# Logstash to elasticsearch ssl connection issue

**URL:** <https://discuss.elastic.co/t/logstash-to-elasticsearch-ssl-connection-issue/302842>\
**Category:** Logstash\
**Created:** [April 20, 2022, 5:06pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-ssl-connection-issue/302842 "2022-04-20T17:06:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fabek.75](https://avatars.discourse-cdn.com/v4/letter/f/7c8e57/32.png) [@fabek.75](https://discuss.elastic.co/u/fabek.75)\
**Post date:** [April 20, 2022, 5:06pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-ssl-connection-issue/302842/1 "2022-04-20T17:06:37Z")

</div>

Hi,  
I have setup an on-prem dev environment with Elasticsearch 8.x and from a client I'm trying to push some data through a Logstash pipeline (version is 8.1.2-1). It seems, however, Logstash wants absolutely that some certs are specified. Basically I'm working on self signed cert on destination and ignoring any cert verification.

My output conf. is

```auto
output {
  elasticsearch {
    hosts => ["https://10.x.x.x:9200"]
    # SSL enabled but not verification
    ssl => true
    cacert => "/usr/share/logstash/jdk/lib/security/cacerts"
    ssl_certificate_verification => false
    # index => "%{[@metadata][proxy]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
    index => "logstash-test"
    # see https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/433
    user => "elastic"
    password => "secret"
  }
 }

```

I also uncommented the cacert directive and btw I don't find any other cert in that logstash path.  
Ofc I can connect there via curl (with the -k option and specifying a user name and a password).

Relevant messages from tracing are:

```auto
[2022-04-20T16:53:31,427][INFO][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["https://10.160.2.101:9200"]}
[2022-04-20T16:53:31,452][DEBUG][logstash.outputs.elasticsearch][main] Normalizing http path {:path=>nil, :normalized=>nil}
[2022-04-20T16:53:31,461][WARN][logstash.outputs.elasticsearch][main] You have enabled encryption but DISABLED certificate verification, to make sure your data is secure remove `ssl_certificate_verification => false`

...

[2022-04-20T16:53:31,655][ERROR][logstash.javapipeline][main] Pipeline error {:pipeline_id=>"main", :exception=>java.security.cert.CertificateException: No certificate data found

...

Failed to execute action {:id=>:main, :action_type=>LogStash::ConvergeResult::FailedAction, :message=>"Could not execute action: PipelineAction::Create<main>, action_result: false", :backtrace=>nil}

```

So it seems I need to setup anyway some certs on the client or server side?

Thanks.

---

<div class="post-metadata">

**Author:** ![fabek.75](https://avatars.discourse-cdn.com/v4/letter/f/7c8e57/32.png) [@fabek.75](https://discuss.elastic.co/u/fabek.75)\
**Post date:** [April 22, 2022, 8:56am UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-ssl-connection-issue/302842/2 "2022-04-22T08:56:33Z")

</div>

The cacert line had to be put, due to a bug, only in a previous version. After removing it was not working probably due to some unclean Logstash configuration reload; so it was reading the previous configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2022, 8:56am UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-ssl-connection-issue/302842/3 "2022-05-20T08:56:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
