# SSL communication fails btw Filebeat (5.1.1) and Logstash (5.1.1)

**URL:** https://discuss.elastic.co/t/ssl-communication-fails-btw-filebeat-5-1-1-and-logstash-5-1-1/80123
**Category:** Logstash
**Created:** [March 27, 2017, 11:03am UTC](https://discuss.elastic.co/t/ssl-communication-fails-btw-filebeat-5-1-1-and-logstash-5-1-1/80123 "2017-03-27T11:03:37Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Gaurav\_Tandon](https://avatars.discourse-cdn.com/v4/letter/g/439d5e/32.png) [@Gaurav\_Tandon](https://discuss.elastic.co/u/Gaurav_Tandon)
#### Post date: [March 27, 2017, 11:03am UTC](https://discuss.elastic.co/t/ssl-communication-fails-btw-filebeat-5-1-1-and-logstash-5-1-1/80123/1 "2017-03-27T11:03:37Z")

</div>

Getting below error in Logstash when filebeat tries to publish logs to Logstash

```auto
“Looks like you either have an invalid key or your private key was not in PKCS8 format.”

```

I followed guidelines in the docs:  
[https://www.elastic.co/guide/en/beats/filebeat/5.1/configuration-output-ssl.html](https://www.elastic.co/guide/en/beats/filebeat/5.1/configuration-output-ssl.html)

I have copied the SSL certs with Server authentication on all the Logstash nodes

- The certificates contains subject alternative names (SAN) that correspond to the dns names of all the logstash nodes

```auto
   port => 5044
    ssl => true
    ssl_certificate_authorities => ["/etc/logstash/ssl/ca.crt"]
    ssl_certificate => "/etc/logstash/ssl/server.crt"
    ssl_key => "/etc/logstash/ssl/server.key"
    ssl_verify_mode => "force_peer"

```

and  
I have also copied the SSL certs with client authentication, where filebeat is installed .

- The certificate contains the CNAME that correspond to the dns names of the application server where filebeat is installed.

```auto
output.logstash:
  ssl.enabled: true
  ssl.verification_mode: full
  ssl.certificate_authorities: ["/etc/pki/root/ca.crt"]
  ssl.certificate: "/etc/pki/client/cert.crt"
  ssl.key: "/etc/pki/client/cert.key"

```

All the certs are signed by common CA.

They are in PEM format.

Any advice, what could be missing or wrong here.?

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [March 27, 2017, 11:36am UTC](https://discuss.elastic.co/t/ssl-communication-fails-btw-filebeat-5-1-1-and-logstash-5-1-1/80123/2 "2017-03-27T11:36:58Z")

</div>

I suspect your private key is not in the PKCS8 format, you can convert it with [OpenSSL](https://www.openssl.org/docs/man1.1.0/apps/pkcs8.html).

---

<div class="post-metadata">

### Author: ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)
#### Post date: [March 27, 2017, 2:47pm UTC](https://discuss.elastic.co/t/ssl-communication-fails-btw-filebeat-5-1-1-and-logstash-5-1-1/80123/3 "2017-03-27T14:47:40Z")

</div>

Try the following command:

`openssl pkcs8 -in privatekey.key -topk8 -nocrypt -out privatekey.p8`

Later, set the .p8 file as your new key on the ssl\_key field in Logstash configuration file for Beats. This was the way I could make Logstash receive data from Filebeat on my set.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 24, 2017, 2:47pm UTC](https://discuss.elastic.co/t/ssl-communication-fails-btw-filebeat-5-1-1-and-logstash-5-1-1/80123/4 "2017-04-24T14:47:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
