# Securing Beats to Logstash with Public Cert (version 6.5.1)

**URL:** <https://discuss.elastic.co/t/securing-beats-to-logstash-with-public-cert-version-6-5-1/159364>\
**Category:** Logstash\
**Created:** [December 4, 2018, 1:37pm UTC](https://discuss.elastic.co/t/securing-beats-to-logstash-with-public-cert-version-6-5-1/159364 "2018-12-04T13:37:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrew\_Griffiths](https://avatars.discourse-cdn.com/v4/letter/a/35a633/32.png) [@Andrew\_Griffiths](https://discuss.elastic.co/u/Andrew_Griffiths)\
**Post date:** [December 4, 2018, 1:37pm UTC](https://discuss.elastic.co/t/securing-beats-to-logstash-with-public-cert-version-6-5-1/159364/1 "2018-12-04T13:37:46Z")

</div>

Hi,

I have a public cert from globalsign for securing beats -\> logstash. I just want a simple way to encrypt the data without having to create hundreds of client certs.

logstash-beats.conf  
input{  
beats{  
host =\> "0.0.0.0"  
port =\> "5043"  
ssl =\> true  
ssl\_certificate\_authorities =\> ["/etc/logstash/certs/GlobalsignCA.pem"]  
ssl\_certificate =\> "/etc/logstash/certs/logcentral.cer"  
ssl\_key =\> "/etc/logstash/certs/logcentral.key"  
tls\_min\_version =\> "1.2"  
cipher\_suites =\> ['TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256', 'TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256', 'TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_GCM\_SHA384', 'TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384']  
}  
}

client is winlogbeats

output.logstash:  
hosts: ["[logstash.logcentral.com:5043](http://logstash.logcentral.com:5043)"]  
index: winlogbeat  
tls:  
certificate\_authorities: ["C:/Program Files/winlogbeats/logcentral\_com.cer"]

when I test from the client  
./winlogbeat -c winlogbeat.yml -e -v  
ERROR logstash/async.go:256 Failed to publish events caused by: lumberjack protocol error  
ERROR logstash/async.go:256 Failed to publish events caused by: client is not connected  
ERROR pipeline/output.go:121 Failed to publish events: client is not connected  
INFO pipeline/output.go:95 Connecting to backoff(async(tcp://logstash.logcentral.com:5043))  
INFO pipeline/output.go:105 Connection to backoff(async(tcp://logstash.logcentral.com:5043)) established  
ERROR logstash/async.go:256 Failed to publish events caused by: lumberjack protocol error  
ERROR logstash/async.go:256 Failed to publish events caused by: client is not connected  
ERROR pipeline/output.go:121 Failed to publish events: client is not connected  
INFO pipeline/output.go:95 Connecting to backoff(async(tcp://logstash.logcentral.com:5043))  
INFO pipeline/output.go:105 Connection to backoff(async(tcp://logstash.logcentral.com:5043)) established

and in the logstash log

```
[2018-12-04T13:07:05,788][INFO][org.logstash.beats.BeatsHandler] [local: 0.0.0.0:5043, remote: <public-ip>:60638] Handling exception: javax.net.ssl.SSLHandshakeException: error:100000f7:SSL routines:OPENSSL_internal:WRONG_VERSION_NUMBER
[2018-12-04T13:07:05,789][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: error:100000f7:SSL routines:OPENSSL_internal:WRONG_VERSION_NUMBER

```

I've tried with and without the tls: certificate\_authorities:

I'd have thought if they were public then this wouldn't be needed.

---

<div class="post-metadata">

**Author:** ![Andrew\_Griffiths](https://avatars.discourse-cdn.com/v4/letter/a/35a633/32.png) [@Andrew\_Griffiths](https://discuss.elastic.co/u/Andrew_Griffiths)\
**Post date:** [December 4, 2018, 3:42pm UTC](https://discuss.elastic.co/t/securing-beats-to-logstash-with-public-cert-version-6-5-1/159364/2 "2018-12-04T15:42:05Z")

</div>

Solved. Simply by changing winlogbeats.yml

output.logstash:  
hosts: ["[logstash.log-central.com:5043](http://logstash.log-central.com:5043)"]  
index: winlogbeat  
**bulk\_max\_size: 1024**  
**ssl.enabled: true**  
tls:  
certificate\_authorities: ["C:/Program Files/winlogbeats/logcentral\_com.cer"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 1, 2019, 3:42pm UTC](https://discuss.elastic.co/t/securing-beats-to-logstash-with-public-cert-version-6-5-1/159364/3 "2019-01-01T15:42:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
