# SSL: routines:OPENSSL\_internal:WRONG\_VERSION\_NUMBER

**URL:** <https://discuss.elastic.co/t/ssl-routineswrong-version-number/158019>\
**Category:** Elasticsearch\
**Created:** [November 23, 2018, 1:35pm UTC](https://discuss.elastic.co/t/ssl-routineswrong-version-number/158019 "2018-11-23T13:35:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yashwant\_Shettigar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yashwant_shettigar/32/47652_2.png) [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Post date:** [November 23, 2018, 1:35pm UTC](https://discuss.elastic.co/t/ssl-routineswrong-version-number/158019/1 "2018-11-23T13:35:32Z")

</div>

I just restarted elasticsearch service and everything has stopped working.

Below is the output that I get for : curl -XGET '[http://localhost:9200/filebeat-\*/\_search?pretty](http://localhost:9200/filebeat-*/_search?pretty)'

Connection refused
# Connection refused

* * *
**Description: Connection refused**
* * *

And this output I'm getting in logstash plain log :

[2018-11-23T09:32:42,476][INFO][org.logstash.beats.BeatsHandler] [local: 0.0.0.0:5044, remote: 10.193.151.30:63155] Handling exception: javax.net.ssl.SSLHandshakeException: error:100000f7:SSL routines:OPENSSL\_internal:WRONG\_VERSION\_NUMBER  
[2018-11-23T09:32:42,476][WARN][io.netty.channel.DefaultChannelPipeline] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.  
io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: error:100000f7:SSL routines:OPENSSL\_internal:WRONG\_VERSION\_NUMBER

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 26, 2018, 12:15am UTC](https://discuss.elastic.co/t/ssl-routineswrong-version-number/158019/2 "2018-11-26T00:15:08Z")

</div>

Those 2 errors look like they problaby have different causes.

> [@Yashwant\_Shettigar](#):
>
> Connection refused

It seems that your elasticsearch node isn't actually running.  
Check the logs.

> [@Yashwant\_Shettigar](#):
>
> org.logstash.beats.BeatsHandler

This seems to be a problem with Beats connecting to Logstash.  
It seems that Beats and Logstash cannot agree on a SSL/TLS version to use. Did something get upgraded recently, or was a config changed?

---

<div class="post-metadata">

**Author:** ![Yashwant\_Shettigar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yashwant_shettigar/32/47652_2.png) [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Post date:** [November 26, 2018, 7:00am UTC](https://discuss.elastic.co/t/ssl-routineswrong-version-number/158019/3 "2018-11-26T07:00:34Z")

</div>

Hi Tim,

The only thing that I did, restarted elasticsearch service and this happened. Now, all of sudden this URL gives me positive output : curl -XGET '[http://localhost:9200/filebeat-\*/\_search?pretty](http://localhost:9200/filebeat-*/_search?pretty)'

But, I'm still getting " [SSL: routines:OPENSSL\_internal:WRONG\_VERSION\_NUMBER](https://discuss.elastic.co/t/ssl-routineswrong-version-number/158019)" this error.

Also, there is one more issue where I need your help. Somehow I'm only able to send logs from one client machine. As soon as I add the setup for second client, the first client would stop sending the logs, but second client would send the data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2018, 7:00am UTC](https://discuss.elastic.co/t/ssl-routineswrong-version-number/158019/4 "2018-12-24T07:00:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
