# Can elasticsearch be accessed by http and htpps simultaneously?

**URL:** <https://discuss.elastic.co/t/can-elasticsearch-be-accessed-by-http-and-htpps-simultaneously/287885>\
**Category:** Logstash\
**Created:** [October 28, 2021, 6:39am UTC](https://discuss.elastic.co/t/can-elasticsearch-be-accessed-by-http-and-htpps-simultaneously/287885 "2021-10-28T06:39:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rodri.gz](https://avatars.discourse-cdn.com/v4/letter/r/aca169/32.png) [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Post date:** [October 28, 2021, 6:39am UTC](https://discuss.elastic.co/t/can-elasticsearch-be-accessed-by-http-and-htpps-simultaneously/287885/1 "2021-10-28T06:39:58Z")

</div>

Hello!

I am working with a supposedly secure cluster that you access through [https://localhost](https://localhost): 9200

but when I went to see the metricbeat.yml configuration file I saw a parameter that surprised me:

`ssl.verification_mode: false`

and when i do a curl i can only acces with de `--insecure` parameter .

Is my environment really secure? Shouldn't Elasticsearch ask me for a certificate?

Thanks in advanced!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 28, 2021, 5:24pm UTC](https://discuss.elastic.co/t/can-elasticsearch-be-accessed-by-http-and-htpps-simultaneously/287885/2 "2021-10-28T17:24:27Z")

</div>

> [@rodri.gz](#):
>
> Is my environment really secure? Shouldn't Elasticsearch ask me for a certificate?

No, it is not secure. The certificate presented by metricbeat is controlled by `ssl.certificate`, not `verification_mode`. Elasticsearch with xpack can be configured to require a certificate as described [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/pki-realm.html).

You have a much bigger problem, because metricbeat is not validating the certificate presented by elasticsearch. As the documentation says

> This mode disables many of the security benefits of SSL/TLS and should only be used after very careful consideration. It is primarily intended as a temporary diagnostic mechanism when attempting to resolve TLS errors; its use in production environments is strongly discouraged.

---

<div class="post-metadata">

**Author:** ![rodri.gz](https://avatars.discourse-cdn.com/v4/letter/r/aca169/32.png) [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Post date:** [November 2, 2021, 8:00am UTC](https://discuss.elastic.co/t/can-elasticsearch-be-accessed-by-http-and-htpps-simultaneously/287885/3 "2021-11-02T08:00:14Z")

</div>

so until my environment has set this: [PKI user authentication | Elasticsearch Guide [7.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/pki-realm.html#pki-realm-for-direct-clients)

it will not really be secure because setting the verification parameter to none let the access anyway, right?

does my `ssl: true` parameter only encrypt the information ?

What you tell me is possible to do it with the open version or only with the paid version?

Thanks for the help!  
Securization seems complicated

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2021, 8:00am UTC](https://discuss.elastic.co/t/can-elasticsearch-be-accessed-by-http-and-htpps-simultaneously/287885/4 "2021-11-30T08:00:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
