# SSL/TLS on ELK cluster

**URL:** <https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 4, 2016, 11:30am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641 "2016-07-04T11:30:07Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 12, 2016, 11:45am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/21 "2016-07-12T11:45:58Z")

</div>

Ok let's take a few steps back and make sure that openssl can read the certificate file.

Can you run the following:

1. `openssl x509 -in cert.crt -noout -text`
2. `openssl version`

Also, if you open the crt file in a text editor, can you verify that the first line is `-----BEGIN CERTIFICATE-----` and the last line is `-----END CERTIFICATE-----`

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 12, 2016, 12:18pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/22 "2016-07-12T12:18:14Z")

</div>

PFA is the output of commands.  
If I open cert.pem then yes I do have the same lines mentioned by you.  
If I open cert.crt then it does not have those.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/d779f750251d6b90d5c57235445ce4705c1141f2.JPG)

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 12, 2016, 12:36pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/23 "2016-07-12T12:36:42Z")

</div>

Does `openssl x509 -in cert.pem -noout -text` work?

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 12, 2016, 12:51pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/24 "2016-07-12T12:51:48Z")

</div>

Here is the output -

> [root@irldxvm022 vinodar3]# openssl x509 -in cert.pem -noout -text  
> unable to load certificate  
> 139660169418568:error:0D0680A8:asn1 encoding routines:ASN1\_CHECK\_TLEN:wrong tag:tasn\_dec.c:1343:  
> 139660169418568:error:0D07803A:asn1 encoding routines:ASN1\_ITEM\_EX\_D2I:nested asn1 error:tasn\_dec.c:393:Type=X509\_CINF  
> 139660169418568:error:0D08303A:asn1 encoding routines:ASN1\_TEMPLATE\_NOEXP\_D2I:nested asn1 error:tasn\_dec.c:777:Field=cert\_info, Type=X509  
> 139660169418568:error:0906700D:PEM routines:PEM\_ASN1\_read\_bio:ASN1 lib:pem\_oth.c:83:  
> [root@irldxvm022 vinodar3]#

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 12, 2016, 1:32pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/25 "2016-07-12T13:32:07Z")

</div>

Ok this doesn't actually seem like a pem file at all.

Next commands to try:

1. `openssl pkcs7 -print_certs -in cert.pem -out cert_pem.cer`
2. `openssl x509 -in cert._pem.cer -noout -text`

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 13, 2016, 7:21am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/26 "2016-07-13T07:21:56Z")

</div>

Here is the output

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0e113de35fbb11f0cf6bb37589c45c035cd24a94.JPG) ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a05143bc1b64dd58cab6a4db8acb22d833ed2b82.JPG)

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 13, 2016, 11:48am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/27 "2016-07-13T11:48:31Z")

</div>

Try this:

1. Create a new file `single_cert.cer`
2. Open `cert_pem.cer` and copy starting at the first `-----BEGIN CERTIFICATE-----` line to the first `-----END CERTIFICATE-----` line.
3. Paste that into `single_cert.cer`
4. `openssl x509 -in single_cert.cer -noout -text`
5. `openssl pkcs12 -export -inkey irldxvm022.key -in single_cert.cer -name irldxvm022 -out irldxvm022.p12`
  1. NOTE: Make sure you use the matching key for the certificate; I simply based the values on what was previously provided

Also, is there a reason you generated the CSR with openssl and did not use the instructions in the [documentation](https://www.elastic.co/guide/en/shield/current/ssl-tls.html#private-key)?

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 13, 2016, 12:22pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/28 "2016-07-13T12:22:39Z")

</div>

Hi Jay,

Thanks, the steps you have given worked. Please let me know the next step.

Regards,  
Vinod

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 13, 2016, 12:36pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/29 "2016-07-13T12:36:26Z")

</div>

I believe these two commands should work:

> [@jaymode](#):
>
> keytool -delete -alias irldxvm022 -keystore irldxvm022.jks  
> keytool -importkeystore -srckeystore irldxvm022.p12 -srcstoretype pkcs12 -destkeystore irldxvm022.jks

After that check `keytool -list -v irldxvm022.jks` and ensure you have a `privateKeyEntry`. You may also need to import the intermediate and root CA certificates into the keystore.

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 14, 2016, 9:49am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/30 "2016-07-14T09:49:15Z")

</div>

Hi Jay,  
Thanks yes both these commands too worked. I could also import root and intermediate certificates. Now I have 3 aliases in keystore. One for private key and 2 for root and intermediate certificates.  
I did same on both nodes and configured keystore.  
Now how to crosscheck if SSL/TLS encryption between ELK node is working.

Kibana to ES and Logstash to ES configuration for SSL/TLS is also done.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 14, 2016, 11:37am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/31 "2016-07-14T11:37:02Z")

</div>

> [@vienodp](#):
>
> Now how to crosscheck if SSL/TLS encryption between ELK node is working.

You can enable DEBUG logging and you should see log messages like "SSL handshake completed for channel". Or you can use something like openssl s\_client to open a connect and see that the socket is using SSL:

```
openssl s_client -showcerts -connect localhost:9300

```

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 15, 2016, 3:37am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/32 "2016-07-15T03:37:36Z")

</div>

Ok thanks.

I have enabled Shield plugin and configured the SSL/TLS encryption. Now my kibana is not starting up.

I can see these entries in logstash logs -

> timestamp=\>"2016-07-15T13:01:51.995000+0530", :message=\>"Attempted to send a bulk request to Elasticsearch configured at '["[https://9.126.112.72:9200/\](https://9.126.112.72:9200/%5C)"]', but Elasticsearch appears to be unreachable or down!", :error\_message=\>"Connection refused", :class=\>"Manticore::SocketException", :client\_config=\>{:hosts=\>["[https://9.126.112.72:9200/](https://9.126.112.72:9200/)"], :ssl=\>{:enabled=\>true, :ca\_file=\>"/etc/logstash/cert.pem"}, :transport\_options=\>{:socket\_timeout=\>0, :request\_timeout=\>0, :proxy=\>nil, :ssl=\>{:enabled=\>true, :ca\_file=\>"/etc/logstash/cert.pem"}}, :transport\_class=\>Elasticsearch::Transport::Transport::HTTP::Manticore, :headers=\>{"Authorization"=\>"Basic dmlub2RhcjNAaW4uaWJtLmNvbTp0aWdlUkAzMjE="}, :logger=\>nil, :tracer=\>nil, :reload\_connections=\>false, :retry\_on\_failure=\>false, :reload\_on\_failure=\>false, :randomize\_hosts=\>false}, :level=\>:error

and these entries in elastcisearch logs

> [2016-07-15 14:07:25,129][WARN][shield.transport.netty] [irldxvm022] received plaintext http traffic on a https channel, closing connection [id: 0x3d9f3207, /9.126.112.35:45330 =\> /9.126.112.72:9200]

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 15, 2016, 10:19am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/33 "2016-07-15T10:19:14Z")

</div>

I don't think those messages are related. Is the `9.126.112.35` IP of the logstash instance? "Connection refused" indicates a failed connection attempt on the socket and nothing to do with ssl

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 15, 2016, 11:12am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/34 "2016-07-15T11:12:00Z")

</div>

I have 2 nodes in a cluster , 35 and 72 with ELK/Shield installed on it. Yes, those messages may not be related. But what could be the reason of connection refused where ES is working fine and listening on the required ports. I also checked with this command which gives me status as green.  
Firewall and selinux parameters also checked and those are disabled.

> curl -XGET -k -u [vinodar3@in.ibm.com](mailto:vinodar3@in.ibm.com) -p '[https://9.126.112.72:9200/\_cluster/health?pretty=true](https://9.126.112.72:9200/_cluster/health?pretty=true)'

```
[root@irldxvm022 ~]# netstat -tulpn | grep 9200
tcp 0 0 ::ffff:9.126.112.72:9200 :::* LISTEN 3573/java
tcp 0 0 fe80::250:56ff:fea0:77:9200 :::* LISTEN 3573/java
tcp 0 0 ::ffff:127.0.0.1:9200 :::* LISTEN 3573/java
tcp 0 0 ::1:9200 :::* LISTEN 3573/java
[root@irldxvm022 ~]# netstat -tulpn | grep 9300
tcp 0 0 ::ffff:9.126.112.72:9300 :::* LISTEN 3573/java
tcp 0 0 fe80::250:56ff:fea0:77:9300 :::* LISTEN 3573/java
tcp 0 0 ::ffff:127.0.0.1:9300 :::* LISTEN 3573/java
tcp 0 0 ::1:9300 :::* LISTEN 3573/java

```

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 15, 2016, 11:24am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/35 "2016-07-15T11:24:25Z")

</div>

Here is my output file -

```
output {
  elasticsearch {
    user => "vinodar3@in.ibm.com"
    password => "xyz@123"
    ssl => true
    cacert => "/etc/logstash/cert.pem"
    hosts => ["https://9.126.112.72:9200"]
    manage_template => false
    document_type => "%{[@metadata][type]}"
  }
}
```

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 15, 2016, 11:36am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/36 "2016-07-15T11:36:08Z")

</div>

I am not sure what could cause that. I think you should open a new topic in the #logstash section as things appear to be working fine on the Shield side.

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 15, 2016, 11:46am UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/37 "2016-07-15T11:46:39Z")

</div>

Ok, I will do that. But after enabling Shield plugin these things started. Kibana is not coming up and not showing anything in the logs. I have gone through the "Using Logstash with Shield" and "Using Kibana with Shield" and configured the things accordingly still no luck.

[https://discuss.elastic.co/t/logstash-es-communication-issue-and-kibana-not-coming-up/55613](https://discuss.elastic.co/t/logstash-es-communication-issue-and-kibana-not-coming-up/55613)

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 15, 2016, 12:09pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/38 "2016-07-15T12:09:39Z")

</div>

What is your kibana configuration? Most likely Kibana is still trying to use plaintext. The logstash aspect is different which is why I asked you to start a new topic

---

<div class="post-metadata">

**Author:** ![vienodp](https://avatars.discourse-cdn.com/v4/letter/v/46a35a/32.png) [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Post date:** [July 15, 2016, 12:18pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/39 "2016-07-15T12:18:17Z")

</div>

For Kibaana I am using https in ES url elasticsearch.url: "[https://9.126.112.72:9200](https://9.126.112.72:9200)" and configured the ssl.crt and ssl.key and [ssl.ca](http://ssl.ca) certificates.  
ES user name and password are LDAP user and its password.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 15, 2016, 12:45pm UTC](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641/40 "2016-07-15T12:45:53Z")

</div>

did you configure `elasticsearch.ssl.ca`?

[Previous page](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641.md?page=1)

[Next page](https://discuss.elastic.co/t/ssl-tls-on-elk-cluster/54641.md?page=3)
