# Client SSL and Server SSL - ES Java Client

**URL:** <https://discuss.elastic.co/t/client-ssl-and-server-ssl-es-java-client/283507>\
**Category:** Elasticsearch\
**Created:** [September 7, 2021, 8:40am UTC](https://discuss.elastic.co/t/client-ssl-and-server-ssl-es-java-client/283507 "2021-09-07T08:40:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Muthukumaran\_Kothand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muthukumaran_kothand/32/46017_2.png) [@Muthukumaran\_Kothand](https://discuss.elastic.co/u/Muthukumaran_Kothand)\
**Post date:** [September 7, 2021, 8:40am UTC](https://discuss.elastic.co/t/client-ssl-and-server-ssl-es-java-client/283507/1 "2021-09-07T08:40:59Z")

</div>

Initial excuse - we are still using TransportClient ( `PreBuiltXPackTransportClient`). Migrating to High Level Rest Client is in progress.  
This question would still be relevant for High Level Rest Client

**Meta:**  
Elasticsearch Server Version : 7.10.2  
Elasticsearch Java Client Dependencies versions : 7.10.2

On Server-side, we have following settings on `elasticsearch.yml` :

```auto
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: <cert_path>
xpack.security.transport.ssl.truststore.path: <cert_path>

```

With above server, can the client - `PreBuiltXPackTransportClient` WITHOUT SSL params can even communicate with server ?

In effect, Server is enabled with SSL and client just using username + password authentication without client-SSL - is this combination possible ?

I conducted two tests as follows :

**Test Case 1** :

_Server_ : Only username and password WITHOUT transport SSL

_Client_ : Tested with `PrebuiltXPackTransportClient` with only username and password WITHOUT SSL

_Observed Behaviour_ : This combination works as expected with only user and password without SSL

**Test Case 2 :**

_Server_ : Username + Password + Transport-SSL enabled in `elasticsearch.yml`

```auto
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: <cert_path>
xpack.security.transport.ssl.truststore.path: <cert_path>

```

_Client_ : Tested with `PrebuiltXPackTransportClient` with ONLY username and password WITHOUT SSL

_Observed Behavior_ : This combination fails with `NoNodeAvailableException [None of the configured nodes are available]` :

**Clarifications**

1. Can non-SSL `PrebuiltXPackTransportClient` communicate with SSL-enabled server - only with username + password based authentication?
2. Can Elasticsearch throw arbitrary exceptions like `NoNodeEvailableException` when above combination is tried - as I have mentioned in **Test Case 2** above ?
3. Is it mandatory that PrebuiltXPackTransportClient must use SSL when xpack.transport on Server side is SSL-enabled ?
4. I did not see any logs on Elasticsearch Server side during this testing

I am referring following Client Documentation for my testing - [Java Client and security | Elasticsearch Guide [7.x] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.x/java-clients.html)

Thanks in advance.

- Muthu

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2021, 8:41am UTC](https://discuss.elastic.co/t/client-ssl-and-server-ssl-es-java-client/283507/2 "2021-10-05T08:41:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
