# Webhook and SSL issue

**URL:** <https://discuss.elastic.co/t/webhook-and-ssl-issue/198786>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [September 9, 2019, 8:49pm UTC](https://discuss.elastic.co/t/webhook-and-ssl-issue/198786 "2019-09-09T20:49:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![petedells](https://avatars.discourse-cdn.com/v4/letter/p/ecc23a/32.png) [@petedells](https://discuss.elastic.co/u/petedells)\
**Post date:** [September 9, 2019, 8:49pm UTC](https://discuss.elastic.co/t/webhook-and-ssl-issue/198786/1 "2019-09-09T20:49:43Z")

</div>

I am generating a https webhook and receive the error below (I am using self-assigned certificates and added them already to the keystore)

> "actions": [  
> {  
> "id": "my\_webhook",  
> "type": "webhook",  
> "status": "failure",  
> "error": {  
> "root\_cause": [  
> {  
> "type": "s\_s\_l\_handshake\_exception",  
> "reason": "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"  
> }  
> ],  
> "type": "s\_s\_l\_handshake\_exception",  
> "reason": "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",  
> "caused\_by": {  
> "type": "validator\_exception",  
> "reason": "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",  
> "caused\_by": {  
> "type": "sun\_cert\_path\_builder\_exception",  
> "reason": "unable to find valid certification path to requested target"  
> }  
> }  
> }  
> },

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 10, 2019, 9:54am UTC](https://discuss.elastic.co/t/webhook-and-ssl-issue/198786/2 "2019-09-10T09:54:29Z")

</div>

> [@petedells](#):
>
> (I am using self-assigned certificates and added them already to the keystore)

Which keystore did you add these to ?

You can specify the necessary trust configuration for watcher, see [Watcher settings in Elasticsearch | Elasticsearch Guide [7.3] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/notification-settings.html#watcher-tls-ssl-key-trusted-certificate-settings).

For example:

```auto
xpack.http.ssl.certificate_authorities: ["/path/to/your/selfsigned/cert"]

```

would work fine

---

<div class="post-metadata">

**Author:** ![petedells](https://avatars.discourse-cdn.com/v4/letter/p/ecc23a/32.png) [@petedells](https://discuss.elastic.co/u/petedells)\
**Post date:** [September 10, 2019, 2:41pm UTC](https://discuss.elastic.co/t/webhook-and-ssl-issue/198786/3 "2019-09-10T14:41:15Z")

</div>

This is my configuration:

xpack.http.ssl.key: certs\_pem/privatekey  
xpack.http.ssl.certificate: certs\_pem/elastic\_node.cert  
xpack.http.ssl.certificate\_authorities: ["/etc/elasticsearch/certs\_pem/ca.cert"]

I still receive the same error.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 10, 2019, 2:47pm UTC](https://discuss.elastic.co/t/webhook-and-ssl-issue/198786/4 "2019-09-10T14:47:32Z")

</div>

The [webhook](https://www.elastic.co/guide/en/elastic-stack-overview/7.3/actions-webhook.html) action is used to send an http request to a web service. You have mentioned that this web service is using a self signed certificate. So the code that makes this request needs to trust the web service self-signed certificate. And this is configured by `xpack.http.ssl.certificate_authorities`

> [@petedells](#):
>
> xpack.http.ssl.key: certs\_pem/privatekey  
> xpack.http.ssl.certificate: certs\_pem/elastic\_node.cert

Why did you add this ? Is the web service that you connect to requiring that you perform client TLS authentication ? If not, you shouldn't be sending a client certificate.

> [@petedells](#):
>
> xpack.http.ssl.certificate\_authorities: ["/etc/elasticsearch/certs\_pem/ca.cert"]

This would only work if the certificate that your web service uses for TLS is signed by ca.cert, is this the case ?

---

<div class="post-metadata">

**Author:** ![petedells](https://avatars.discourse-cdn.com/v4/letter/p/ecc23a/32.png) [@petedells](https://discuss.elastic.co/u/petedells)\
**Post date:** [September 10, 2019, 3:26pm UTC](https://discuss.elastic.co/t/webhook-and-ssl-issue/198786/5 "2019-09-10T15:26:39Z")

</div>

I left alone just this part:

pack.security.http.ssl.certificate\_authorities: ["/etc/elasticsearch/ca/mycert\_1.cert", "/etc/elasticsearch/ca/mycert\_2.cert"]

Still the same error.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 10, 2019, 3:29pm UTC](https://discuss.elastic.co/t/webhook-and-ssl-issue/198786/6 "2019-09-10T15:29:15Z")

</div>

You don't offer any context or details so it becomes really hard to help you. We can't know if this configuration is fine or not, as we don't know what mycert\_2.cert or mycert\_1.cert is, how you created them, where these are used, how do they relate to the web service you want to connect to with the webhook

---

<div class="post-metadata">

**Author:** ![petedells](https://avatars.discourse-cdn.com/v4/letter/p/ecc23a/32.png) [@petedells](https://discuss.elastic.co/u/petedells)\
**Post date:** [September 11, 2019, 1:17pm UTC](https://discuss.elastic.co/t/webhook-and-ssl-issue/198786/7 "2019-09-11T13:17:12Z")

</div>

Figured it out. The problem was that the destination for the webhook is utilizing different certificate for web traffic and webhooks after adding also the one for the webhook error disappeared.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2019, 1:17pm UTC](https://discuss.elastic.co/t/webhook-and-ssl-issue/198786/8 "2019-10-09T13:17:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
