# Does X-Pack Security authenticates clients via client certificates

**URL:** <https://discuss.elastic.co/t/does-x-pack-security-authenticates-clients-via-client-certificates/99325>\
**Category:** Elasticsearch\
**Created:** [September 4, 2017, 3:01pm UTC](https://discuss.elastic.co/t/does-x-pack-security-authenticates-clients-via-client-certificates/99325 "2017-09-04T15:01:31Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 7, 2017, 4:25am UTC](https://discuss.elastic.co/t/does-x-pack-security-authenticates-clients-via-client-certificates/99325/2 "2017-09-07T04:25:15Z")

</div>

I think I probably answered most of your questions through your [other post](https://discuss.elastic.co/t/is-it-possible-to-implement-index-level-access-control-depending-on-the-client-certificate/99390), but I'll fill in a few details. Please post a followup if I've missed something.

> [@](#):
>
> If the two application servers are using the same certificate to authenticate the Elasticsearch node server ...
> 
> ```auto
> curl -XDELETE https://:9200/index/filebeat-app01-* --cacert ca.crt
> 
> ```

It's important to be really clear about client certificates _vs_ server certificates (which you might be, but it's not entirely clear from your post)

When enabling TLS on Elasticsearch you _must_ supply a server certificate (that `certgen` can generate for you), but _client_ certificates are optional.  
In your curl example, you're using the server `ca.crt` to verify the server certificate, but you're not supplying a client certificate.

If you want to rely on TLS to distinguish between different clients (such as different logstash instances) then you need to enable client certificates. The instructions for the [PKI realm](https://www.elastic.co/guide/en/x-pack/5.5/pki-realm.html) can guide you through that process.

You can use `certgen` to generate client certificates, but you would typically separate your client certificates from your server certificates.

---

_[View the full topic](https://discuss.elastic.co/t/does-x-pack-security-authenticates-clients-via-client-certificates/99325)._
