# Ssl\_certificate\_validation not working

**URL:** <https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304>\
**Category:** Logstash\
**Created:** [April 4, 2016, 10:51pm UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304 "2016-04-04T22:51:12Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 4, 2016, 10:51pm UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/1 "2016-04-04T22:51:12Z")

</div>

ssl\_certificate\_validation =\> false is not working in HTTP\_Poller configuration.

My service URL is HTTPS but there is no need to pass any certs along with the call. Hence, I wanted to skip it.

Even with the above option enabled, it is checking for SSL certs. What can I do here ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 5, 2016, 4:23am UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/2 "2016-04-05T04:23:34Z")

</div>

What error are you getting?

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 5, 2016, 4:37am UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/3 "2016-04-05T04:37:48Z")

</div>

"error" =\> "PKIX path building failed: sun.security.provider.c  
ertpath.SunCertPathBuilderException: unable to find valid certification path to  
requested target".

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 5, 2016, 4:38am UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/4 "2016-04-05T04:38:48Z")

</div>

And what does the config look like?

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 5, 2016, 4:40am UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/5 "2016-04-05T04:40:57Z")

</div>

input  
{  
http\_poller  
{  
urls =\>  
{  
Locations =\>  
{  
method =\> Get  
url =\> "[https://zep-pt.com/WebService/api/getlocations/1234](https://zep-pt.com/WebService/api/getlocations/1234)"  
headers =\>  
{  
"Content-Type" =\> "application/json"  
}  
}  
}  
ssl\_certificate\_validation =\> false  
interval =\> 60  
codec =\> "json"  
metadata\_target =\> "http\_poller\_metadata"  
}  
}

output  
{  
stdout  
{  
codec =\> rubydebug  
}  
}

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 5, 2016, 3:05pm UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/6 "2016-04-05T15:05:27Z")

</div>

Any update on this Mark Walkom ?

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 8, 2016, 1:01am UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/7 "2016-04-08T01:01:16Z")

</div>

Can anyone provide any solution here ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 8, 2016, 1:29am UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/8 "2016-04-08T01:29:18Z")

</div>

Even though you aren't validating the cert, I am pretty sure you still need a `client_cert` path.

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 8, 2016, 1:44am UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/9 "2016-04-08T01:44:18Z")

</div>

Where should i place my pfx file and what shld i mention in the path ???

---

<div class="post-metadata">

**Author:** ![Sameer\_Panicker](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Post date:** [April 12, 2016, 5:48am UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/10 "2016-04-12T05:48:13Z")

</div>

This worked fine. I added the certificate to JRE KeyStore.

Since, logstash uses JDK env. cert needs to be installed under JDK KeyStore.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:02am UTC](https://discuss.elastic.co/t/ssl-certificate-validation-not-working/46304/11 "2017-07-06T05:02:51Z")

</div>


