Skip to content

Conversation

@barkbay
Copy link
Contributor

@barkbay barkbay commented Aug 11, 2022

Fix #5917 by setting ssl.verification_mode to certificate in the Beat output configuration.

This PR also adds a unit test to cover newBeatConfig and buildOutputConfig.

@barkbay barkbay added >bug Something isn't working v2.5.0 labels Aug 11, 2022
@barkbay barkbay marked this pull request as draft August 11, 2022 14:03
@barkbay barkbay marked this pull request as ready for review August 18, 2022 11:50
@barkbay
Copy link
Contributor Author

barkbay commented Aug 18, 2022

Sorry for the lag. PR is ready for review, it has been tested with the following configurations for the monitoring cluster:

  • Custom CA with the 3 required files (ca.crt, tls.crt and tls.key)
  • Certificate from a well known issuer, Let's Encrypt in my tests, with an empty ca.crt
  • TLS disabled

Copy link
Collaborator

@pebrc pebrc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM there is one compile error due to a change in main,

@barkbay barkbay merged commit 61d81a2 into elastic:main Aug 22, 2022
@barkbay barkbay deleted the stackmon/verification_mode_certificate branch August 22, 2022 09:01
fantapsody pushed a commit to fantapsody/cloud-on-k8s that referenced this pull request Feb 7, 2023
…#5945)

Stack monitoring: set "ssl.verification_mode" to "certificate" in the Beat output configuration in order to trust Elasticsearch certificates issued by "well known" certificate authorities or custom CA, which do not include the "private" service hostname used by Filebeat and Metricbeat.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

>bug Something isn't working v2.5.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Stack Monitoring certificate validation on beats

2 participants