using logstash Elasticsearch input plugin. I have Elasticsearch cluster installed and configured to work over tls using mutual authentication.

Now I want to read from this cluster and send it to the output. Let's skip output plugin part for now.

Below applied logstash configuration

```auto
input {
    elasticsearch {
        hosts => ["host:port"]
        ssl => true
        user => "myUser"
        password => "myPassword"
        ca_file => "path/to/my/certificate/authority/cert.pem"
        index => "index_name"
    }
}

```

As far as I understand **ca\_file** used in order to validate certificate that comes from Elasticsearch (server side) as part of TLS handshake.

My questions are:

1. **One way TLS.** ssl flag is enabled, ca\_file is populated, but is there any configuration based on which I could state that I don't need to verify hostname I am working with?
2. **Mutual TLS case.** How I can provide client certificate or keystore to the logstash. So this certificate can be used by elasticsearch cluster (server) in order to authenticate the logstash (client). Is there such an option? Does logstash Elasticsearch input plugin really supports that?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 7, 2021, 4:48pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin-mtls/275098/2 "2021-06-07T16:48:42Z")

</div>

> [@Armen\_Petrosyan](#):
>
> is there any configuration based on which I could state that I don't need to verify hostname I am working with?

No, the elasticsearch input and filter do not support disabling name-match verification. The elasticsearch output does, but it is a terrible, terrible idea to do so.

As far as I know, the elasticsearch input does not support client certificates.

---

<div class="post-metadata">

**Author:** ![Armen\_Petrosyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/armen_petrosyan/32/80330_2.png) [@Armen\_Petrosyan](https://discuss.elastic.co/u/Armen_Petrosyan)\
**Post date:** [June 8, 2021, 6:14am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin-mtls/275098/3 "2021-06-08T06:14:14Z")

</div>

> As far as I know, the elasticsearch input does not support client certificates.

It does not ☹ which is problematic if cluster requires client authentication.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2021, 6:15am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin-mtls/275098/4 "2021-07-06T06:15:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
