# Tcp over SSL error message

**URL:** <https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303>\
**Category:** Logstash\
**Created:** [March 2, 2016, 8:17pm UTC](https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303 "2016-03-02T20:17:59Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 2, 2016, 8:18pm UTC](https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303/1 "2016-03-02T20:18:00Z")

</div>

I'm attempting to receive syslog events that are being sent over SSL/TLS. I'm using the post at [https://groups.google.com/forum/#!topic/logstash-users/PcR0it4wiK0](https://groups.google.com/forum/#!topic/logstash-users/PcR0it4wiK0) as an example.

```
input{
    tcp{
        port => 7007
        ssl_enable => true
        ssl_cacert => "/tmp/ca.crt"
        ssl-cert => "/tmp/mycert.crt"
        ssl_key => "/tmp/mykey.pem"
        ssl_key_passphrase => "secret"
    }
}
filter{
    grok...
}
output{
    stdout{codec=>rubydebug}
}

```

Configtest comes back OK but when I run I get this error:

`Could not initialize SSL context {:exception=>#<OpenSSL::PKey::RSAError: Neither PUB key nor PRIV key:> :backtrace=>["org/jruby/ext/openssl/PKeyRSA.java:277:in 'initialize'", etc.`

Anyone know what I'm doing wrong?

Craig

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 3, 2016, 3:26pm UTC](https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303/2 "2016-03-03T15:26:11Z")

</div>

bump bump

---

<div class="post-metadata">

**Author:** ![ndrost](https://avatars.discourse-cdn.com/v4/letter/n/c6cbf5/32.png) [@ndrost](https://discuss.elastic.co/u/ndrost)\
**Post date:** [March 7, 2016, 5:05pm UTC](https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303/3 "2016-03-07T17:05:13Z")

</div>

Are you sure the ssl\_key =\> "/tmp/mykey.pem" only contains your SSL key?

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 7, 2016, 5:54pm UTC](https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303/4 "2016-03-07T17:54:47Z")

</div>

Hi Nick, thanks for responding. I'm kind of new at this certificate business but I did have help from a local guru who's set up multiple java systems. There were a series of events leading up to the .pem file:

1. using java keytool, created a .jks
2. using java keytool, imported certificate authorities into .jks
3. using java keytool, created and submitted a certificate request .csr
4. received certificate .cer and imported it using java keytool into .jks
5. using java keytool, exported .jks to .p12
6. using openssl, I exported .p12 to .pem. So the .pem includes my server's private key and certificates for my server and CAs.
7. using notepad, I copied private key text from .pem to mykey.key.
8. using notepad, I copied certificate text to mycert.crt

I tried setting in the tcp input configuration's "ssl\_key" option both the .pem with it's multiple components and the mykey.key. On a whim I tried renaming mykey.key to mykey.pem and tried it. In all cases I received the error "Neither PUB key nor PRIV key" on logstash startup.

---

<div class="post-metadata">

**Author:** ![ndrost](https://avatars.discourse-cdn.com/v4/letter/n/c6cbf5/32.png) [@ndrost](https://discuss.elastic.co/u/ndrost)\
**Post date:** [March 7, 2016, 10:41pm UTC](https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303/5 "2016-03-07T22:41:00Z")

</div>

> [@CraigFoote](#):
>
> 1. using notepad, I copied private key text from .pem to mykey.key.

I do not see this referenced in your example above.

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 8, 2016, 1:57pm UTC](https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303/6 "2016-03-08T13:57:09Z")

</div>

In the example above I listed mykey.pem because that's what was used on [https://groups.google.com/forum/#!topic/logstash-users/PcR0it4wiK0](https://groups.google.com/forum/#!topic/logstash-users/PcR0it4wiK0). It gave me the "Neither PUB key nor PRIV key" so I started trying other things, one of which was the private encrypted key from the pem file saved as mykey.key. It gave me the same error.

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 11, 2016, 1:38pm UTC](https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303/7 "2016-03-11T13:38:09Z")

</div>

Any ideas @ndrost ?

---

<div class="post-metadata">

**Author:** ![CraigFoote](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/craigfoote/32/4571_2.png) [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Post date:** [March 15, 2016, 2:29pm UTC](https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303/8 "2016-03-15T14:29:25Z")

</div>

bump bump

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/tcp-over-ssl-error-message/43303/9 "2017-07-06T05:06:54Z")

</div>


