# Logstash TCP/SSL | General OpenSslEngine problem

**URL:** <https://discuss.elastic.co/t/logstash-tcp-ssl-general-opensslengine-problem/158044>\
**Category:** Logstash\
**Created:** [November 23, 2018, 7:21pm UTC](https://discuss.elastic.co/t/logstash-tcp-ssl-general-opensslengine-problem/158044 "2018-11-23T19:21:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![x4cker](https://avatars.discourse-cdn.com/v4/letter/x/f08c70/32.png) [@x4cker](https://discuss.elastic.co/u/x4cker)\
**Post date:** [November 23, 2018, 7:21pm UTC](https://discuss.elastic.co/t/logstash-tcp-ssl-general-opensslengine-problem/158044/1 "2018-11-23T19:21:58Z")

</div>

Hi,  
I'm forwarding logs from logstash to logstash using tcp output/input plugins over SSL.  
on the client side i use this config in the output:

```
tcp{
			host => "logstash01.domain.tld"
			port => 8443
			codec => json_lines			
			ssl_enable => true
			ssl_cacert => "/etc/logstash/certs/ca.cer"
			ssl_cert => "/etc/logstash/certs/client.cer"
			ssl_key => "/etc/logstash/certs/client.key"
		}

```

and this on the server input:

```
tcp {
		port => "8443"
		codec => json_lines
		ssl_enable => true
		ssl_extra_chain_certs => ["/etc/logstash/certs/ca.cer"]
		ssl_cert => "/etc/logstash/certs/logstash01.cer"
		ssl_key => "/etc/logstash/certs/logstash01.key"
	}

```

the problem is that i'm getting this exception on the client:  
`

> SSL Error {:exception=\>#\<OpenSSL::SSL::SSLError: Received fatal alert: internal\_error\>, :backtrace=\>["org/jruby/ext/openssl/SSLSocket.java:266:in `connect'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-output-tcp-5.0.3/lib/logstash/outputs/tcp.rb:179:in `block in connect'", ...... trimmed

and this on the server:

> `[ERROR][logstash.inputs.tcp] Error in Netty pipeline: io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: General OpenSslEngine problem`

The goal is to achieve mutual authentication. anyone can help?  
thank you

PS: the certificates are self-signed

---

<div class="post-metadata">

**Author:** ![LCF](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lcf/32/38717_2.png) [@LCF](https://discuss.elastic.co/u/LCF)\
**Post date:** [December 12, 2018, 5:44am UTC](https://discuss.elastic.co/t/logstash-tcp-ssl-general-opensslengine-problem/158044/2 "2018-12-12T05:44:13Z")

</div>

I think you should replace `ssl_extra_chain_certs` with `ssl_certificate_authorities`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2019, 5:44am UTC](https://discuss.elastic.co/t/logstash-tcp-ssl-general-opensslengine-problem/158044/3 "2019-01-09T05:44:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
