# Multiple ssl certificates in logstash-forwarder

**URL:** <https://discuss.elastic.co/t/multiple-ssl-certificates-in-logstash-forwarder/27337>\
**Category:** Logstash\
**Created:** [August 13, 2015, 4:08pm UTC](https://discuss.elastic.co/t/multiple-ssl-certificates-in-logstash-forwarder/27337 "2015-08-13T16:08:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![iamrudra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iamrudra/32/4160_2.png) [@iamrudra](https://discuss.elastic.co/u/iamrudra)\
**Post date:** [August 13, 2015, 4:08pm UTC](https://discuss.elastic.co/t/multiple-ssl-certificates-in-logstash-forwarder/27337/1 "2015-08-13T16:08:52Z")

</div>

The basic/example [config](https://github.com/elastic/logstash-forwarder/blob/master/logstash-forwarder.conf.example) shipped with logstash-forwarder states the following for listing `multiple downstream servers`:

> ...  
> #A list of downstream servers listening for our messages.  
> #logstash-forwarder will pick one at random and only switch if  
> #the selected one appears to be dead or unresponsive  
> "servers": ["localhost:5043"],  
> ...

Now going further in the next section of the config:

> ...

# The path to your trusted ssl CA file. This is used

```
# to authenticate your downstream server.
#"ssl ca": "./logstash-forwarder.crt",

```

...

So the list of servers is an array and there is provision to add only one certificate file path in the form of string- Now my case is that I have more than one certificates (issues per public IP of my logstash boxes since I don't have a DNS for them). Is there a work around for this?

One that that I think might work is using a wildcard "\*" while generating a certificate but would like to get some opinions on that - how good/bad it is?

---

<div class="post-metadata">

**Author:** ![msimos](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@msimos](https://discuss.elastic.co/u/msimos)\
**Post date:** [August 13, 2015, 9:34pm UTC](https://discuss.elastic.co/t/multiple-ssl-certificates-in-logstash-forwarder/27337/2 "2015-08-13T21:34:06Z")

</div>

It should be fine to use a wildcard cert assuming you always connect with \*.domain.com. You may want to read over this conversation to get a better feel for what works and what doesn't.

[https://github.com/elastic/logstash-forwarder/issues/221](https://github.com/elastic/logstash-forwarder/issues/221)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:32am UTC](https://discuss.elastic.co/t/multiple-ssl-certificates-in-logstash-forwarder/27337/3 "2017-07-06T05:32:01Z")

</div>


