# Securing APM agent comms

**URL:** <https://discuss.elastic.co/t/securing-apm-agent-comms/202764>\
**Category:** APM\
**Tags:** java, server\
**Created:** [October 9, 2019, 6:01am UTC](https://discuss.elastic.co/t/securing-apm-agent-comms/202764 "2019-10-09T06:01:00Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![RichardH](https://avatars.discourse-cdn.com/v4/letter/r/9de0a6/32.png) [@RichardH](https://discuss.elastic.co/u/RichardH)\
**Post date:** [October 9, 2019, 6:01am UTC](https://discuss.elastic.co/t/securing-apm-agent-comms/202764/1 "2019-10-09T06:01:01Z")

</div>

\*\*Kibana version 7.4

\*\*Elasticsearch version 7.4:

\*\*APM Server version 7.4:

**APM Agent language and version** :

\*\*Original install method (e.g. download page, yum, deb, from source, etc.) and version APT:

\*\*Fresh install or upgraded from other version? Fresh

I have set up APM agent on a Tomcat server. Downloaded latest version of the agent, updated the server startup paramters in wrapper.conf and it works. Now I need to secure the Agent to APM-Server comms. I have created a cert for the server (using our MS CA Server), and downloaded the sert, the key and the CA cert. Converted the CA cert to a .PEM . Copied all three across to the apm-server and updated the apm-server.yml file. Also confirmed that the user apm-server is owner of all cert files.

$  
ssl:  
enabled: true  
certificate\_authorities: ["/usr/share/apm-server/cert/CA.pem"]  
certificate: /usr/share/apm-server/cert/xxxxxxxx\*.cer  
key: /usr/share/apm-server/cert/server.key

On the agent, changed the wrapper.conf to point it to the APM server on https instead of http.

Started the apm server with debug to console (apm-server -e -d "\*") nothing coming through - before changing to SSL could see transactions coming through.

Any suggestions

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [October 9, 2019, 6:23am UTC](https://discuss.elastic.co/t/securing-apm-agent-comms/202764/2 "2019-10-09T06:23:48Z")

</div>

Since you're using your own certificate authority, I'm guessing that the agent is not aware of it and so certificate verification will fail. You can confirm this by passing `-Delastic.apm.verify_server_cert=false` to the agent: [https://www.elastic.co/guide/en/apm/agent/java/current/config-reporter.html#config-verify-server-cert](https://www.elastic.co/guide/en/apm/agent/java/current/config-reporter.html#config-verify-server-cert)

Note that disabling certificate verification isn't recommended in production, as it means MITM attacks will be possible. You should instead create and use a truststore, using Java Keytool.

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [October 9, 2019, 8:18am UTC](https://discuss.elastic.co/t/securing-apm-agent-comms/202764/3 "2019-10-09T08:18:19Z")

</div>

Hi @RichardH,  
please note that the config option `ssl.certificate_authorities` in the `apm-server.yml` should be used to define CAs for [verifying client certificates](https://www.elastic.co/guide/en/apm/server/current/agent-server-ssl.html#_certificate_authorities_2). By default the server does not require client authentication, but as soon as certificate\_authorities are configured, it does require the client to provide a valid certificate. Find more details about [configuring SSL input settings](https://www.elastic.co/guide/en/apm/server/current/agent-server-ssl.html#agent-server-ssl) for the APM Server.

---

<div class="post-metadata">

**Author:** ![RichardH](https://avatars.discourse-cdn.com/v4/letter/r/9de0a6/32.png) [@RichardH](https://discuss.elastic.co/u/RichardH)\
**Post date:** [October 9, 2019, 8:28am UTC](https://discuss.elastic.co/t/securing-apm-agent-comms/202764/4 "2019-10-09T08:28:08Z")

</div>

Thanks. I have tried adding the Issuer CA and a combined CA (combining the issuer an CA from our cert server). I have also tried installing both the rootCA and intermediate CA in Ubuntu ([https://superuser.com/questions/437330/how-do-you-add-a-certificate-authority-ca-to-ubuntu](https://superuser.com/questions/437330/how-do-you-add-a-certificate-authority-ca-to-ubuntu)) and then taking out the ssl.certificate.authorites line in my YML file. Still no luck.

---

<div class="post-metadata">

**Author:** ![RichardH](https://avatars.discourse-cdn.com/v4/letter/r/9de0a6/32.png) [@RichardH](https://discuss.elastic.co/u/RichardH)\
**Post date:** [October 9, 2019, 8:48am UTC](https://discuss.elastic.co/t/securing-apm-agent-comms/202764/5 "2019-10-09T08:48:23Z")

</div>

It looks like I need to specify the root ca and intermediate ca seperately under 'certiciate\_authorities'in my apm-server.yml file. What is the corrext syntax for specifying multiple certificates ?

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [October 9, 2019, 12:16pm UTC](https://discuss.elastic.co/t/securing-apm-agent-comms/202764/6 "2019-10-09T12:16:06Z")

</div>

Sorry for not being more clear in my previous response. The java agent does not support sending a client certificate. Therefore you need to ensure that the server does not require and try to verify such a client certificate. When using default options for `apm-server.ssl.certificate_authorities` and `apm-server.ssl.client_authentication` the server does not require it.

If the communication still doesn't work, can you please check the logs for the agent and the server.

---

<div class="post-metadata">

**Author:** ![RichardH](https://avatars.discourse-cdn.com/v4/letter/r/9de0a6/32.png) [@RichardH](https://discuss.elastic.co/u/RichardH)\
**Post date:** [October 10, 2019, 6:13am UTC](https://discuss.elastic.co/t/securing-apm-agent-comms/202764/7 "2019-10-10T06:13:27Z")

</div>

Thanks All.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2019, 2:13am UTC](https://discuss.elastic.co/t/securing-apm-agent-comms/202764/8 "2019-10-31T02:13:52Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
