# Secured connection from FIlebeat to Logstash (remote error: tls: handshake failure)

**URL:** <https://discuss.elastic.co/t/secured-connection-from-filebeat-to-logstash-remote-error-tls-handshake-failure/245652>\
**Category:** Beats\
**Tags:** elastic-stack-security, docker, filebeat\
**Created:** [August 19, 2020, 4:37pm UTC](https://discuss.elastic.co/t/secured-connection-from-filebeat-to-logstash-remote-error-tls-handshake-failure/245652 "2020-08-19T16:37:32Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ofer.h](https://avatars.discourse-cdn.com/v4/letter/o/ea5d25/32.png) [@ofer.h](https://discuss.elastic.co/u/ofer.h)\
**Post date:** [August 19, 2020, 4:37pm UTC](https://discuss.elastic.co/t/secured-connection-from-filebeat-to-logstash-remote-error-tls-handshake-failure/245652/1 "2020-08-19T16:37:33Z")

</div>

Hi,  
I'm trying to configure tls for logstash and I'm getting the following error:

```
2020-08-19T11:56:29.340-0400 ERROR [publisher_pipeline_output] pipeline/output.go:106 Failed to connect to backoff(async(tcp://logstash.server.host:5044)): remote error: tls: handshake failure
2020-08-19T11:56:29.340-0400 INFO [publisher_pipeline_output] pipeline/output.go:99 Attempting to reconnect to backoff(async(tcp://logstash.server.host:5044)) with 6 reconnect attempt(s)

```

In the tcpdump all I can see is the following line:

```
6	0.047390	x.x.x.x	y.y.y.y	TLSv1.2	73	Alert (Level: Fatal, Description: Handshake Failure)

and it's details are:

Alert Message- Level Fatal(2), Description: Handshake Failure(4)

```

Logstash input plugin is configured:

```
beats {
        port => 5044
        ssl => true
        ssl_certificate => "/etc/pki/logstash/logstash.crt"
        ssl_key => "/etc/pki/logstash/logstash.key"
        type => filebeat
  }

```

Filebeat.yml:

```
# ------------------------------ Logstash Output -------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["logstash.server.host:5044"]
  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  ssl.certificate_authorities: ["/etc/pki/filebeat/logstash.crt"]

  # Certificate for SSL client authentication
  #ssl.certificate: "/etc/pki/client/cert.pem"

  # Client Certificate Key
  #ssl.key: "/etc/pki/client/cert.key"

```

I generated logstash.key and logstash.crt using openssl and copied logstash.crt to Filebeat server (/etc/pki/filebeat/logstash.crt, as configured in filebeat.yml) according to this guide:  
https://documentation.wazuh.com/3.8/installation-guide/installing-elastic-stack/elastic\_ssl.html  
Generated a couple of keys (with server IP, with server hostname, with -subj flag) and none of them worked.

A couple of notes:

1. The flow works perfectly fine when I'm trying regular tcp send

2. I tried it in systems without firewalls and/or proxies too, got the same error

3. Testing the connection with `curl -v --cacert /etc/pki/filebeat/logstash.crt > https://logstash.server.host:5044` returned the following error:

4. Testing the connection with `openssl s_client -connectlogstash.server.host:5044 -CAfile /etc/pki/filebeat/logstash.cr`t returned the following error:

I tried pretty much anything I can think of...  
Do you have any suggestion of what might be the problem?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2020, 6:37pm UTC](https://discuss.elastic.co/t/secured-connection-from-filebeat-to-logstash-remote-error-tls-handshake-failure/245652/2 "2020-09-16T18:37:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
