# Logstash RSS Input Plugin SSL Support

**URL:** <https://discuss.elastic.co/t/logstash-rss-input-plugin-ssl-support/301624>\
**Category:** Logstash\
**Created:** [April 5, 2022, 11:24am UTC](https://discuss.elastic.co/t/logstash-rss-input-plugin-ssl-support/301624 "2022-04-05T11:24:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![butchkelley](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Post date:** [April 5, 2022, 11:24am UTC](https://discuss.elastic.co/t/logstash-rss-input-plugin-ssl-support/301624/1 "2022-04-05T11:24:54Z")

</div>

Hello,

Does the Logstash RSS Input plugin have the ability to use a specific CA certificate to validate an SSL enabled website? There are no "ca\_cert" settings in the docs that I can find.

The specific error I'm getting is:

```auto
[date][INFO][logstash.inputs.rss] Polling RSS {:url=>"https://somesite.com/rss/bla.rss"}
[date][ERROR][logstash.javapipeline] A plugin had an unrecoverable error. Will restart this plugin.
   Pipeline_id:some_rss
   Plugin: <_lots of stuff that doesn't appear to be of much use in troubleshooting this issue_>
   Error: certificate verify failed
   Exception: Faraday::SSLError
.... <_java stack dump_>....

```

The github case below implies that there are CA certs imbedded in Logstash (or the plugin itself) but we're using our own CA.

> <https://github.com/logstash-plugins/logstash-input-rss/issues/32>
>
> logstash-input-rss cant fetch various RSS feeds due to Error: certificate verify… failed
> Checked forum for how-to disable, skip or ignore SSL certificate check. 
> Error for NIST feeds, Debian Security feeds. Looks like Feeds provided by websites running Let's Encrypt.
> Looks like Ruby or JRuby does SSL different than openssl which might cause this issue?
> 
> \- Version: 
> logstash 7.15.0
> 
> \- Operating System: 
> Debian 11 Bullseye
> 
> \- Config File:
> Simple input Filter for NIST NVD feed:
> 
> \`\`\`
> input {
> rss {
> url =\> "https://nvd.nist.gov/feeds/xml/cve/misc/nvd-rss.xml"
> interval =\> 3600
> id =\> "rss-nist-nvd"
> tags =\> \["cert", "usa", "nist"\]
> }
> }
> \`\`\`
> 
> \- Sample Data:
> Started with: /usr/share/logstash/bin/logstash --path.settings /etc/logstash --log.level debug
> 
> \`\`\`
> \[2021-10-04T17:31:51,902\]\[ERROR\]\[logstash.javapipeline \]\[main\]\[rss-nist-nvd\] A plugin had an unrecoverable error. Will restart this plugin.
> Pipeline\_id:main
> Plugin: \<LogStash::Inputs::Rss interval=\>3600, id=\>"rss-nist-nvd", url=\>"https://nvd.nist.gov/feeds/xml/cve/misc/nvd-rss.xml", tags=\>\["cert", "usa", "nist"\], enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_059720a1-f3c2-42f3-90ea-d04827ee3035", enable\_metric=\>true, charset=\>"UTF-8"\>\>
> Error: certificate verify failed
> Exception: Faraday::SSLError
> \`\`\`
> 
> 
> \- Steps to Reproduce:
> Create input filter with above RSS feed URL.

Thanks for your help,  
Butch

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 5, 2022, 5:36pm UTC](https://discuss.elastic.co/t/logstash-rss-input-plugin-ssl-support/301624/2 "2022-04-05T17:36:24Z")

</div>

> [@butchkelley](#):
>
> Does the Logstash RSS Input plugin have the ability to use a specific CA certificate to validate an SSL enabled website?

Not that I know of. The plugin uses Faraday, and I think that uses [jruby-openssl](https://github.com/elastic/logstash/pull/13355), and that uses Bouncy Castle.

You need to get your CA cert into the Trusted Root Certificate Authorities store. I cannot tell you how to do that.

---

<div class="post-metadata">

**Author:** ![butchkelley](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Post date:** [April 5, 2022, 5:52pm UTC](https://discuss.elastic.co/t/logstash-rss-input-plugin-ssl-support/301624/3 "2022-04-05T17:52:59Z")

</div>

Thanks Badger,

Unfortunately adding my CA cert to the Trusted Root Certificate Authorities store is not an option as I'm on an isolated network.

Butch

---

<div class="post-metadata">

**Author:** ![butchkelley](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Post date:** [April 5, 2022, 6:17pm UTC](https://discuss.elastic.co/t/logstash-rss-input-plugin-ssl-support/301624/4 "2022-04-05T18:17:34Z")

</div>

I was able to find a solution. Jruby will use the following environment variable:

```auto
SSL_CERT_FILE=/path/to/some_CA_cert.pem

```

Thanks,  
Butch

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2022, 6:18pm UTC](https://discuss.elastic.co/t/logstash-rss-input-plugin-ssl-support/301624/5 "2022-05-03T18:18:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
