# ●\[TLS\] Question: Secure communication between Winlogbeat/ElasticSearch causes an error

**URL:** <https://discuss.elastic.co/t/tls-question-secure-communication-between-winlogbeat-elasticsearch-causes-an-error/350898>\
**Category:** Beats\
**Tags:** elastic-stack-security, winlogbeat\
**Created:** [January 12, 2024, 3:11am UTC](https://discuss.elastic.co/t/tls-question-secure-communication-between-winlogbeat-elasticsearch-causes-an-error/350898 "2024-01-12T03:11:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![YUUTA.INOUE-JPN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuuta.inoue-jpn/32/117963_2.png) [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Post date:** [January 12, 2024, 3:11am UTC](https://discuss.elastic.co/t/tls-question-secure-communication-between-winlogbeat-elasticsearch-causes-an-error/350898/1 "2024-01-12T03:11:30Z")

</div>

I am configuring "Elastic Stack" using a self-signed certificate.  
Secure communication between Elasticsearch worked fine, but  
Secure communication between Winlogbeat/Elasticsearch will result in an error.

Please teach me the "series of tasks" as specifically as possible, such as the certificate-related files and settings that should be kept on the Windows side.

▼ERROR Details

```auto
ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch(https://xxx.xxx.xxx.xxx:9200)): Get https://xxx.xxx.xxx.xxx:9200: x509: certificate signed by unknown authority

```

▼Setting parameters for “output.elasticsearch” in “winlogbeat.yml” (excerpt)

```auto

output.elasticsearch:
  hosts: ["xxx.xxx.xxx.xxx:9200", "xxx.xxx.xxx.xxx:9200", "xxx.xxx.xxx.xxx:9200"]
  protocol: "https"
  api_key: "id:api_key"

```

▼“winlogbeat.exe test config” execution command on Windows

```auto
.\winlogbeat.exe test config -c .\winlogbeat.yml -e

```

▼Execution results of "winlogbeat.exe test config" command on Windows

```auto
Config OK

```

▼“winlogbeat.exe” execution command on Windows

```auto
.\winlogbeat.exe -c .\winlogbeat.yml -e

```

▼Execution results of the “winlogbeat.exe” command on Windows

```auto
ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch(https://xxx.xxx.xxx.xxx:9200)): Get https://xxx.xxx.xxx.xxx:9200: x509: certificate signed by unknown authority
INFO pipeline/output.go:93 Attempting to reconnect to backoff(elasticsearch(https://xxx.xxx.xxx.xxx:9200)) with 3 reconnect attempt(s)

```

My environment is as below

```auto
The server OS uses Ubuntu
Elasticsearch8.11 is configured redundantly with 3 units.
Winlogbeat is using 8.11

```

Please help me  
regards

Thank you

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 12, 2024, 3:20am UTC](https://discuss.elastic.co/t/tls-question-secure-communication-between-winlogbeat-elasticsearch-causes-an-error/350898/2 "2024-01-12T03:20:45Z")

</div>

Hi @YUUTA.INOUE-JPN

First try

```auto
output.elasticsearch:
  hosts: ["xxx.xxx.xxx.xxx:9200", "xxx.xxx.xxx.xxx:9200", "xxx.xxx.xxx.xxx:9200"]
  protocol: "https"
  api_key: "id:api_key"
  ssl.verification_mode: "none"

```

Set that and test output

`.\winlogbeat.exe test output -c .\winlogbeat.yml -e`

If that works then you will need to get the CA or trusted fingerprint from elasticsearch and set that l

Take a look at

> **[Start the Elastic Stack with security enabled | Elasticsearch Guide \[8.0\] |...](https://www.elastic.co/guide/en/elasticsearch/reference/8.0/configuring-stack-security.html#_connect_clients_to_elasticsearch_5)**

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 12, 2024, 3:33am UTC](https://discuss.elastic.co/t/tls-question-secure-communication-between-winlogbeat-elasticsearch-causes-an-error/350898/3 "2024-01-12T03:33:52Z")

</div>

Yeah, I would agree with Stephen. It looks like you need to tell Winlogbeat which CAs to trust with `output.elasticsearch.ssl.certificate_authorities`.

And then because you are using IP addresses in the configuration to Winlogbeat, those servers' certificates need to contain an [SAN](https://en.wikipedia.org/wiki/Subject_Alternative_Name) for their IP.

> **[Configure SSL | Winlogbeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-ssl.html#client-certificate-authorities)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2024, 5:34am UTC](https://discuss.elastic.co/t/tls-question-secure-communication-between-winlogbeat-elasticsearch-causes-an-error/350898/4 "2024-02-09T05:34:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
