# TLS connection failed because of certificate signed by unknown authority

**URL:** <https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 3, 2016, 3:20am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064 "2016-08-03T03:20:27Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![caoping](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@caoping](https://discuss.elastic.co/u/caoping)\
**Post date:** [August 3, 2016, 3:20am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/1 "2016-08-03T03:20:27Z")

</div>

Hello,  
I have spent two days in configuring filebeat TLS, and always encountered below error. Can anyone give me some tips on how to resolve this issue?

The error message in filebeat side:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/4566154ae52b79a4a777bad97dca45e0611c2828.png)

Below is the steps and configuration.

1. I generated a self-signed certificate, named ca.crt.

> openssl genrsa -out ca/ca-key.pem 1024  
> openssl req -new -out ca/ca.csr -key ca/ca.key -config openssl.cnf  
> openssl x509 -req -in ca/ca.csr -out ca/ca.crt -signkey ca/ca.key -days 365

1. generate server certificate

> _here, skipped the steps to generate server.csr and server.key file_  
> openssl x509 -req -in server/server.csr -out server/server.crt -signkey server/server.key -CA ca/ca.crt -CAkey ca/ca.key -CAcreateserial -days 365

1. generate client certificate

> _here, skipped the steps to generate client.csr and client.key file_  
> openssl x509 -req -in client/client.csr -out client/client.crt -signkey client/client.key -CA ca/ca.crt -CAkey ca/ca.key -CAcreateserial -days 365

Then I configured filebeat tls section like below:

> logstash:  
> hosts: ["newname3:5044"]  
> tls:  
> certificate\_authorities: ["/usr/ssl/ca/ca.crt"]  
> certificate: "/usr/ssl/client/client.crt"  
> certificate\_key: "/usr/ssl/client/client.key"

logstash configuration:

> input {  
> beats {  
> ssl\_certificate\_authorities =\> ["/usr/ssl/ca/ca.crt"]  
> ssl\_certificate =\> "/usr/ssl/server/server.crt"  
> ssl\_key =\> "/usr/ssl/server/server.key"  
> ssl\_verify\_mode =\> "force\_peer"  
> port =\> 5044  
> ssl =\> true  
> }  
> }

By the way, my filebeat and logstash are installed in the same virtual machine. filebeat version is 1.2.3, and logstash is 2.3.4  
I searched a lot, but didn't find an applicable solution for me. Can anyone who met this kind of issue before, or who have successfully setup filebeat TLS, give me some tips? Thank you so much.

---

<div class="post-metadata">

**Author:** ![caoping](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@caoping](https://discuss.elastic.co/u/caoping)\
**Post date:** [August 3, 2016, 10:04am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/2 "2016-08-03T10:04:16Z")

</div>

After I did some investigation, I can run "curl -v --cert ... [https://localhost:5044](https://localhost:5044)" to validate my certificate. But when starting filebeat, different error occurred.

> 2016/08/03 09:46:28.901034 transport.go:125: ERR SSL client failed to connect with: x509: certificate signed by unknown authority (possibly because of "x509: cannot verify signature: **algorithm unimplemented**" while trying to verify candidate authority certificate "My CA")

I think I made a small progress although I can't configure it successfully. Can anyone give me some tips on that issue?

By the way, below is a part of response message, hope it's helpful for trouble shooting.

> SSL connection using TLS\_DHE\_RSA\_WITH\_AES\_128\_CBC\_SHA

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [August 3, 2016, 10:43am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/3 "2016-08-03T10:43:18Z")

</div>

Did you follow the guide here? [https://www.elastic.co/guide/en/beats/filebeat/current/configuring-tls-logstash.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-tls-logstash.html)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 3, 2016, 11:31am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/4 "2016-08-03T11:31:30Z")

</div>

the error message is very interesting no? Error message says it can not read the certificate, because the algorithm used to sign the certificate is not supported by golang. What's the signature algorithm used for the certificate?

Something like  
`$ openssl x509 -in <certificate-file> -noout -text`  
should print `Signature Algorithm: ...` .

Here is a list of supposedly supported algorithms: [https://golang.org/pkg/crypto/x509/#SignatureAlgorithm](https://golang.org/pkg/crypto/x509/#SignatureAlgorithm)

---

<div class="post-metadata">

**Author:** ![caoping](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@caoping](https://discuss.elastic.co/u/caoping)\
**Post date:** [August 3, 2016, 1:59pm UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/5 "2016-08-03T13:59:58Z")

</div>

@steffens  
Thanks for your reply. Below is the algorithm used.

![](https://us1.discourse-cdn.com/elastic/original/2X/d/dee54b4a800ee21f9701d583511f23279449c167.png)

The command to generate key file is:

> openssl genrsa -des3 -out key.pem 1024

I checked the url you post, there is only **md5withrsa** , not what I used, **md5withrsaencryption**. That's probably the cause, right? If that, what I should use? Remove "-des3" option?

---

<div class="post-metadata">

**Author:** ![caoping](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@caoping](https://discuss.elastic.co/u/caoping)\
**Post date:** [August 3, 2016, 2:05pm UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/6 "2016-08-03T14:05:44Z")

</div>

Hi @ruflin,

Thanks for your reply.

Yes, I followed the guide that you mentioned. The certificate\_authority in filebeat and logstash configuration, is the self-signed root CA. Also, I used that root ca to sign the filebeat certificate and logstash certificate.

I'm trying to not encrypt the generated key. Hope it works. Any update, I'll post here. Thank you again.

---

<div class="post-metadata">

**Author:** ![caoping](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@caoping](https://discuss.elastic.co/u/caoping)\
**Post date:** [August 3, 2016, 2:19pm UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/7 "2016-08-03T14:19:01Z")

</div>

Hi @steffens, I tried to generate key file without "-des3" option, then use this key file to generate my root ca. However, the algorithm printed is still the same, "md5withrsaencryption". How can I change the algorithm? And my direction is correct?

---

<div class="post-metadata">

**Author:** ![caoping](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@caoping](https://discuss.elastic.co/u/caoping)\
**Post date:** [August 4, 2016, 3:14am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/8 "2016-08-04T03:14:51Z")

</div>

Hi @steffens

Can I use keytool to generate certificate?

I just had a try, and found the signature algorithm used without the "Encryption" suffix. I didn't find how to change the signature algorithm when using openssl, and it always use the algorithms with "Encryption" suffix, which are not supported by Golang, per the link you posted.

---

<div class="post-metadata">

**Author:** ![caoping](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@caoping](https://discuss.elastic.co/u/caoping)\
**Post date:** [August 4, 2016, 9:30am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/9 "2016-08-04T09:30:55Z")

</div>

Hi @ruflin

Still not work. I followed the guide you mentioned to configure filebeat and logstash. But when validating certificate, the curl command listed there doesn't work for me. Finally, I used below command, and it seems the validation succeeded.

> curl -v --cert /mycert.pem --key /mycertkey.pem [https://localhost:5044](https://localhost:5044)

This is results of above command:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/ca830ae9c086e18198b745e84379f1fa662a6a84.png)

However, it still failed when starting filebeat after above validation. The error message is "signature algorithm unimplemented". By looking into the certificate, it said the algorithm is " **MD5WithRsaEncryption**".

I'd like to know if that's a supported algorithm. If not, how can I change it to a supported one? I didn't find how to change it when using openssl.

This TLS issue really blocked me for several days. Any further suggestion is really appreciated. Thanks a lot!

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [August 8, 2016, 10:39am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/10 "2016-08-08T10:39:44Z")

</div>

As far as I know we support the algorithm supported by Golang. The list can be found here: [https://golang.org/pkg/crypto/x509/#SignatureAlgorithm](https://golang.org/pkg/crypto/x509/#SignatureAlgorithm) There seems to be a MD5WithRSA in the list. Perhaps @andrewkroh has some more ideas here?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 8, 2016, 1:07pm UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/11 "2016-08-08T13:07:32Z")

</div>

This is probably unrelated to the problem, but the first thing I noticed is that you are using MD5. Use SHA256 instead. Most people stopped using MD5 years ago. [https://www.kb.cert.org/vuls/id/836068](https://www.kb.cert.org/vuls/id/836068)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 8, 2016, 1:33pm UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/12 "2016-08-08T13:33:28Z")

</div>

I'm a little confused about this line:

```auto
$ curl -v --cert /mycert.pem --key /mycertkey.pem https://localhost:5044

```

Our integration tests use a self-signed certificate only. Can you test this approach first, before adding a CA to the picture?  
See [gencerts.sh](https://github.com/elastic/beats/blob/master/testing/environments/docker/logstash/gencerts.sh) from you logstash integration tests, on how a self-signed certificate for testing is created. The testing hostname is `logstash`. Change `-subj '/CN=logstash/'` to your hostname in use. See [logstash input config](https://github.com/elastic/beats/blob/master/testing/environments/docker/logstash/logstash.conf.2.tmpl#L1) using the generated certificate.

If this works, let's continue with server certificate + CA only (no client authentication).

---

<div class="post-metadata">

**Author:** ![caoping](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@caoping](https://discuss.elastic.co/u/caoping)\
**Post date:** [August 9, 2016, 5:34am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/13 "2016-08-09T05:34:25Z")

</div>

Hi @steffens

I generated a certificate for logstash server referring to _[gencerts.sh](http://gencerts.sh)_, and also added it in the logstash config, like below.  
`input { beats { ssl_certificate => "/etc/pki/tls/certs/logstash.crt" ssl_key => "/etc/pki/tls/private/logstash.key" port => 5044 ssl => true } }`  
But I don't know how to configure filebeat. Should I enable `tls` in logstash output?

---

<div class="post-metadata">

**Author:** ![caoping](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@caoping](https://discuss.elastic.co/u/caoping)\
**Post date:** [August 9, 2016, 6:45am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/14 "2016-08-09T06:45:31Z")

</div>

Hi @steffens,

I enabled `tls` section, like this. Same .crt and .key files with logstash configuration as filebeat and logstash are installed in the same VM.

```auto
 tls:
      certificate_authorities: ["/etc/pki/tls/certs/logstash.crt"]
      certificate: "/etc/pki/tls/certs/logstash.crt"
      certificate_key: "/etc/pki/tls/private/logstash.key"

```

It's a good news that no error log when starting filebeat. But also no log showing it's using encrypted way to communicate with logstash. Does it mean it's working?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 9, 2016, 10:44am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/15 "2016-08-09T10:44:35Z")

</div>

As config according to gencerts.sh is using a self-signed certificate only with client only validating server this config is enough:

```auto
 tls:
      certificate_authorities: ["/etc/pki/tls/certs/logstash.crt"]

```

The key file is required to parse the private part of a certificate.

Right, there is no log message if encryption is used. But I think it's a great idea to print some connection information if TLS is used. I created this ticket to implement some logs: [INFO log if TLS is used · Issue #2198 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/2198)

If all you want is encryption, you can stop here, but this is far from the initial solution. You have had a CA + client authentication. In case you just need client authentication you can create a self-signed client certificate just as you did for logstash. Given we name the files filebeat.crt and filebeat.key your config will look like:

logstash.conf:

```auto
input {
   beats {
      port => 5044
      ssl => true
      ssl_certificate => "/etc/pki/tls/certs/logstash.crt"
      ssl_key => "/etc/pki/tls/private/logstash.key"
      ssl_certificate_authorities => ["/etc/pki/tls/certs/filebeat.crt"]
      ssl_verify_mode => "force_peer"
    }
}

```

and filebeat.yml:

```auto
    tls:
      certificate: "/etc/pki/tls/certs/filebeat.crt"
      certificate_key: "/etc/pki/client/filebeat.key"
      certificate_authorities: ["/etc/pki/tls/certs/logstash.crt"]

```

As you can see, it becomes very cumbersome to add many more certificates for additional filebeat instances. This is where a CA comes into play.

Next let's add a CA (certificate authority) and a server certificate only. For example see [this guide](https://jamielinux.com/docs/openssl-certificate-authority/index.html) (I haven't tested this myself, though). As explained in the guide, it's good practice to create intermediate signing CAs. Unfortunately there's a bug in SSL libs loading intermediate CAs. From docs:

> Although intermediate CAs are currently not supported, you may be able to work around this issue by merging all the certificates in the chain into one file. You can create the PEM file containing the CA chain by concatenating the root CA cert and the intermediate CA into a single file: cat root-ca.crt intermediate-ca.crt \> chain.crt. Then set certificate\_authorities to use this file: certificate\_authorities: ['chain.crt'].

See [beats-\>logstash TLS docs](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-tls-logstash.html)

---

<div class="post-metadata">

**Author:** ![caoping](https://avatars.discourse-cdn.com/v4/letter/c/aca169/32.png) [@caoping](https://discuss.elastic.co/u/caoping)\
**Post date:** [August 11, 2016, 9:32am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/16 "2016-08-11T09:32:50Z")

</div>

All I want is encrypted communication between filebeat and logstash. So the configuration you provided is enough, right? If yes, that's great. Thank you so much.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 11, 2016, 10:48am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/17 "2016-08-11T10:48:05Z")

</div>

Yes, this config is enough for encrypted traffic, only. Without client authentication, any client can connect and push events though.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2016, 3:20am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064/18 "2016-08-24T03:20:28Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
