# SSL config to ignore validation

**URL:** https://discuss.elastic.co/t/ssl-config-to-ignore-validation/119551
**Category:** Elasticsearch
**Created:** [February 12, 2018, 9:31pm UTC](https://discuss.elastic.co/t/ssl-config-to-ignore-validation/119551 "2018-02-12T21:31:35Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)
#### Post date: [February 12, 2018, 9:31pm UTC](https://discuss.elastic.co/t/ssl-config-to-ignore-validation/119551/1 "2018-02-12T21:31:35Z")

</div>

I want to encrypt the data from Filebeat to Logstash using SSL but I don't want to enforce validating the certificate. Is that possible? I am trying to avoid generating/buying a ssl for each filebeat host.

If I remove the client certs from the config logstash denies the connection  
Exception: javax.net.ssl.SSLHandshakeException: error:100000c0:SSL routines:OPENSSL\_internal:PEER\_DID\_NOT\_RETURN\_A\_CERTIFICATE  
I have this entry in the conf file along with the othe ssl settings.  
ssl\_verify\_mode =\> none  
Thoughts?

---

<div class="post-metadata">

### Author: ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)
#### Post date: [February 12, 2018, 11:02pm UTC](https://discuss.elastic.co/t/ssl-config-to-ignore-validation/119551/2 "2018-02-12T23:02:24Z")

</div>

I see there isn't any verification so what I'm looking for is to not provide a client key on filebeat host.  
So um nevermind? I'm now trying to hide the key file, we want to deploy filebeat at customers sites without providing the .key file. I guess I could password protect it?

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [February 13, 2018, 3:27am UTC](https://discuss.elastic.co/t/ssl-config-to-ignore-validation/119551/3 "2018-02-13T03:27:44Z")

</div>

Filebeat shouldn't need a key. You can enable TLS (SSL) on the Logstash side, without Beats needing to have its own key.

Keys are only needed if you want to use them as an authentication method between Beats and Logstash. Perhaps you want to use TLS for that, but if you do, then keys become unavoidable - that's how TLS certificate-based authentication works.

---

<div class="post-metadata">

### Author: ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)
#### Post date: [February 13, 2018, 6:03pm UTC](https://discuss.elastic.co/t/ssl-config-to-ignore-validation/119551/4 "2018-02-13T18:03:14Z")

</div>

I tried filebeat without any ssl configured and got an Exception: not an SSL/TLS record: xxxx....  
Logstash beat config,  
ssl =\> true  
ssl\_key =\> "c:\logstash\Config\logstashdev1.key"  
ssl\_certificate =\> "c:\logstash\Config\logstashdev1.crt"  
ssl\_certificate\_authorities =\> "c:\logstash\Config\ca.cer"  
ssl\_verify\_mode =\> none  
Then I tried  
protocol: "https" in filebeat.yml  
and filebeat shows, Failed to publish events caused by: client is not connected.  
Am I missing anything?  
Thanks

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [February 14, 2018, 3:32am UTC](https://discuss.elastic.co/t/ssl-config-to-ignore-validation/119551/5 "2018-02-14T03:32:39Z")

</div>

> [@GSCully](#):
>
> I tried filebeat without any ssl configured

Sorry, my previous post wasn't very clear. You definitely need to configure SSL, but you shouldn't need the key.

It looks like your logstash configuration is correct (although `ssl_certificate_authorities` is redundant since you're not using client verification).

What I suspect you're missing on the beats side is the certificate authority.  
Your filebeat configuration should look something like:

```auto
output.logstash:
  hosts: ["logstash.example.net:5044"]
  ssl.certificate_authorities: ["c:\filebeat\Config\logstash-ca.cer"]

```

---

<div class="post-metadata">

### Author: ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)
#### Post date: [February 14, 2018, 6:18pm UTC](https://discuss.elastic.co/t/ssl-config-to-ignore-validation/119551/6 "2018-02-14T18:18:05Z")

</div>

I had to remove the CA from logstash for it to work,  
I'm good to go now  
Thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 14, 2018, 6:18pm UTC](https://discuss.elastic.co/t/ssl-config-to-ignore-validation/119551/7 "2018-03-14T18:18:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
