# Logstash Filebeat incorrect SSL key

**URL:** https://discuss.elastic.co/t/logstash-filebeat-incorrect-ssl-key/205849
**Category:** Logstash
**Created:** [October 30, 2019, 12:15pm UTC](https://discuss.elastic.co/t/logstash-filebeat-incorrect-ssl-key/205849 "2019-10-30T12:15:24Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Devopsio](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@Devopsio](https://discuss.elastic.co/u/Devopsio)
#### Post date: [October 30, 2019, 12:15pm UTC](https://discuss.elastic.co/t/logstash-filebeat-incorrect-ssl-key/205849/1 "2019-10-30T12:15:25Z")

</div>

Hi. I can't establish an SSL connection between Logstash (containerized) and Filebeat. I'm using a self-signed certificate.

# Actions I performed:

openssl req -newkey rsa:4096 -nodes -keyout logstash.key -subj "/CN=(hostname IP)" -out logstash.csr;

openssl x509 -req -extfile \<(printf "subjectAltName=IP:(hostname IP)"\> -sha256 -days 3650 -in logstash.csr -signkey logstash.key -out logstash.crt

openssl pkcs8 -in logstash.key -topk8 -nocrypt -out logstash.pkcs8.key and mounted it in Logstash' continer

Then I specified logstash.crt as a certificate\_authorities in Filebeat conf file.

And it turns out, that Filebeat can't connect to Logstash. I know I should use elastic' util for certification generation but I don't see how can I specify SAN option there. From Logstash' logs: file does not contain valid private key: /logstash.key. My question is what wrong with the key?

---

<div class="post-metadata">

### Author: ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)
#### Post date: [October 31, 2019, 11:49am UTC](https://discuss.elastic.co/t/logstash-filebeat-incorrect-ssl-key/205849/2 "2019-10-31T11:49:16Z")

</div>

Hi @Devopsio,

this [blog post](https://gist.github.com/andrewkroh/fdc7e5f3f0f0ed63a11c) helped me out when I was setting up SSL between Filebeat and Logstash

The Filebeat output config and Logstash input config would help a lot to be able to give you more specific advise 😉

---

<div class="post-metadata">

### Author: ![Devopsio](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@Devopsio](https://discuss.elastic.co/u/Devopsio)
#### Post date: [October 31, 2019, 3:56pm UTC](https://discuss.elastic.co/t/logstash-filebeat-incorrect-ssl-key/205849/3 "2019-10-31T15:56:30Z")

</div>

The problem is that I've used elastic' certutil to create CA and a certificate. And according to elastic's guide, it's the way to generate ca, crt and key files. Also, to create a pkcs8 key. And I can't find how to add SAN to the certificate with the certutil. Without IP SAN my certs don't work. What I can do?

---

<div class="post-metadata">

### Author: ![Devopsio](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@Devopsio](https://discuss.elastic.co/u/Devopsio)
#### Post date: [November 1, 2019, 8:33am UTC](https://discuss.elastic.co/t/logstash-filebeat-incorrect-ssl-key/205849/4 "2019-11-01T08:33:51Z")

</div>

So, I managed to solve my issue by using IP instead of DNS in instances.yml file when generating ca, crt and key files with elasticsearch-certutil. Also, being in container, Logstash doesn't automatically rereads pipeline file if you change it.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 29, 2019, 8:33am UTC](https://discuss.elastic.co/t/logstash-filebeat-incorrect-ssl-key/205849/5 "2019-11-29T08:33:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
