# SSL from filebeat to Kafka

**URL:** <https://discuss.elastic.co/t/ssl-from-filebeat-to-kafka/98105>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 23, 2017, 4:07pm UTC](https://discuss.elastic.co/t/ssl-from-filebeat-to-kafka/98105 "2017-08-23T16:07:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![venky1987](https://avatars.discourse-cdn.com/v4/letter/v/e56c9b/32.png) [@venky1987](https://discuss.elastic.co/u/venky1987)\
**Post date:** [August 23, 2017, 4:07pm UTC](https://discuss.elastic.co/t/ssl-from-filebeat-to-kafka/98105/1 "2017-08-23T16:07:45Z")

</div>

I could see the below note in the link: [https://www.elastic.co/guide/en/beats/filebeat/current/securing-communication-elasticsearch.html](https://www.elastic.co/guide/en/beats/filebeat/current/securing-communication-elasticsearch.html)

For any given connection, the SSL/TLS certificates must have a subject that matches the value specified for hosts, or the SSL handshake fails. For example, if you specify hosts: ["foobar:9200"], the certificate MUST include foobar in the subject (CN=foobar) or as a subject alternative name (SAN). Make sure the hostname resolves to the correct IP address. If no DNS is available, then you can associate the IP address with your hostname in /etc/hosts (on Unix) or C:\Windows\System32\drivers\etc\hosts (on Windows).

Does this hold good for Kafka as well. If this is so, could you please explain why it will needed?

Thanks

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 24, 2017, 12:34pm UTC](https://discuss.elastic.co/t/ssl-from-filebeat-to-kafka/98105/2 "2017-08-24T12:34:03Z")

</div>

This note is general about SSL/TLS certificates and not specific to Filebeat or Elasticsearch. This is how certificates work. So it is true for Kafka as well.

So it means, if you want to secure the connection to your Kafka server, you have to configure your Kafka output to use SSL. Just like you would do for other outputs.

For example:

```auto
output.kafka:
  # [...your fields ...]
  ssl.certificate_authorities:
    - /etc/pki/my_root_ca.pem
    - /etc/pki/my_other_ca.pem
  ssl.certificate: "/etc/pki/client.pem"
  ssl.key: "/etc/pki/key.pem"

```

Here is the docs on how to configure SSL for Kafka output: [https://www.elastic.co/guide/en/beats/filebeat/master/kafka-output.html#\_literal\_ssl\_literal\_3](https://www.elastic.co/guide/en/beats/filebeat/master/kafka-output.html#_literal_ssl_literal_3)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2017, 12:34pm UTC](https://discuss.elastic.co/t/ssl-from-filebeat-to-kafka/98105/3 "2017-09-21T12:34:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
