# SSL certificate in email output plugin logstash

**URL:** <https://discuss.elastic.co/t/ssl-certificate-in-email-output-plugin-logstash/273450>\
**Category:** Logstash\
**Created:** [May 19, 2021, 9:29pm UTC](https://discuss.elastic.co/t/ssl-certificate-in-email-output-plugin-logstash/273450 "2021-05-19T21:29:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jrojasp95](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jrojasp95/32/88988_2.png) [@jrojasp95](https://discuss.elastic.co/u/jrojasp95)\
**Post date:** [May 19, 2021, 9:29pm UTC](https://discuss.elastic.co/t/ssl-certificate-in-email-output-plugin-logstash/273450/1 "2021-05-19T21:29:53Z")

</div>

Hi I am trying to use the email output plugin in logstash but I can't get it to work on the server with docker, on localhost it works with port 587 but on the server I get an OpenSSL hostname not match with ssl certificate error, any idea of where should I put the certificate for the email

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 19, 2021, 9:52pm UTC](https://discuss.elastic.co/t/ssl-certificate-in-email-output-plugin-logstash/273450/2 "2021-05-19T21:52:07Z")

</div>

This is telling you that the server hostname/ip you are using doesn't match the CN or SAN on the certificate. I would use what's on the cert or if possible update the SANs on the cert.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 19, 2021, 10:03pm UTC](https://discuss.elastic.co/t/ssl-certificate-in-email-output-plugin-logstash/273450/3 "2021-05-19T22:03:21Z")

</div>

The logstash email output is a wrapper around [mail](https://github.com/mikel/mail). The smtp delivery module for that notes that

> When using TLS, some mail servers provide certificates that are self-signed or whose names do not exactly match the hostname given in the address. OpenSSL will reject these by default. The best remedy is to use the correct hostname or update the certificate authorities trusted by your ruby.

It then goes on to note that

> If that isn't possible, you can control this behavior with an :openssl\_verify\_mode setting.

That is only true if you are calling mail directly, the email output does not provide a way to set mail options.

---

<div class="post-metadata">

**Author:** ![jrojasp95](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jrojasp95/32/88988_2.png) [@jrojasp95](https://discuss.elastic.co/u/jrojasp95)\
**Post date:** [May 19, 2021, 10:11pm UTC](https://discuss.elastic.co/t/ssl-certificate-in-email-output-plugin-logstash/273450/4 "2021-05-19T22:11:02Z")

</div>

Thanks for answering, this is the output plugin configuration

output {  
stdout {  
codec =\> rubydebug  
}  
email {

```
	to => "jrojasp@grupoasd.com.co"
	subject => "pruebacorreo"
	htmlbody => "<html><>"
	domain => "papiro.grupoasd.com.co"
	address => "10.0.4.106"
	port => 587
	use_tls => true
	username => "notificaciones.prueba@prueba.com.co"
	password => 123456"

}

```

}

---

<div class="post-metadata">

**Author:** ![jrojasp95](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jrojasp95/32/88988_2.png) [@jrojasp95](https://discuss.elastic.co/u/jrojasp95)\
**Post date:** [May 19, 2021, 10:20pm UTC](https://discuss.elastic.co/t/ssl-certificate-in-email-output-plugin-logstash/273450/5 "2021-05-19T22:20:38Z")

</div>

Uploading: image.png...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2021, 10:20pm UTC](https://discuss.elastic.co/t/ssl-certificate-in-email-output-plugin-logstash/273450/6 "2021-06-16T22:20:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
