# Configure HTTPS on Elastic

**URL:** <https://discuss.elastic.co/t/configure-https-on-elastic/224124>\
**Category:** Elasticsearch\
**Created:** [March 18, 2020, 1:49pm UTC](https://discuss.elastic.co/t/configure-https-on-elastic/224124 "2020-03-18T13:49:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [March 18, 2020, 1:49pm UTC](https://discuss.elastic.co/t/configure-https-on-elastic/224124/1 "2020-03-18T13:49:47Z")

</div>

If I secure elasticsearch with HTTPS, that means that I have to secure logstash and kibana?  
or I just have to change the logstash configuration, and kibana configuration to point to an HTTPS instead of HTTP

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [March 18, 2020, 2:12pm UTC](https://discuss.elastic.co/t/configure-https-on-elastic/224124/2 "2020-03-18T14:12:40Z")

</div>

You would have to point logstash elasticsearch output to https and possibly provide cacerts. You are not required to secure the input sides.

Kibana likewise, but IMHO, securing the input side of Kibana is needed because user account info will flow.

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [March 18, 2020, 3:18pm UTC](https://discuss.elastic.co/t/configure-https-on-elastic/224124/3 "2020-03-18T15:18:59Z")

</div>

thaks, do I need to change every output in my logstash pipelines also?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [March 18, 2020, 4:07pm UTC](https://discuss.elastic.co/t/configure-https-on-elastic/224124/4 "2020-03-18T16:07:08Z")

</div>

Probably, elastic should refuse http connections after security is enabled, so all have to be replaced with https.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 15, 2020, 4:07pm UTC](https://discuss.elastic.co/t/configure-https-on-elastic/224124/5 "2020-04-15T16:07:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
