docs/reference/metricbeat/ssl-client-fails.md
The host running {{ls}} might be unreachable or the certificate may not be valid. To resolve your issue:
Make sure that {{ls}} is running and you can connect to it. First, try to ping the {{ls}} host to verify that you can reach it from the host running Metricbeat. Then use either nc or telnet to make sure that the port is available. For example:
ping <hostname or IP>
telnet <hostname or IP> 5044
Verify that the certificate is valid and that the hostname and IP match.
::::{tip}
For testing purposes only, you can set verification_mode: none to disable hostname checking.
::::
Use OpenSSL to test connectivity to the {{ls}} server and diagnose problems. See the OpenSSL documentation for more info.
Make sure that you have enabled SSL (set ssl_enabled => true) when configuring the Beats input plugin for {{ls}}.
Here are some common errors and ways to fix them:
This might occur for a few reasons:
This happens because your certificate is only valid for the hostname present in the Subject field.
To resolve this problem, try one of these solutions:
/etc/hosts for the hostname. Or on Windows add an entry to C:\Windows\System32\drivers\etc\hosts.This is not a SSL problem. It’s a networking problem. Make sure the two hosts can communicate.
This is not a SSL problem. Make sure that {{ls}} is running and that there is no firewall blocking the traffic.
A firewall is refusing the connection. Check if a firewall is blocking the traffic on the client, the network, or the destination host.