Wazuh agent registration SSL error
When registering Wazuh agents to the log aggregator or central wazuh manager, an error stating “SSL error” and “Connection refused by manager” combined indicates that SSL interception or SSL inspection is in use in the network where the agent is connecting from. As Wazuh has a custom encryption implementation any kind of SSL tampering will break the communication between manager and agent.
Resolution:
To resolve this issue it is recommended to create an exclusion rule for traffic on TCP ports 1514, 1515 and 1516 from any IP to the hydra or central wazuh manager.