# Cannot get sensu-go cluster to connect over TLS

**URL:** <https://discourse.sensu.io/t/cannot-get-sensu-go-cluster-to-connect-over-tls/3062>\
**Category:** Sensu Go\
**Tags:** sensu-go, tls, backend\
**Created:** [January 9, 2023, 3:35pm UTC](https://discourse.sensu.io/t/cannot-get-sensu-go-cluster-to-connect-over-tls/3062 "2023-01-09T15:35:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael\_Kelly](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/michael_kelly/32/823_2.png) [@Michael\_Kelly](https://discourse.sensu.io/u/Michael_Kelly)\
**Post date:** [January 9, 2023, 3:35pm UTC](https://discourse.sensu.io/t/cannot-get-sensu-go-cluster-to-connect-over-tls/3062/1 "2023-01-09T15:35:46Z")

</div>

Very new to sensu & sensu-go.  
Environment: 3 node cluster running Ubuntu 20.04.5 LTS and sensu-go-backend 6.7.4

I have followed the instructions in the sensu docs to create a CA and generate certificates for the 3 nodes.  
The certificates have been installed and the backup.yml files modified.  
When I start the backends they don’t report any issues with the configuration.  
However, the journal starts to fill up with the same warning  
`"tls: first record does not look like a TLS handshake"`

I did a packet capture of the traffic between two of the nodes and this is where it gets really weird.  
Looking at the traffic in Wireshark, I can see no attempt to start a TLS handshake but I can see lots of HTTP GET requests for /raft/stream/message and /raft/stream/msgapp objects.

I tried stopping the backends, clearing out the state-dir and restarting but that made no difference.  
If I comment out all the tls stuff and change https to http, all the backends start up without a problem.

I have no idea what’s going on here and any help will be much appreciated.

---

<div class="post-metadata">

**Author:** ![Michael\_Kelly](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/michael_kelly/32/823_2.png) [@Michael\_Kelly](https://discourse.sensu.io/u/Michael_Kelly)\
**Post date:** [January 11, 2023, 12:39pm UTC](https://discourse.sensu.io/t/cannot-get-sensu-go-cluster-to-connect-over-tls/3062/2 "2023-01-11T12:39:59Z")

</div>

Solved.  
I originally configured the cluster to use HTTP.  
When I reconfigured it to use HTTPS I was unaware that the etcd component was holding state somewhere so it was trying to use HTTP to communicate with backends expecting HTTPS.  
I rebuilt the cluster from scratch using HTTPS and it is now working as expected.

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/aaronsachs/32/47_2.png) [@aaronsachs](https://discourse.sensu.io/u/aaronsachs)\
**Post date:** [January 11, 2023, 3:10pm UTC](https://discourse.sensu.io/t/cannot-get-sensu-go-cluster-to-connect-over-tls/3062/3 "2023-01-11T15:10:06Z")

</div>

Hey there @Michael_Kelly , glad to hear you solved it. Etcd does indeed hold the configuration for TLS, so if the members start off unsecured, Etcd stores them as such.

---

<div class="post-metadata">

**Author:** ![Michael\_Kelly](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/michael_kelly/32/823_2.png) [@Michael\_Kelly](https://discourse.sensu.io/u/Michael_Kelly)\
**Post date:** [January 11, 2023, 3:41pm UTC](https://discourse.sensu.io/t/cannot-get-sensu-go-cluster-to-connect-over-tls/3062/4 "2023-01-11T15:41:32Z")

</div>

Hi @aaronsachs, thanks for your reply.  
Where does etcd store that configuration?  
I’m wondering if it is possible to avoid having to rebuild an existing sensu-go cluster (currently using HTTP).  
The cluster I created was a test to see if we could use certificates generated by puppet but it looks like we can’t. All I see are ‘bad certificate’ errors.

---

<div class="post-metadata">

**Author:** ![aaronsachs](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/aaronsachs/32/47_2.png) [@aaronsachs](https://discourse.sensu.io/u/aaronsachs)\
**Post date:** [January 11, 2023, 6:52pm UTC](https://discourse.sensu.io/t/cannot-get-sensu-go-cluster-to-connect-over-tls/3062/5 "2023-01-11T18:52:23Z")

</div>

Etcd stores the data in whatever you specify as the data directory in your `backend.yml`. By default, that’s `/var/lib/sensu/sensu-backend/etcd`. The challenge is accessing the data directly–you’ll need to install `etcdctl` to access the data. The cluster members can be viewed using `etcdctl member list`, and you may be able to update the members using `etcdctl member update`, but it’s often quicker to rebuild.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/sensu/original/1X/ad88ecc0d60777fbbb8dad05fe976fca2a4d87b2.jpeg) [@system](https://discourse.sensu.io/u/system)\
**Post date:** [February 10, 2023, 6:53pm UTC](https://discourse.sensu.io/t/cannot-get-sensu-go-cluster-to-connect-over-tls/3062/6 "2023-02-10T18:53:12Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
