# LS 2.3 -\> 5.0 TLS trouble, PKCS#8 and cipher\_suites

**URL:** <https://discuss.elastic.co/t/ls-2-3-5-0-tls-trouble-pkcs-8-and-cipher-suites/67309>\
**Category:** Logstash\
**Created:** [November 28, 2016, 7:20am UTC](https://discuss.elastic.co/t/ls-2-3-5-0-tls-trouble-pkcs-8-and-cipher-suites/67309 "2016-11-28T07:20:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gregoryo](https://avatars.discourse-cdn.com/v4/letter/g/34f0e0/32.png) [@gregoryo](https://discuss.elastic.co/u/gregoryo)\
**Post date:** [November 28, 2016, 7:20am UTC](https://discuss.elastic.co/t/ls-2-3-5-0-tls-trouble-pkcs-8-and-cipher-suites/67309/1 "2016-11-28T07:20:57Z")

</div>

On FreeBSD 10, I had TLS working for encrypted communication between previous versions of Logstash and both Filebeat and Metricbeat. I've recently upgraded ELK to the versions below:

- Logstash [2.3](http://www.freshports.org/sysutils/logstash/) -\> [5.0](http://www.freshports.org/sysutils/logstash5/)
- Filebeat [1.2](http://www.freshports.org/sysutils/filebeat/) -\> 5.0 ([hand built](https://github.com/elastic/beats/issues/974#issuecomment-262778791))
- Metricbeat 5.0 alpha ([hand built](https://github.com/elastic/beats/issues/974#issuecomment-229604457)) -\> 5.0 ([hand built](https://github.com/elastic/beats/issues/974#issuecomment-262778791))

Things work with TLS disabled, but I am being hindered by the [LS 2.4 breaking change](https://www.elastic.co/blog/logstash-2-4-0-released) regarding PKCS#8.

```
logstash/bin/logstash -f /usr/local/etc/logstash/logstash.conf
...
[2016-11-28T14:57:53,934][ERROR][logstash.inputs.beats] Looks like you either have an invalid key or your private key was not in PKCS8 format. {:exception=>java.lang.IllegalArgumentException: File does not contain valid private key: /usr/local/share/certs/managed/raw/logstash.key}

```

I followed some advice about converting the private key for both \*beats and Logstash...

```
# openssl pkcs8 -topk8 -nocrypt -in $inkey -out $inkey.pkcs8

```

... and changing configs for all three services to use the .pkcs8 file for the key. Still no luck:

```
logstash/bin/logstash -f /usr/local/etc/logstash/logstash.conf
...
[2016-11-28T13:54:43,883][ERROR][logstash.inputs.beats] Looks like you either have an invalid key or your private key was not in PKCS8 format. {:exception=>java.lang.IllegalArgumentException: Unsupported ciphersuite TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA38}

```

Can I get some help troubleshooting this please?

```
$ openssl version
OpenSSL 1.0.1p-freebsd 9 Jul 2015

```

Thanks,  
Greg.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2016, 7:21am UTC](https://discuss.elastic.co/t/ls-2-3-5-0-tls-trouble-pkcs-8-and-cipher-suites/67309/2 "2016-12-26T07:21:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
