Https setup in graylog 3.0

(Mohd Arif) #1

I am setting up https in graylog with CA signed(not self singed) after that i am facing the issue and nothing loads in graylog UI.

Please find my server.log:

is_master = true
node_id_file = /etc/graylog/server/node-id
password_secret = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
root_password_sha2 = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
bin_dir = /usr/share/graylog-server/bin
data_dir = /graylog/graylog-server
plugin_dir = /usr/share/graylog-server/plugin
http_bind_address = xxxxxxxxxxxxxxxxxx:9000
http_enable_tls = true
http_tls_cert_file = /graylog/graylog-server/certificates/xxxxxxxxxxxxxxxxxxxxxxx.pem
http_tls_key_file = /graylog/graylog-server/certificates/xxxxxxxxxxxxxxxxxxxxxx_pk8.pem
http_tls_key_password = changeit
elasticsearch_hosts =
rotation_strategy = count
elasticsearch_max_docs_per_index = 20000000
elasticsearch_max_number_of_indices = 20
retention_strategy = delete
elasticsearch_shards = 4
elasticsearch_replicas = 0
elasticsearch_index_prefix = graylog
allow_leading_wildcard_searches = false
allow_highlighting = false
elasticsearch_analyzer = standard
output_batch_size = 500
output_flush_interval = 1
output_fault_count_threshold = 5
output_fault_penalty_seconds = 30
processbuffer_processors = 5
outputbuffer_processors = 3
processor_wait_strategy = blocking
ring_size = 65536
inputbuffer_ring_size = 65536
inputbuffer_processors = 2
inputbuffer_wait_strategy = blocking
message_journal_enabled = true
message_journal_dir = /graylog/graylog-server/journal
lb_recognition_period_seconds = 3
mongodb_uri = mongodb://localhost/graylog
mongodb_max_connections = 1000
mongodb_threads_allowed_to_block_multiplier = 5
proxied_requests_thread_pool_size = 32

I am formatted the key as PKCS#8.pem format and certificate is .pem.
Please let me know if it is really necessary to add the certificate in cacerts?



(Jan Doberstein) #2

if you have used your own CA. Did you add this CA to the java keystore that Graylog is able to connect to itself and verify the certificate?

Did you checked the Graylog server.log?


(Mohd Arif) #3

I checked the server.log but did not find anything relevant.
I did not added them in cacert. I will try that now.


(Mohd Arif) #4

I do not have any logs for https but when i set the value of “http_tls_key_password” graylog does not start itself.

2019-03-20T02:32:01.422-04:00 ERROR [ServerBootstrap] Graylog startup failed. Exiting. Exception was:
java.lang.IllegalStateException: Expected to be healthy after starting. The following services are not running: {FAILED=[JerseyService [FAILED]]}
at$ServiceManagerState.checkHealthy( ~[graylog.jar:?]
at$ServiceManagerState.awaitHealthy( ~[graylog.jar:?]
at ~[graylog.jar:?]
at org.graylog2.bootstrap.ServerBootstrap.startCommand( [graylog.jar:?]
at [graylog.jar:?]
at org.graylog2.bootstrap.Main.main( [graylog.jar:?]
Suppressed:$FailedService: JerseyService [FAILED]
Caused by: overrun, bytes = 2351
at javax.crypto.EncryptedPrivateKeyInfo.( ~[?:1.8.0_201]
at ~[graylog.jar:?]
at ~[graylog.jar:?]
at org.graylog2.shared.initializers.JerseyService.buildSslEngineConfigurator( ~[graylog.jar:?]
at org.graylog2.shared.initializers.JerseyService.startUpApi( ~[graylog.jar:?]
at org.graylog2.shared.initializers.JerseyService.startUp( ~[graylog.jar:?]
at$DelegateService$ ~[graylog.jar:?]
at$ ~[graylog.jar:?]
at ~[?:1.8.0_201]


(Jan Doberstein) #5

does your certificate need a password?


(Mohd Arif) #6

I have added my certificate in cacert.jks still no luck.


(Mohd Arif) #7

I have setup the https and everything is working except when i click system–>node–>node ID.
Please find the screenshot…

and when i click node below error message comes…

Could not get plugins

    Getting plugins on node "8cf7f4b5-d19f-469e-b1ab-d71e58334d91" failed: Error: cannot GET https://serverip/api/cluster/8cf7f4b5-d19f-469e-b1ab-d71e58334d91/plugins (500)

    Could not get JVM information

    Getting JVM information for node '8cf7f4b5-d19f-469e-b1ab-d71e58334d91' failed: Error: cannot GET https://serverip:9000/api/cluster/8cf7f4b5-d19f-469e-b1ab-d71e58334d91/jvm (500)

here the graylog server.log

2019-03-28T06:41:05.779-04:00 WARN  [ProxiedResource] Unable to call https://serverip:9000/api/system/metrics/multiple on node <8cf7f4b5-d19f-469e-b1ab-d71e58334d91> Hostname serverip not verified:
    subjectAltNames: [my domian]
        at okhttp3.internal.connection.RealConnection.connectTls( ~[graylog.jar:?]
        at okhttp3.internal.connection.RealConnection.establishProtocol( ~[graylog.jar:?]
        at okhttp3.internal.connection.RealConnection.connect( ~[graylog.jar:?]
        at okhttp3.internal.connection.StreamAllocation.findConnection( ~[graylog.jar:?]
        at okhttp3.internal.connection.StreamAllocation.findHealthyConnection( ~[graylog.jar:?]
        at okhttp3.internal.connection.StreamAllocation.newStream( ~[graylog.jar:?]
        at okhttp3.internal.connection.ConnectInterceptor.intercept( ~[graylog.jar:?]
        at okhttp3.internal.http.RealInterceptorChain.proceed( ~[graylog.jar:?]
        at okhttp3.internal.http.RealInterceptorChain.proceed( ~[graylog.jar:?]
        at okhttp3.internal.cache.CacheInterceptor.intercept( ~[graylog.jar:?]
        at okhttp3.internal.http.RealInterceptorChain.proceed( ~[graylog.jar:?]
        at okhttp3.internal.http.RealInterceptorChain.proceed( ~[graylog.jar:?]
        at okhttp3.internal.http.BridgeInterceptor.intercept( ~[graylog.jar:?]
        at okhttp3.internal.http.RealInterceptorChain.proceed( ~[graylog.jar:?]
        at okhttp3.internal.http.RetryAndFollowUpInterceptor.intercept( ~[graylog.jar:?]
        at okhttp3.internal.http.RealInterceptorChain.proceed( ~[graylog.jar:?]
        at okhttp3.internal.http.RealInterceptorChain.proceed( ~[graylog.jar:?]
        at$get$0( ~[graylog.jar:?]
        at okhttp3.internal.http.RealInterceptorChain.proceed( ~[graylog.jar:?]
        at okhttp3.internal.http.RealInterceptorChain.proceed( ~[graylog.jar:?]
        at okhttp3.RealCall.getResponseWithInterceptorChain( ~[graylog.jar:?]
        at okhttp3.RealCall.execute( ~[graylog.jar:?]
        at retrofit2.OkHttpCall.execute( ~[graylog.jar:?]
        at$getForAllNodes$0( ~[graylog.jar:?]
        at [?:1.8.0_201]
        at java.util.concurrent.ThreadPoolExecutor.runWorker( [?:1.8.0_201]
        at java.util.concurrent.ThreadPoolExecutor$ [?:1.8.0_201]
        at [?:1.8.0_201]

(Mohd Arif) #8

I am using CA singed certificates that does not have the ip of Gray log server and even hostname.
it has my domain FQDN and IP which is configured on Apache proxy.

Please share some inputs.


(Jan Doberstein) #9

you have not all needed URIs in your cert…

http_bind_address = xxxxxxxxxxxxxxxxxx:9000

Hostname serverip not verified

(Mohd Arif) #10

Sorry, I did not get.
I need that URI in my certificate or not? if not then why graylog is complaining about the hostname not verified.


(Jan Doberstein) #11

your certificate needs all IPs and URIs that might be used to connect to the URL/Graylog.


(Mohd Arif) #12

I have created the self-signed certificate with graylog server hostname and IP and now this issue resolved.
Thank You @jan


(system) closed #13

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.