# Problem with Logstash SSL

**URL:** <https://discuss.elastic.co/t/problem-with-logstash-ssl/298084>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [February 23, 2022, 8:34pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084 "2022-02-23T20:34:29Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [February 23, 2022, 8:34pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/1 "2022-02-23T20:34:29Z")

</div>

hi, im having difficulties when changing my logstash SSL certificate, today i have a certificate that is in the /etc/logstash folder and i generated a new one through the elastic tool, using Elasticsearch-certutil and then Im generating the .crt through from openssl. The new certificate is already correctly named everywhere and with the proper permissions, same as the old certificate that works.

however, when i upload the new certificate, this error appears below in the logstash log

**[2022-02-17T15:15:43,619][WARN][logstash.outputs.Elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=\>"[https://elastic:xxxxxx@localhost:9200/](https://elastic:xxxxxx@localhost:9200/)", :exception=\>LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError, :message=\>"Elasticsearch Unreachable: [[https://elastic:xxxxxx@localhost:9200/](https://elastic:xxxxxx@localhost:9200/)][Manticore::ClientProtocolException] PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"}**

my configuration file is as follows (only the certificate snippet was pasted here)

```auto
output {
        if [type] == "host-1" {
                elasticsearch {
                        hosts => ["https://localhost:9200"]
                        #index => "cacheaudit-cloud1-%{+YYYY.MM.dd}"
                        user => "user"
                        password => "pass"
                        ssl => true
                        ssl_certificate_verification => false
                        cacert => "/etc/logstash/ca.crt"
                        ilm_rollover_alias => "cacheaudit-host1"
                        ilm_policy => "cache-lifecycle"
                }
        }

        if [type] == "host-2" {
                elasticsearch {
                        hosts => ["https://localhost:9200"]
                        #index => "cacheaudit-cloud2-%{+YYYY.MM.dd}"
                        user => "user"
                        password => "pass"
                        ssl => true
                        ssl_certificate_verification => false
                        cacert => "/etc/logstash/ca.crt"
                        ilm_rollover_alias => "cacheaudit-host2"
                        ilm_policy => "cache-lifecycle"
                }
        }
}

```

the new SSL certificate is valid until 2025

someone can help me with this issue?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 23, 2022, 9:09pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/2 "2022-02-23T21:09:27Z")

</div>

@gustavoluza Did you make sure that the new certs are readable by logstash from a permission perspective?

---

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [February 24, 2022, 11:09am UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/3 "2022-02-24T11:09:27Z")

</div>

@stephenb yes, old and new certificate belong to root group and root user in linux, with maximum access permission to this file and directory.

but i tried to change permissions for the new certificate, but i have the same issue at the logstash log

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 24, 2022, 3:27pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/4 "2022-02-24T15:27:28Z")

</div>

I would try a simple curl with the certificate to the Elasticsearch host and see if that works with the same connection information and cert.

---

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [February 24, 2022, 4:40pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/5 "2022-02-24T16:40:09Z")

</div>

thats just, curl [https://instanceIP:9200](https://instanceIP:9200) ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 24, 2022, 4:56pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/6 "2022-02-24T16:56:59Z")

</div>

See [https://www.baeldung.com/linux/curl-https-connection](https://www.baeldung.com/linux/curl-https-connection)

---

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [February 24, 2022, 5:06pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/7 "2022-02-24T17:06:27Z")

</div>

@stephenb curl with the new certificate

```auto
{"error":{"root_cause":[{"type":"security_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":["Basic realm=\"security\" charset=\"UTF-8\"","Bearer realm=\"security\"","ApiKey"]}}],"type":"security_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":["Basic realm=\"security\" charset=\"UTF-8\"","Bearer realm=\"security\"","ApiKey"]}},"status":401}

```

this error is expected because of my configurations and also occour with the older certificate

with the old certificate i also have the same result

---

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [March 2, 2022, 2:18pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/8 "2022-03-02T14:18:12Z")

</div>

someone can help?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 2, 2022, 4:44pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/9 "2022-03-02T16:44:27Z")

</div>

If you use curl with the `-u username:password` option does it connect and return a result?

Have you tried to put the IP in instead of localhost in the elasticsearch output?

Are there any other pertinent logs in the logstash logs?

I see you are using openssl to generate the CA why did you not just use the the elasticsearch-certutil in ca mode (I am not clear what you did)

> **[elasticsearch-certutil | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/certutil.html#certutil-ca)**

> `ca`
> 
> Specifies to generate a new local certificate authority (CA). This parameter cannot be used with the `csr` or `cert` parameters.

@Badger any thoughts?

---

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [March 2, 2022, 5:46pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/10 "2022-03-02T17:46:37Z")

</div>

@stephenb how i can to generate a .zip file with p12, ca and crt inside? im trying to use the --multiple option, but i get some erros, can you give me a link with the sintax? (im also searching about this on the web, but without success till the moment)

EDIT: i generated the cert with --multiple option, but, in the zip file just came the .p12

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 2, 2022, 7:02pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/11 "2022-03-02T19:02:33Z")

</div>

What version of the stack are you using.

You will need to show the commands and in order you used otherwiseI / we can not help....

For the Elasticsearch https endpoint you should be following [these instructions](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup-https.html#encrypt-http-communication)

The ca you should use for logstash should be the same you would use for kibana

> #### Encrypt traffic between Kibana and Elasticsearch
> 
> When you ran the `elasticsearch-certutil` tool with the `http` option, it created a `/kibana` directory containing an `elasticsearch-ca.pem`

---

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [March 2, 2022, 7:11pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/12 "2022-03-02T19:11:37Z")

</div>

My stack version is 7.15.1

here are the commands that i used to generate the .zip file with .p12 cert inside.

```auto
./bin/elasticsearch-certutil cert --multiple elastic-stack-ca.p12

```

For Kibana i use a wildcard ca, that was not been generated with certutil, but this cert doesnt work with logstash

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 2, 2022, 7:18pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/13 "2022-03-02T19:18:52Z")

</div>

Right....

You need to do the second step.... following the instruction I just gave you ... the certs you created was for TLS internode not the http endpoint, you need to create the CA / Certs for the http endpoint

Why don't you try running with the http instruction per the instructions I just gave and then use that with logstash (instead kibana)

`./bin/elasticsearch-certutil http`

---

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [March 2, 2022, 7:26pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/14 "2022-03-02T19:26:48Z")

</div>

Ok...

now i have this files...  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/b/ab079c6820bca211a84774d6c039dc0d43c9627c.png)  
but logstash use a .crt file, how i can generate that file?

in the kibana directory that was been created, i have this  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8c6e5180e6330d82eaade5d86f63fe2c053b6507.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 2, 2022, 7:50pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/15 "2022-03-02T19:50:03Z")

</div>

Please don't paste images

Looks like you did a csr request which is not correct

> 1. When asked if you want to generate a CSR, enter `n` .

> [@gustavoluza](#):
>
> but logstash use a .crt file, how i can generate that file?

the elasticsearch output for logstash is looking for a CA file not a cert.

BTW I wrote a How To here that shows all this

[https://github.com/bvader/howtos/tree/master/basic-security-elasticsearch](https://github.com/bvader/howtos/tree/master/basic-security-elasticsearch)

---

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [March 2, 2022, 8:22pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/16 "2022-03-02T20:22:13Z")

</div>

@stephenb sorry for post the images.

I did the procedure that you told me, but i still get a error from logstash.

```auto
[WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://elastic:xxxxxx@localhost:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [https://elastic:xxxxxx@localhost:9200/][Manticore::ClientProtocolException] PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors"}

```

here is my logstash file with my hosts... (i use JDBC on input)

```auto
if [type] == "host-1" {
                elasticsearch {
                        hosts => ["https://localhost:9200"]
                        user => "user"
                        password => "pass"
			cacert => "/etc/logstash/elasticsearch-ca.pem"
			ilm_rollover_alias => "cacheaudit-cloud1"
			ilm_policy => "cache-lifecycle"
                }
        }

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 2, 2022, 9:04pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/17 "2022-03-02T21:04:24Z")

</div>

Did you use IPs or localhost when you created the cert... use the same in the setting

`hosts => ["https://localhost:9200"]`

Note my example

```auto
    hosts => ["https://10.168.0.116:9200"]

```

This may be an issues with your SSL Setup on the Box...

There was also a thread on this here

> [@Error "Path does not chain with any of the trust anchors" when enabling TSL between nodes](https://discuss.elastic.co/t/error-path-does-not-chain-with-any-of-the-trust-anchors-when-enabling-tsl-between-nodes/131078):
>
> Hi, I have been trying to enable TLS encryption between my nodes. I have followed [the instructions of the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/configuring-tls.html#tls-transport) and generated p12-format certificates for each node and configured my cluster like this (the certificates don't have a password: cluster.name: eLABsticsearch node.name: elastic01 node.data: True node.master: True node.ingest: True node.ml: True search.remote.connect: false path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch network.host: 172.28.128.11 …

---

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [March 3, 2022, 2:36pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/18 "2022-03-03T14:36:03Z")

</div>

@stephenb i follow all the steps from the article (i deploy a new environment) but,  
im getting this error

```auto
[2022-03-03T11:29:46,552][ERROR][logstash.licensechecker.licensereader] Unable to retrieve license information from license server {:message=>"Elasticsearch Unreachable: [https://10.0.0.114:9200/_xpack][Manticore::ClientProtocolException] PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"}
[2022-03-03T11:30:16,457][ERROR][logstash.licensechecker.licensereader] Unable to retrieve license information from license server {:message=>"No Available connections"}

```

when i curl my Elasticsearch i have the same exit that in article.

my problem is just with logstash, Elasticsearch and kibana are working good.

i used the same certificates for all (Elasticsearch, kibana and logstash)

in my browser i can access [https://10.0.0.114:9200/\_xpack](https://10.0.0.114:9200/_xpack) and after put the user and pass to login, i see this

```auto
{"build":{"hash":"e5acb99f822233d62d6444ce45a4543dc1c8059a","date":"2022-02-23T22:20:54.153567231Z"},"license":{"uid":"8d62208b-4ef5-4cc4-ab42-16a6de4639a5","type":"basic","mode":"basic","status":"active"},"features":{"aggregate_metric":{"available":true,"enabled":true},"analytics":{"available":true,"enabled":true},"ccr":{"available":false,"enabled":true},"data_streams":{"available":true,"enabled":true},"data_tiers":{"available":true,"enabled":true},"enrich":{"available":true,"enabled":true},"eql":{"available":true,"enabled":true},"frozen_indices":{"available":true,"enabled":true},"graph":{"available":false,"enabled":true},"ilm":{"available":true,"enabled":true},"logstash":{"available":false,"enabled":true},"ml":{"available":false,"enabled":true,"native_code_info":{"version":"7.17.1","build_hash":"6d8a28b39bf223"}},"monitoring":{"available":true,"enabled":true},"rollup":{"available":true,"enabled":true},"searchable_snapshots":{"available":false,"enabled":true},"security":{"available":true,"enabled":true},"slm":{"available":true,"enabled":true},"spatial":{"available":true,"enabled":true},"sql":{"available":true,"enabled":true},"transform":{"available":true,"enabled":true},"voting_only":{"available":true,"enabled":true},"watcher":{"available":false,"enabled":true}},"tagline":"You know, for X"}

```

---

<div class="post-metadata">

**Author:** ![gustavoluza](https://avatars.discourse-cdn.com/v4/letter/g/d2c977/32.png) [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Post date:** [March 3, 2022, 8:50pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/19 "2022-03-03T20:50:26Z")

</div>

@stephenb after deploy 3 environments and do many tests, your article help me to resolve the problem.

thanks so much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2022, 8:50pm UTC](https://discuss.elastic.co/t/problem-with-logstash-ssl/298084/20 "2022-03-31T20:50:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
