# Connect remote cluster between a cluster disabled TLS/SSL and a cluster enabled TLS/SSL

**URL:** <https://discuss.elastic.co/t/connect-remote-cluster-between-a-cluster-disabled-tls-ssl-and-a-cluster-enabled-tls-ssl/361005>\
**Category:** Elasticsearch\
**Tags:** ccr-cross-cluster-replication, ccs-cross-cluster-search\
**Created:** [June 7, 2024, 2:15am UTC](https://discuss.elastic.co/t/connect-remote-cluster-between-a-cluster-disabled-tls-ssl-and-a-cluster-enabled-tls-ssl/361005 "2024-06-07T02:15:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Huy\_Nguyen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/huy_nguyen/32/135104_2.png) [@Huy\_Nguyen](https://discuss.elastic.co/u/Huy_Nguyen)\
**Post date:** [June 7, 2024, 2:15am UTC](https://discuss.elastic.co/t/connect-remote-cluster-between-a-cluster-disabled-tls-ssl-and-a-cluster-enabled-tls-ssl/361005/1 "2024-06-07T02:15:54Z")

</div>

I have a task migrate Elasticsearch from v7 to v8. I'd like new cluster add old cluster as a remote cluster. A cluster Elasticsearch v8 require enable https ssl/tls, however a cluster Elasticsearch v7 in prod environment disabled ssl/tls. I research and read the document just connect between trust 2 CA cert each other, the problem is remote cluster is not able to have any certs.

What should I do in this case, thank you everyone

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 7, 2024, 3:57am UTC](https://discuss.elastic.co/t/connect-remote-cluster-between-a-cluster-disabled-tls-ssl-and-a-cluster-enabled-tls-ssl/361005/2 "2024-06-07T03:57:41Z")

</div>

> [@Huy\_Nguyen](#):
>
> What should I do in this case

I don't think you have any other option besides enabling SSL/TLS in your v7 cluster.

The [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/remote-clusters-cert.html) is pretty clear about it.

> To use cross-cluster replication or cross-cluster search safely with remote clusters, **enable security on all connected clusters** and configure Transport Layer Security (TLS) on every node.

---

<div class="post-metadata">

**Author:** ![Huy\_Nguyen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/huy_nguyen/32/135104_2.png) [@Huy\_Nguyen](https://discuss.elastic.co/u/Huy_Nguyen)\
**Post date:** [June 7, 2024, 4:52am UTC](https://discuss.elastic.co/t/connect-remote-cluster-between-a-cluster-disabled-tls-ssl-and-a-cluster-enabled-tls-ssl/361005/3 "2024-06-07T04:52:33Z")

</div>

> [@leandrojmp](#):
>
> I don't think you have any other option besides enabling SSL/TLS in your v7 cluster.

Thank you for your advance, but I can not enable that because this cluster is running on production, the action will cause down the entire of application services ☹

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 7, 2024, 5:22am UTC](https://discuss.elastic.co/t/connect-remote-cluster-between-a-cluster-disabled-tls-ssl-and-a-cluster-enabled-tls-ssl/361005/4 "2024-06-07T05:22:30Z")

</div>

@Huy_Nguyen Then I would suggest using Snapshot and Restore between the 2 clusters. CRR requires a secure connection i.e. TLS / SSL.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 7, 2024, 6:22am UTC](https://discuss.elastic.co/t/connect-remote-cluster-between-a-cluster-disabled-tls-ssl-and-a-cluster-enabled-tls-ssl/361005/5 "2024-06-07T06:22:23Z")

</div>

> [@Huy\_Nguyen](#):
>
> A cluster Elasticsearch v8 require enable https ssl/tls, however a cluster Elasticsearch v7 in prod environment disabled ssl/tls

The requirement to use TLS for cross cluster connections has not changed between v7 and v8.  
If you have security enabled on a v7 cluster you would need to enable TLS to support CCS/CCR.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 7, 2024, 12:18pm UTC](https://discuss.elastic.co/t/connect-remote-cluster-between-a-cluster-disabled-tls-ssl-and-a-cluster-enabled-tls-ssl/361005/6 "2024-06-07T12:18:00Z")

</div>

> [@Huy\_Nguyen](#):
>
> Thank you for your advance, but I can not enable that because this cluster is running on production, the action will cause down the entire of application services

So, as mentioned you could use snapshots, but this also may have issues, first you need a snapshot that would be accessible by both cluster, ideally you would use a cloud storage snapshot on AWS, GCP or Azure, if you do not have a snapshot configured you would need to install the snapshot repository plugin and do a rolling restart of your nodes.

Another option is to use logstash to transfer the data, you would use an `elasticsearch` input consuming from your v7 cluster and an `elasticsearch` output sending to your v8 cluster.
