# Why does filebeat only need cert and metricbeat need key, ca and cert? \[RESOLVED\]

**URL:** https://discuss.elastic.co/t/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert-resolved/104214
**Category:** Beats
**Tags:** beats-development
**Created:** [October 17, 2017, 9:20am UTC](https://discuss.elastic.co/t/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert-resolved/104214 "2017-10-17T09:20:46Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![gotjoshua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gotjoshua/32/23102_2.png) [@gotjoshua](https://discuss.elastic.co/u/gotjoshua)
#### Post date: [October 17, 2017, 9:20am UTC](https://discuss.elastic.co/t/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert-resolved/104214/1 "2017-10-17T09:20:46Z")

</div>

I am quite new to the whole ELK stack, and i just managed to set up both filebeat and metricbeat to connect to a remote ELK stack. All v6.0.0-rc1

The SSL setup got me a bit confused, and I am left with the question:  
Why does filebeat only need cert and metricbeat need key, ca and cert?

filebeat.yml

```
ssl:
  certificate_authorities:
    - /host/certs/logstash-beats.crt

```

metricbeat.yml:

```
output.logstash:
    hosts: ["host.url:5044"] 
    ssl.certificate_authorities: ["/host/certs/reporter-ca.crt"]
    ssl.certificate: "/host/certs/reporter.crt"
    ssl.key: "/host/certs/reporter-private.key"
```

---

<div class="post-metadata">

### Author: ![mdanner](https://avatars.discourse-cdn.com/v4/letter/m/76d3ee/32.png) [@mdanner](https://discuss.elastic.co/u/mdanner)
#### Post date: [October 21, 2017, 9:52pm UTC](https://discuss.elastic.co/t/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert-resolved/104214/2 "2017-10-21T21:52:13Z")

</div>

Good question! And it raises the further questions:

- Is it bad practice to distribute the private key to each metricbeat agent?
- Should that private key have a password?

---

<div class="post-metadata">

### Author: ![gotjoshua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gotjoshua/32/23102_2.png) [@gotjoshua](https://discuss.elastic.co/u/gotjoshua)
#### Post date: [October 22, 2017, 10:20am UTC](https://discuss.elastic.co/t/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert-resolved/104214/3 "2017-10-22T10:20:07Z")

</div>

Yeah...  
I would ask: is it "bad design" rather than "bad practice", because I couldn't get metricbeat to function without the private key.  
Is there a way?

And if there was a password, what would be a reasonable way to use it?

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [October 23, 2017, 1:12pm UTC](https://discuss.elastic.co/t/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert-resolved/104214/4 "2017-10-23T13:12:20Z")

</div>

Where do you have the beats configuration from?

TLS/SSL uses a public-key infrastructure. The service that needs to be authenticated requires the public and the private key. The other endpoint (validating the service) only requires the public key (or even better only the CA certificate - public key). When using TLS/SSL by default only the 'server' a client connects to will be authenticated. In this scenario beats are the client and Logstash is the server.

In addition the server can request the client to authenticate itself (using a certificate). This modus is called client-authentication and must be explicitly enabled in the server (Logstash). With client-auth enabled, the client also requires a certificate and a private key + the server requires the certificate (or CAs certificate) in order to verify/authenticate the client.

Anyways, when using client-auth, each client should have it's own client certificate with matching IP/Domain name. Plus Logstash should only have the CAs public certificate for verification. This boils down to having a proper CA infrastructure.

NEVER share the private key of an endpoint/machine with another machine.

> Is it bad practice to distribute the private key to each metricbeat agent?

Indeed it is.

> Should that private key have a password?

If possible yes (as private key should be encrypted), but this most likely obfuscate access, as [somewhere the passphrase](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-output-ssl.html#_key_passphrase) must be configured so the key can be used. Still, encrypting the key can somewhat reduce damage if the key gets stolen.

Without client authentication the beats config should be (at least) like:

```auto
output.logstash:
    hosts: ["host.url:5044"] 
    ssl.certificate_authorities:
    - /host/certs/logstash-beats.crt

```

With client authentication the beats config should be (at least) like:

```auto
output.logstash:
    hosts: ["host.url:5044"] 
    ssl.certificate_authorities:
    - /host/certs/logstash-beats.crt
    ssl.certificate: "/host/certs/reporter.crt"
    ssl.key: "/host/certs/reporter-private.key"
    ssl.key_passphrase: ...

```

---

<div class="post-metadata">

### Author: ![gotjoshua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gotjoshua/32/23102_2.png) [@gotjoshua](https://discuss.elastic.co/u/gotjoshua)
#### Post date: [October 26, 2017, 9:55am UTC](https://discuss.elastic.co/t/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert-resolved/104214/5 "2017-10-26T09:55:28Z")

</div>

Thanks for the thorough explanation!

> [@steffens](#):
>
> Where do you have the beats configuration from?

> **[elk-docker](https://elk-docker.readthedocs.io/#forwarding-logs-filebeat)**
>
> None

---

<div class="post-metadata">

### Author: ![gotjoshua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gotjoshua/32/23102_2.png) [@gotjoshua](https://discuss.elastic.co/u/gotjoshua)
#### Post date: [October 26, 2017, 1:25pm UTC](https://discuss.elastic.co/t/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert-resolved/104214/6 "2017-10-26T13:25:41Z")

</div>

@steffens, I [cross posted this at stack exchange](https://stackoverflow.com/questions/46789400/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert), do you also have an account over there? Would be great if you post your precise answer there as well...

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [October 27, 2017, 12:52pm UTC](https://discuss.elastic.co/t/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert-resolved/104214/7 "2017-10-27T12:52:22Z")

</div>

Sure, I added my answer to stackexchange. While stackX is an awesome platform in itself, I normally don't use it to discuss any beats issues. Beats issues often need more detailed discussions and questionaries, which the discuss forum is much better suited for.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 24, 2017, 12:52pm UTC](https://discuss.elastic.co/t/why-does-filebeat-only-need-cert-and-metricbeat-need-key-ca-and-cert-resolved/104214/8 "2017-11-24T12:52:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
