# Can we update to 8.0 without enabling securitys

**URL:** <https://discuss.elastic.co/t/can-we-update-to-8-0-without-enabling-securitys/298275>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 25, 2022, 12:04pm UTC](https://discuss.elastic.co/t/can-we-update-to-8-0-without-enabling-securitys/298275 "2022-02-25T12:04:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dheeraj\_Gupta](https://avatars.discourse-cdn.com/v4/letter/d/49beb7/32.png) [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Post date:** [February 25, 2022, 12:04pm UTC](https://discuss.elastic.co/t/can-we-update-to-8-0-without-enabling-securitys/298275/1 "2022-02-25T12:04:32Z")

</div>

We have our filebeat-logstash-Elasticsearch-kibana ecosystem on a private subnet within our organization network. Due to the placement of all components on a fenced subnet, we don't need any security features such as role based access control, encryption during transit or when feeding data into Elasticsearch from logstash. Kibana too is behind an Nginx reverse proxy and basic authentication control at Nginx provides us good enough security for our use case.

So all our Elasticsearch nodes have the following setting

```auto
xpack.security.enabled: false

```

Reading the 8.0 release notes, first thing that jumps up is [Security is now on by default](https://www.elastic.co/guide/en/elasticsearch/reference/current/release-highlights.html#_security_features_are_enabled_and_configured_by_default)

My shallow understanding is that to use security, we would need to:

- Setup TLS keys on Elasticsearch nodes
- Edit `elasticsearch` plugin in Logstash to add the new certificate information
- Edit kibana config to tell it to use TLS to talk to Elasticsearch
- Maybe ad authentication to Kibana

Given this is a production cluster, we cannot afford to have a failed 8.0 upgrade. So I would like to know if we can upgrade the current "no-security" ElasticStack-7.17 to a "no-security" ElasticStack-8.0 and then think about enabling security/TLS? I couldn't find relevant information in the release documentation of Elasticsearch, logstash and Kibana.

---

<div class="post-metadata">

**Author:** ![amitmbm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amitmbm/32/102111_2.png) [@amitmbm](https://discuss.elastic.co/u/amitmbm)\
**Post date:** [February 25, 2022, 12:09pm UTC](https://discuss.elastic.co/t/can-we-update-to-8-0-without-enabling-securitys/298275/2 "2022-02-25T12:09:23Z")

</div>

it just means that in previous versions Basic security wasn't enabled by default and you have to enable it using `xpack.security.enabled: true` config, now its enabled by default, so if you don't want to use it, please change it in `elasticsearch.yml` to `xpack.security.enabled: false` and you are good to go.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2022, 3:20am UTC](https://discuss.elastic.co/t/can-we-update-to-8-0-without-enabling-securitys/298275/4 "2022-03-29T03:20:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
