# Logstash TLS/SSL fails to connect to Elasticsearch with CN=instance does not match the certificate subject provided

**URL:** <https://discuss.elastic.co/t/logstash-tls-ssl-fails-to-connect-to-elasticsearch-with-cn-instance-does-not-match-the-certificate-subject-provided/211181>\
**Category:** Logstash\
**Created:** [December 9, 2019, 7:37pm UTC](https://discuss.elastic.co/t/logstash-tls-ssl-fails-to-connect-to-elasticsearch-with-cn-instance-does-not-match-the-certificate-subject-provided/211181 "2019-12-09T19:37:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bharath\_venkat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bharath_venkat/32/48504_2.png) [@Bharath\_venkat](https://discuss.elastic.co/u/Bharath_venkat)\
**Post date:** [December 9, 2019, 7:37pm UTC](https://discuss.elastic.co/t/logstash-tls-ssl-fails-to-connect-to-elasticsearch-with-cn-instance-does-not-match-the-certificate-subject-provided/211181/1 "2019-12-09T19:37:09Z")

</div>

Hi

Trying to enable logstash TLS/SSL communication on kubernetes. Logstash fails to communicate with Elasticsearch . ried several ways to fix the CN instance issue . below are my methods

Method 1

Created cert bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12 --dns sample-elasticsearch-0  
sample-elasticsearch-0 is the hostname of the elasticsearch

> Blockquote  
> [2019-12-09T18:59:26,079][WARN][logstash.licensechecker.licensereader] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[https://filebeat:xxxxxx@sample-elasticsearch-0.elasticsearch.svc.cluster.local:9200/](https://filebeat:xxxxxx@sample-elasticsearch-0.elasticsearch.svc.cluster.local:9200/)", :error\_type=\>LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[https://filebeat:xxxxxx@sample-elasticsearch-0.elasticsearch.svc.cluster.local:9200/](https://filebeat:xxxxxx@sample-elasticsearch-0.elasticsearch.svc.cluster.local:9200/)][Manticore::ResolutionFailure] sample-elasticsearch-0.elasticsearch.svc.cluster.local"}

when i do curl on the pod

> sh-4.2# curl -k -u filebeat:123456 [https://sample-elasticsearch-0.elasticsearch.svc.cluster.local:9200](https://sample-elasticsearch-0.elasticsearch.svc.cluster.local:9200) curl: (6) Could not resolve host: sample-elasticsearch-0.elasticsearch.svc.cluster.local; Unknown error

Method 2

I have a service sample-elasticsearch-svc which is attached to sample-elasticsearch-0 pod . When i Curl from the pod i get response as below . After changing logstash config host to sample-elasticsearch-svc the logstash pods fails with CN instance issue because the elastic hostname is sample-elasticsearch-0 but here i am pointing to the k8 service

> Blockquote sh-4.2# curl -k -u filebeat:123456 [https://sample-elasticsearch-svc.elasticsearch.svc.cluster.local:9200](https://sample-elasticsearch-svc.elasticsearch.svc.cluster.local:9200)  
> {  
> "name" : "sample-elasticsearch-0",  
> "cluster\_name" : "sample-elasticsearch-cluster",  
> "cluster\_uuid" : "UrTJQee6QoSD2TEPketiMw",  
> "version" : {  
> "number" : "7.4.1",  
> "build\_flavor" : "default",  
> "build\_type" : "docker",  
> "build\_hash" : "fc0eeb6e2c25915d63d871d344e3d0b45ea0ea1e",  
> "build\_date" : "2019-10-22T17:16:35.176724Z",  
> "build\_snapshot" : false,  
> "lucene\_version" : "8.2.0",  
> "minimum\_wire\_compatibility\_version" : "6.8.0",  
> "minimum\_index\_compatibility\_version" : "6.0.0-beta1"  
> },  
> "tagline" : "You Know, for Search"  
> }

Logs on Pod

> Blockquote arch-svc.elasticsearch.svc.cluster.local:9200/]}}  
> [2019-12-09T19:09:41,088][ERROR][logstash.javapipeline] Pipeline aborted due to error {:pipeline\_id=\>"beats", :exception=\>#\<Manticore::UnknownException: Host name 'sample-elasticsearch-svc.elasticsearch.svc.cluster.local' does not match the certificate subject provided by the peer (CN=instance)\>, :backtrace=\>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.6.4-java/lib/manticore/response.rb:37:in `block in initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.6.4-java/lib/manticore/response.rb:79:in `call

config for logstash

> Blockquote  
> data:  
> logstash.yml: |-  
> xpack.monitoring.elasticsearch.hosts: [https://sample-elasticsearch-0.elasticsearch.svc.cluster.local:9200](https://sample-elasticsearch-0.elasticsearch.svc.cluster.local:9200)  
> dead\_letter\_queue.enable: true  
> xpack.monitoring.enabled: true  
> xpack.monitoring.elasticsearch.username: filebeat  
> xpack.monitoring.elasticsearch.password: "123456"  
> xpack.monitoring.elasticsearch.ssl.verification\_mode: none  
> xpack.monitoring.elasticsearch.ssl.certificate\_authority: "/usr/share/logstash/config/elastic-stack-ca.pem"  
> output {  
> elasticsearch {  
> hosts =\> "sample-elasticsearch-0.elasticsearch.svc.cluster.local:9200"  
> manage\_template =\> false  
> user =\> 'filebeat'  
> password =\> '123456'  
> index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> ssl =\> true  
> cacert =\> "/usr/share/logstash/config/elastic-stack-ca.pem"  
> }  
> }

Elasticsearch config

```
cluster.name: "sample-elasticsearch-cluster"
network.host: 0.0.0.0
discovery.zen.minimum_master_nodes: 1
# Update max_local_storage_nodes value based on number of nodes
node.max_local_storage_nodes: 1
xpack.security.enabled: true
xpack.monitoring.collection.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.license.self_generated.type: trial
xpack.security.transport.ssl.keystore.path: /usr/share/elasticsearch/config/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /usr/share/elasticsearch/config/elastic-certificates.p12
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: /usr/share/elasticsearch/config/elastic-certificates.p12
xpack.security.http.ssl.truststore.path: /usr/share/elasticsearch/config/elastic-certificates.p12
http.cors.enabled: true
http.cors.allow-origin: "*"
http.max_header_size: 16kb
cluster.initial_master_nodes:
 - sample-elasticsearch-0

```

I would really appreciate any help here

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2020, 7:38pm UTC](https://discuss.elastic.co/t/logstash-tls-ssl-fails-to-connect-to-elasticsearch-with-cn-instance-does-not-match-the-certificate-subject-provided/211181/3 "2020-01-06T19:38:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
