# Setup\_ssl error

**URL:** <https://discuss.elastic.co/t/setup-ssl-error/336840>\
**Category:** Logstash\
**Created:** [June 25, 2023, 4:01pm UTC](https://discuss.elastic.co/t/setup-ssl-error/336840 "2023-06-25T16:01:01Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lampros](https://avatars.discourse-cdn.com/v4/letter/l/b782af/32.png) [@Lampros](https://discuss.elastic.co/u/Lampros)\
**Post date:** [June 25, 2023, 4:01pm UTC](https://discuss.elastic.co/t/setup-ssl-error/336840/1 "2023-06-25T16:01:02Z")

</div>

Hello,

I am a little bit lost on this topic.  
I have a container which is running logstash.

What I am trying to do is to use the output syslog module to send logs to a third party application over ssl.  
But it fails with this error =\>

```auto
Pipeline error {:pipeline_id=>"main", :exception=>#<TypeError: no implicit conversion of nil into String>, :
backtrace=>[
  "org/jruby/RubyIO.java:3774:in `read'", 
  "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-syslog-3.0.5/lib/logstash/outputs/syslog.rb:229:in `setup_ssl'", 
  "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-syslog-3.0.5/lib/logstash/outputs/syslog.rb:132:in `register'", 
  "org/logstash/config/ir/compiler/OutputStrategyExt.java:131:in `register'", 
  "org/logstash/config/ir/compiler/AbstractOutputDelegatorExt.java:68:in `register'", 
  "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:232:in `block in register_plugins'", 
  "org/jruby/RubyArray.java:1821:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:231:in `register_plugins'", 
  "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:589:in `maybe_setup_out_plugins'", 
  "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:244:in `start_workers'", 
  "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:189:in `run'", 
  "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:141:in `block in start'"],

```

my current configuration for this plugin look like this =\>

```auto
 output {
     syslog {
       host => "qradar.blooding.com"
       port => "6514"
       protocol => "ssl-tcp"
       appname => "LOGSTASH-AnsibleTower"
       sourcehost => "AT-Host"
     }

```

If I leave the protocol to the default "udp" value is not crashing.  
And the certificate CA and intermediate CA are already inside the container and you can list them with  
`trust list --filter=ca-anchors`  
for instance.

I have tried many things.  
I was checking the documentation from [here](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-syslog.html).

I have tried to provide the qRadar certificate by trying various combinations of the following option  
ssl\_cacert  
ssl\_cert  
ssl\_verify

but to my understanding these properties are not meant to be for qRadar.  
So, my question is, how to send the logs to qRadar over ssl? How the output.syslog should look like and where should I trust the qRadar certificate?

Thank you in advance for your time to read this.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2023, 6:38pm UTC](https://discuss.elastic.co/t/setup-ssl-error/336840/2 "2023-06-25T18:38:15Z")

</div>

> [@Lampros](#):
>
> ```auto
> backtrace=>[
> "org/jruby/RubyIO.java:3774:in `read'", 
> "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-syslog-3.0.5/lib/logstash/outputs/syslog.rb:229:in `setup_ssl'", 
> 
> ```

If you set protocol to "ssl-tcp" then ssl\_cert is a mandatory option. The code reads the cert [here](https://github.com/logstash-plugins/logstash-output-syslog/blob/30b8f9130878595ab87dfa0fbd4b8f04b0ed7139/lib/logstash/outputs/syslog.rb#L229) and it is getting that exception because ssl\_cert is nil. Looking at the next line of code I imagine ssl\_key and ssl\_key\_passphrase are also mandatory.

[This](https://github.com/logstash-plugins/logstash-output-syslog/issues/42) issue has a possible patch.

---

<div class="post-metadata">

**Author:** ![Lampros](https://avatars.discourse-cdn.com/v4/letter/l/b782af/32.png) [@Lampros](https://discuss.elastic.co/u/Lampros)\
**Post date:** [June 25, 2023, 8:59pm UTC](https://discuss.elastic.co/t/setup-ssl-error/336840/3 "2023-06-25T20:59:13Z")

</div>

Hello Badger,

thank you for your reply.

I have seen the links you have shared already.

My main set of questions remains the same =\>

- How to send the logs to qRadar over ssl?
- How the output.syslog should look like and
- Where should I trust the qRadar certificate?

Moreover, I am trying to understand what is the purpose of the protocol option inside output.syslog. Do I need it in order to send logs over ssl to qRadar?  
Where in the git code is visible that when protocol = ssl-tcp the other properties are required?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2023, 9:27pm UTC](https://discuss.elastic.co/t/setup-ssl-error/336840/4 "2023-06-25T21:27:45Z")

</div>

> [@Lampros](#):
>
> Moreover, I am trying to understand what is the purpose of the protocol option inside output.syslog. Do I need it in order to send logs over ssl to qRadar?  
> Where in the git code is visible that when protocol = ssl-tcp the other properties are required?

Setting protocol to "ssl-tcp" enables ssl over the tcp connection to syslog. That is checked [here](https://github.com/logstash-plugins/logstash-output-syslog/blob/30b8f9130878595ab87dfa0fbd4b8f04b0ed7139/lib/logstash/outputs/syslog.rb#L199), and a dozen lines later it triggers the creation of an OpenSSL::SSL::SSLSocket.

When the plugin is initialized the SSL context is created. [During](https://github.com/logstash-plugins/logstash-output-syslog/blob/30b8f9130878595ab87dfa0fbd4b8f04b0ed7139/lib/logstash/outputs/syslog.rb#L229) that creation the client certificate (not the server certificate) is unconditionally loaded, followed by the unconditional attempt to load the private key file.

I was shocked to find that the default value for ssl\_verify is false, so it does not, by default, validate the server certificate that it receives. If you set ssl\_verify to true then you also need to set the ssl\_cacert option to either a file or a directory that contains the CA cert chain of the syslog server certificate.

If qRadar is not expecting a client certificate then I do not know what it will do when it sees one.

---

<div class="post-metadata">

**Author:** ![Lampros](https://avatars.discourse-cdn.com/v4/letter/l/b782af/32.png) [@Lampros](https://discuss.elastic.co/u/Lampros)\
**Post date:** [June 25, 2023, 9:53pm UTC](https://discuss.elastic.co/t/setup-ssl-error/336840/5 "2023-06-25T21:53:03Z")

</div>

Hello Badger,

to be honest I do not understand how exactly this  
def ssl?  
definition is forcing the  
def setup\_ssl  
definition, but that's ok, I am not aware of ruby inner mechanics.  
So, it is not important. Thank you for pointing it out though.

I am not sure if I was able to follow exactly what you said.  
Do I need the protocol = ssl-tcp or not after all?  
How exactly should I set up my configuration in order to be able to send over ssl my logs to qRadar and where should I trust qRadar's certificate?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2023, 1:42am UTC](https://discuss.elastic.co/t/setup-ssl-error/336840/6 "2023-06-26T01:42:49Z")

</div>

If you want to use tls then you must set `protocol =\> "ssl-tcp". If you do that you must create a _client_ certificate and set the ssl\_cert, ssl\_key, and ssl\_key\_passphrase options to allow the output to load the client certificate and its key.

---

<div class="post-metadata">

**Author:** ![Lampros](https://avatars.discourse-cdn.com/v4/letter/l/b782af/32.png) [@Lampros](https://discuss.elastic.co/u/Lampros)\
**Post date:** [June 26, 2023, 6:07am UTC](https://discuss.elastic.co/t/setup-ssl-error/336840/7 "2023-06-26T06:07:57Z")

</div>

Hello Badger,

let me recap.  
There is a qRadar server that is listening on a ssl port.  
qRadar is the server I am the client (syslog in this case).  
I want to establish an ssl communication between syslog and qRadar.  
Why on earth syslog needs to have its own certificate? qRadar is accepting all incoming traffic, no need to authenticate.  
What am I missing here?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2023, 3:41pm UTC](https://discuss.elastic.co/t/setup-ssl-error/336840/8 "2023-06-26T15:41:57Z")

</div>

> [@Lampros](#):
>
> What am I missing here?

The output was written so that it requires a client certficate, but doesn't bother to verify the server certificate. It's absolutely bizarre, but that's how it was written. As I mentioned, there is a patch available that fixes that if you want to build the code yourself.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2023, 3:42pm UTC](https://discuss.elastic.co/t/setup-ssl-error/336840/9 "2023-07-24T15:42:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
