# Addition of new elasticsearch nodes and security (SSL / TLS / HTTPS configuration)

**URL:** <https://discuss.elastic.co/t/addition-of-new-elasticsearch-nodes-and-security-ssl-tls-https-configuration/213285>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 29, 2019, 3:03pm UTC](https://discuss.elastic.co/t/addition-of-new-elasticsearch-nodes-and-security-ssl-tls-https-configuration/213285 "2019-12-29T15:03:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rysiu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rysiu/32/61919_2.png) [@Rysiu](https://discuss.elastic.co/u/Rysiu)\
**Post date:** [December 29, 2019, 3:03pm UTC](https://discuss.elastic.co/t/addition-of-new-elasticsearch-nodes-and-security-ssl-tls-https-configuration/213285/1 "2019-12-29T15:03:08Z")

</div>

I have a question about configuring additional new Elasticsearch nodes (SSL / TLS / HTTPS issue) and adding them to an existing cluster.

Earlier I secured the cluster according to the description:

> **[Configuring SSL, TLS, and HTTPS to secure Elasticsearch, Kibana, Beats, and...](https://www.elastic.co/blog/configuring-ssl-tls-and-https-to-secure-elasticsearch-kibana-beats-and-logstash)**
>
> Feeling insecure about your Elastic Stack security? Run through these step-by-step instructions for setting up TLS encryption and https on Elasticsearch, Kibana, Logstash, and Beats to shore up your stack's defenses. Highly recommended for end-to-end...

Is it enough to create an instance yaml file with only new nodes and configure only new nodes?

Do you need to change certificates on existing nodes? (however, this is not required?)

Quick hint?

PS. Elasticsearch \>= 7.5.0

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 29, 2019, 11:39pm UTC](https://discuss.elastic.co/t/addition-of-new-elasticsearch-nodes-and-security-ssl-tls-https-configuration/213285/2 "2019-12-29T23:39:13Z")

</div>

I recommend following the actual documentation where it exists, in preference to a blog post that can become out of date, and only describes one of many possible configuration options.

- [https://www.elastic.co/guide/en/elasticsearch/reference/7.5/configuring-tls.html#tls-http](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/configuring-tls.html#tls-http)

Assuming you kept your CA cert and key in step `2-4` of the blog, you can use those in `elasticsearch-certutil` to generate additional node certificates, either using a new instances.yml or by passing options on the command line.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2020, 11:39pm UTC](https://discuss.elastic.co/t/addition-of-new-elasticsearch-nodes-and-security-ssl-tls-https-configuration/213285/3 "2020-01-26T23:39:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
