# What is the point and purpose of ca\_trusted\_fingerprint?

**URL:** <https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [April 9, 2023, 1:56pm UTC](https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623 "2023-04-09T13:56:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jba/32/118482_2.png) [@jba](https://discuss.elastic.co/u/jba)\
**Post date:** [April 9, 2023, 1:56pm UTC](https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623/1 "2023-04-09T13:56:18Z")

</div>

What is the point of adding the ca\_trusted\_fingerprint parameter to an logstash-output-elasticsearch section in an output filter? Is it purely to defend against a possible attack on DNS servers? Misconfiguration of the ES hosts?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 9, 2023, 2:31pm UTC](https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623/2 "2023-04-09T14:31:19Z")

</div>

> [@jba](#):
>
> What is the point of adding the ca\_trusted\_fingerprint parameter to an logstash-output-elasticsearch section in an output filter?

If your Elasticsearch is listening on with TLS, on HTTPS, and the CA used to sign the certificate is not a trusted CA, like a self-generated CA that you used, then you need to pass the CA in logstash so it can trust the Elasticsearch Certificate.

This can be done in two ways, one is using the `cacert` option, the other is using the `ca_trusted_fingerprint`, but this option only works on Logstash 8.3+

This is explained in the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ca_trusted_fingerprint)

> The SHA-256 fingerprint of an SSL Certificate Authority to trust, such as the autogenerated self-signed CA for an Elasticsearch cluster.

---

<div class="post-metadata">

**Author:** ![jba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jba/32/118482_2.png) [@jba](https://discuss.elastic.co/u/jba)\
**Post date:** [April 9, 2023, 4:42pm UTC](https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623/3 "2023-04-09T16:42:56Z")

</div>

Thanks. So in our case, where we run ELK on-premise and have an internal CA organisation that issues all our certificates, using the fingerprint feature is like using both belt and suspenders? It does not gain us any additional security?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 9, 2023, 5:40pm UTC](https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623/4 "2023-04-09T17:40:38Z")

</div>

> [@leandrojmp](#):
>
> This can be done in two ways, one is using the `cacert` option, the other is using the `ca_trusted_fingerprint`, but this option only works on Logstash 8.3+

Same effect, security and outcome just 2 different implementations... Using both provides no additional security.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2023, 5:41pm UTC](https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623/5 "2023-05-07T17:41:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
