# Logstash output plugins and self signed certificates?

**URL:** <https://discuss.elastic.co/t/logstash-output-plugins-and-self-signed-certificates/192848>\
**Category:** Logstash\
**Created:** [July 30, 2019, 8:01am UTC](https://discuss.elastic.co/t/logstash-output-plugins-and-self-signed-certificates/192848 "2019-07-30T08:01:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [July 30, 2019, 8:02am UTC](https://discuss.elastic.co/t/logstash-output-plugins-and-self-signed-certificates/192848/1 "2019-07-30T08:02:00Z")

</div>

Hi,

I want to use the Redmine output plugin but I'm running into a small problem. Our Redmine uses a self signed certificate and when I enable `ssl => true` in the output I get the following error which i assume is because the cert is not accepted?

`WARN ][logstash.outputs.redmine] Skipping redmine output; error during request post {"error"=>#<OpenSSL::SSL::SSLError: handshake alert: unrecognized_name>, "missed_event"=>#<LogStash::Event:0x222ac>}`

The plugin itself doesn't have any options besides ssl true/false and the official docs don't have any mention of what to do in case of self signed certificates either.

Is allowing self signed certificates something you have to set up inside Logstash itself instead of the .conf? If so, where can I find how to do this? I couldn't find anything on the docs page.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2019, 12:58pm UTC](https://discuss.elastic.co/t/logstash-output-plugins-and-self-signed-certificates/192848/2 "2019-07-30T12:58:38Z")

</div>

The output [disables](https://github.com/logstash-plugins/logstash-output-redmine/blob/218231ddc6cf1c7171aba7ae6583cce936cda269/lib/logstash/outputs/redmine.rb#L108) certificate verification, so self-signed certificates should be OK. However, you might want to read through [this](https://stackoverflow.com/questions/7615645/ssl-handshake-alert-unrecognized-name-error-since-upgrade-to-java-1-7-0).

---

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [July 31, 2019, 6:03am UTC](https://discuss.elastic.co/t/logstash-output-plugins-and-self-signed-certificates/192848/3 "2019-07-31T06:03:26Z")

</div>

Thanks for the tip @Badger. Adding `-Djsse.enableSNIExtension=false` to `jvm.options` solved the problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2019, 6:03am UTC](https://discuss.elastic.co/t/logstash-output-plugins-and-self-signed-certificates/192848/4 "2019-08-28T06:03:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
