# Cross cluster replication security. Mutual TLS query

**URL:** <https://discuss.elastic.co/t/cross-cluster-replication-security-mutual-tls-query/277340>\
**Category:** Elasticsearch\
**Tags:** ccr-cross-cluster-replication\
**Created:** [June 29, 2021, 11:47am UTC](https://discuss.elastic.co/t/cross-cluster-replication-security-mutual-tls-query/277340 "2021-06-29T11:47:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Armen\_Petrosyan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/armen_petrosyan/32/80330_2.png) [@Armen\_Petrosyan](https://discuss.elastic.co/u/Armen_Petrosyan)\
**Post date:** [June 29, 2021, 11:47am UTC](https://discuss.elastic.co/t/cross-cluster-replication-security-mutual-tls-query/277340/1 "2021-06-29T11:47:31Z")

</div>

**ClusterA (leader)**  
keystore (includes server certificate with principal cn=ClusterA, signed by company CA)  
truststore (company CA)  
**ClusterB (follower)**  
keystore (includes server certificate with principal cn=ClusterB, signed by company CA)  
truststore (company CA)

Configured to work with native realm, meaning one way TLS + user and password.  
Defined two roles - ccr\_leader, ccr\_follower with relevant privileges.  
Assumption is that I developed process that can switch sites so follower become leader and leader become follower.

My security definition mappings look like this:

|SITE A  
| **user**** role**  
|ccr\_user1 |ccr\_leader  
|ccr\_user2 |ccr\_follower

|SITE B|  
| **user** | **role**  
|ccr\_user1 |ccr\_follower  
|ccr\_user2 |ccr\_leader

ccr\_user1 is used in case if I want SITE B to follow SITE A  
ccr\_user2 is used in case if I want SITE A to follow SITE B

As far as I understood **user name is correlated** between leader and follower. When I am issuing rest call _/\_follow_ and passing ccr\_user1 to security header, this user propagated to the follower and then to the leader. So there is correlation among user that I am passing from my external client (script) in order to \_follow, user on follower and user on the leader.

1. Is my understanding correct???

Now, let's suppose I don't want to use user/password and want to add additional realm - pki.

I am adding role mappings like below:

|SITE A  
ccr\_leader  
-cn=ClusterB

ccr\_follower  
-cn=ClusterA

|SITE B  
ccr\_follower  
-cn=ClusterB

ccr\_leader  
-cn=ClusterA

1. Is it possible to work with pki realm without user/password for CCR?
2. If yes, and assuming my case when I want to switch sites, Is this predefined mapping is correct in case of PKI realm?
3. When I am triggering _\_follow_ as a external client, I suppose the cn of this external client should not be correlated to the follower and leader pki users correct? In case of pki it muct be working in other way?

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2021, 11:47am UTC](https://discuss.elastic.co/t/cross-cluster-replication-security-mutual-tls-query/277340/2 "2021-07-27T11:47:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
