# Logstash unable to connect to Elasticsearch over https

**URL:** <https://discuss.elastic.co/t/logstash-unable-to-connect-to-elasticsearch-over-https/56105>\
**Category:** Logstash\
**Created:** [July 21, 2016, 2:07pm UTC](https://discuss.elastic.co/t/logstash-unable-to-connect-to-elasticsearch-over-https/56105 "2016-07-21T14:07:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![prabhakar349](https://avatars.discourse-cdn.com/v4/letter/p/5e9695/32.png) [@prabhakar349](https://discuss.elastic.co/u/prabhakar349)\
**Post date:** [July 21, 2016, 2:07pm UTC](https://discuss.elastic.co/t/logstash-unable-to-connect-to-elasticsearch-over-https/56105/1 "2016-07-21T14:07:16Z")

</div>

HI All ,

We are trying to connect to elastic serach server from logstash, but it throws following error even after specifying the path to certificate , we have tried giving

We first tried using the following :

truststore =\> /xxxx/cacert  
truststore\_password =\> "XXXXX"

we also tried using :  
cacert =\> "/path to/xxxx.cer"

And we are sure that cacerts has appropriate root certificate , when we run a java program using the same cacert it works without any errors.

```auto
PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors {:class=>"Manticore::ClientProtocolException", :level=>:error}
PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors {:class=>"Manticore::ClientProtocolException", :level=>:error}

input {
  kafka {
    topic_id => "logs"
    group_id => "logstashdevgroup"
   zk_connect => "10.203.91.61:8164"
  }
}
 
filter{
mutate{
  add_field => {
    "applicationName" => "%{[contextMap][applicationName]}"
  }
}
uuid{
   target => "documenteventId"
}
}
 
output {
 
if [level] == "ERROR" or [level] == "WARN" or [level] == "FATAL" {
 
  elasticsearch {
     ssl => true
     cacert => /opt/xxx.cer
     hosts => "https://xxxxxxxx.com"
  }
 
  kafka {
    topic_id => "omega-error-logs"
    bootstrap_servers => "10.203.91.61:8165"
  }
 
}
 
else {
  elasticsearch {
      ssl => true
      cacert => /opt/xxx.cer
      hosts => "https://xxxxxx.com"
  }
}
 
 
}

```

Any help would be appreciated , we are blocked on this issue.

---

<div class="post-metadata">

**Author:** ![jpcarey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpcarey/32/46668_2.png) [@jpcarey](https://discuss.elastic.co/u/jpcarey)\
**Post date:** [July 21, 2016, 5:51pm UTC](https://discuss.elastic.co/t/logstash-unable-to-connect-to-elasticsearch-over-https/56105/2 "2016-07-21T17:51:45Z")

</div>

For the elasticsearch cluster, are you using a CA + an intermediate?

`keytool -list -v -keystore file.jks`

If so, you may need to import both into the truststore for logstash.

[https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-truststore](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-truststore)

---

<div class="post-metadata">

**Author:** ![prabhakar349](https://avatars.discourse-cdn.com/v4/letter/p/5e9695/32.png) [@prabhakar349](https://discuss.elastic.co/u/prabhakar349)\
**Post date:** [July 21, 2016, 6:39pm UTC](https://discuss.elastic.co/t/logstash-unable-to-connect-to-elasticsearch-over-https/56105/3 "2016-07-21T18:39:40Z")

</div>

Actually Our elasticsearch itself is not SSL enabled , but we have fronted Elastic search with an ELB in AWS environment . The ELB is configured with the a CA signed certificate.

So are you saying I need to add both the root certificate and then the Public certificate to the trust store ?

---

<div class="post-metadata">

**Author:** ![jpcarey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpcarey/32/46668_2.png) [@jpcarey](https://discuss.elastic.co/u/jpcarey)\
**Post date:** [July 21, 2016, 9:27pm UTC](https://discuss.elastic.co/t/logstash-unable-to-connect-to-elasticsearch-over-https/56105/4 "2016-07-21T21:27:34Z")

</div>

What happens if you curl that endpoint using `--cacert [file]`?

---

<div class="post-metadata">

**Author:** ![prabhakar349](https://avatars.discourse-cdn.com/v4/letter/p/5e9695/32.png) [@prabhakar349](https://discuss.elastic.co/u/prabhakar349)\
**Post date:** [August 10, 2016, 8:15pm UTC](https://discuss.elastic.co/t/logstash-unable-to-connect-to-elasticsearch-over-https/56105/5 "2016-08-10T20:15:32Z")

</div>

Thanks @jpcarey Its issue with the certificate

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:43am UTC](https://discuss.elastic.co/t/logstash-unable-to-connect-to-elasticsearch-over-https/56105/6 "2017-07-06T04:43:56Z")

</div>


