# Unable to generate client certificate for fluentd from elasticsearch cluster 8.0.0

**URL:** <https://discuss.elastic.co/t/unable-to-generate-client-certificate-for-fluentd-from-elasticsearch-cluster-8-0-0/298129>\
**Category:** Elasticsearch\
**Created:** [February 24, 2022, 8:21am UTC](https://discuss.elastic.co/t/unable-to-generate-client-certificate-for-fluentd-from-elasticsearch-cluster-8-0-0/298129 "2022-02-24T08:21:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abdul\_Gaffar\_Shaikh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdul_gaffar_shaikh/32/78006_2.png) [@Abdul\_Gaffar\_Shaikh](https://discuss.elastic.co/u/Abdul_Gaffar_Shaikh)\
**Post date:** [February 24, 2022, 8:21am UTC](https://discuss.elastic.co/t/unable-to-generate-client-certificate-for-fluentd-from-elasticsearch-cluster-8-0-0/298129/1 "2022-02-24T08:21:17Z")

</div>

hi Team ,

this is in continuation from the question raised for v8 [elastic and kibana installation](https://discuss.elastic.co/t/configure-multi-node-configuration-with-enrollment-token-elasticsearch-8-0-0/297486)

i was successfully able to create 5 node cluster and kibana, but since we have fluentd aggregator , i was unable to send data to elastic cluster as i placed the http\_ca.crt certificate from elastic in fluentd instance, i faced below issue.

> <https://github.com/uken/fluent-plugin-elasticsearch/issues/615>
>
> Problem:
> We are using searchguard with elasticsearch and fluentd, 
> I have enab…led client\_certificate based authentication for elasticsearch.
> 
> Configured client certificates in fluentd - so that ES can verify client connections.
> After providing client certificates, td-agent is unable to communicate over SSL to elasticsearch and it shows below error:
> 
> Error logs:
> \`\[error\]: #0 unexpected error error\_class=Faraday::SSLError error="SSL\_connect returned=1 errno=0 state=error: sslv3 alert certificate unknown (OpenSSL::SSL::SSLError)"\`
> 
> Followed the link: https://www.rubydoc.info/gems/fluent-plugin-elasticsearch/1.2.0
> 
> td-agent configuration:
> 
> \`\`\`aconf
> \<match apache\*\*\>
> @type elasticsearch
> @log\_level info
> include\_tag\_key true
> host elasticsearch.abc
> port 9200
> ca\_file /etc/td-agent/certs/es-root-ca.pem
> client\_cert /etc/td-agent/certs/admin.crt.pem
> client\_key /etc/td-agent/certs/admin.key.pem
> scheme https
> ssl\_verify true
> ssl\_version TLSv1\_2
> logstash\_format true
> logstash\_prefix prash
> \</match\>
> \`\`\`
> 
> But with the same certificates I am able to connect to elacticsearch with curl requests.
> for example:
> \`curl --insecure --cert /abc/admin.crt.pem --key /abc/admin.key.pem https://xx.xxx.xxx.xx:9200/\_cat/indices?v\`
> 
> Above curl command gives me appropriate result.
> 
> Can you please suggest solution for this? What additional configurations are needed to enable client-cert validation with fluentd?

now i did not place the node certificates since i was not able to generate from elastic as the below link specifiy only 3 certificates

http\_ca.crt  
http.p12  
transport.p12

> **[Install Elasticsearch with Debian Package | Elasticsearch Guide \[8.0\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/deb.html#_security_certificates_and_keys_2)**

command below needs ca.key (which was missing)

```auto
bin/elasticsearch-certutil cert --ca-cert ca_cert_path --ca-key ca_key_path --pem --in instances.yml --out certs.zip 

```

please let me know how i can enable tls in fluentd with http\_ca.cert?  
do i need any other parameter? i was able to generate manually configuring security but with the enrollment token approach , i am not sure , how to enable clients to send data securely to elastic.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [February 25, 2022, 11:12am UTC](https://discuss.elastic.co/t/unable-to-generate-client-certificate-for-fluentd-from-elasticsearch-cluster-8-0-0/298129/2 "2022-02-25T11:12:41Z")

</div>

> [@Abdul\_Gaffar\_Shaikh](#):
>
> was unable to send data to elastic cluster as i placed the http\_ca.crt certificate from elastic in fluentd instance,

Please share exact configuration and exact error messages. As said in the previous post you opened, it is really hard for anyone to help if you don’t provide enough information.

How did you try to use the http\_ca.crt in the fluentd configuration and what _exactly_ was the error

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2022, 11:13am UTC](https://discuss.elastic.co/t/unable-to-generate-client-certificate-for-fluentd-from-elasticsearch-cluster-8-0-0/298129/3 "2022-03-25T11:13:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
