# Logstashのクライアント認証について

**URL:** <https://discuss.elastic.co/t/logstash/184283>\
**Category:** 日本語による質問・議論はこちら\
**Created:** [June 5, 2019, 6:16am UTC](https://discuss.elastic.co/t/logstash/184283 "2019-06-05T06:16:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![devdevdev](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@devdevdev](https://discuss.elastic.co/u/devdevdev)\
**Post date:** [June 5, 2019, 6:16am UTC](https://discuss.elastic.co/t/logstash/184283/1 "2019-06-05T06:16:58Z")

</div>

logstashからlogstashへのhttpプロトコルを利用したデータ送信を模索しています。

output.http -\> input.httpによるデータ送信は確認できました。  
あとはhttpsとクライアント認証でデータ送信を実現したいと考えています。

公式docを見るとSSL(https)とクライアント認証が可能なようにみえます。

> **[Http output plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-http.html)**

> **[Http input plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html)**

検証した結果、SSLは出来たのですがクライアント認証がうまくいきません。

よろしくお願いします。

以下、検証時情報。

> 証明書コマンド例  
> openssl req -x509 -days 18250 -batch -nodes -newkey rsa:2048 -keyout test.key -out test.cert -subj /CN=test）

> ＊送信側＊  
> input {  
> stdin{}  
> }  
> output {  
> http{  
> http\_method =\> "post"  
> url =\> "[https://test:443](https://test:443)"  
> cacert =\> "./crt/test.crt"  
> }  
> }

> ＊受信側＊  
> input {  
> http{  
> port =\> 443  
> ssl =\> true  
> ssl\_certificate =\> "./crt/test.crt"  
> ssl\_key =\> "./crt/test.key"  
> }  
> }  
> output {  
> stdout{  
> codec =\> rubydebug  
> }  
> }

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [June 6, 2019, 12:45pm UTC](https://discuss.elastic.co/t/logstash/184283/2 "2019-06-06T12:45:23Z")

</div>

what is the problem you see? I tried your configuration and was able to send data:

```auto
/tmp/logstash-7.1.0 % bin/logstash -f in.cfg
Sending Logstash logs to /tmp/logstash-7.1.0/logs which is now configured via log4j2.properties
[2019-06-06T13:41:54,883][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified
[2019-06-06T13:41:54,896][INFO][logstash.runner] Starting Logstash {"logstash.version"=>"7.1.0"}
[2019-06-06T13:41:56,732][INFO][logstash.javapipeline] Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>8, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50, "pipeline.max_inflight"=>1000, :thread=>"#<Thread:0x33f4594 run>"}
[2019-06-06T13:41:56,839][INFO][logstash.javapipeline] Pipeline started {"pipeline.id"=>"main"}
The stdin plugin is now waiting for input:
[2019-06-06T13:41:56,899][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[2019-06-06T13:41:57,116][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
hey

```

```auto
/tmp/logstash-7.1.0 % bin/logstash -f out.cfg --path.data data2
Sending Logstash logs to /tmp/logstash-7.1.0/logs which is now configured via log4j2.properties
[2019-06-06T13:42:02,007][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified
[2019-06-06T13:42:02,016][INFO][logstash.runner] Starting Logstash {"logstash.version"=>"7.1.0"}
[2019-06-06T13:42:03,259][INFO][logstash.javapipeline] Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>8, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50, "pipeline.max_inflight"=>1000, :thread=>"#<Thread:0x6d41fc93 run>"}
[2019-06-06T13:42:03,921][INFO][logstash.javapipeline] Pipeline started {"pipeline.id"=>"main"}
[2019-06-06T13:42:03,936][INFO][logstash.inputs.http] Starting http input listener {:address=>"0.0.0.0:443", :ssl=>"true"}
[2019-06-06T13:42:03,974][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[2019-06-06T13:42:04,252][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9601}
{
      "@version" => "1",
    "@timestamp" => 2019-06-06T12:42:32.435Z,
       "headers" => {
             "connection" => "Keep-Alive",
           "content_type" => "application/json",
         "content_length" => "95",
        "accept_encoding" => "gzip,deflate",
            "http_accept" => nil,
              "http_host" => "test:443",
        "http_user_agent" => "Manticore 0.6.4",
         "request_method" => "POST",
           "http_version" => "HTTP/1.1",
           "request_path" => "/"
    },
       "message" => "hey",
          "host" => "127.0.0.1"
}

```

---

<div class="post-metadata">

**Author:** ![devdevdev](https://avatars.discourse-cdn.com/v4/letter/d/ee7513/32.png) [@devdevdev](https://discuss.elastic.co/u/devdevdev)\
**Post date:** [June 11, 2019, 7:38am UTC](https://discuss.elastic.co/t/logstash/184283/3 "2019-06-11T07:38:59Z")

</div>

thanks jsvd.

私もデータ送信は出来ました。  
クライアント証明書が出来ません。  
クライアント証明書の作成方法や下のoptionsの設定のサンプルとかありますか？

output.http.  
client\_cert:?  
client\_key:?

input:.http  
ssl\_certificate\_authorities:?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2019, 7:39am UTC](https://discuss.elastic.co/t/logstash/184283/4 "2019-07-09T07:39:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
