# Don't want to use https and user:password

**URL:** <https://discuss.elastic.co/t/dont-want-to-use-https-and-user-password/202332>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [October 4, 2019, 11:15am UTC](https://discuss.elastic.co/t/dont-want-to-use-https-and-user-password/202332 "2019-10-04T11:15:39Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [October 4, 2019, 12:47pm UTC](https://discuss.elastic.co/t/dont-want-to-use-https-and-user-password/202332/2 "2019-10-04T12:47:36Z")

</div>

Hello,

TLS can be disabled as explained here: [https://www.elastic.co/guide/en/cloud-on-k8s/0.9/k8s-accessing-elastic-services.html#k8s-disable-tls](https://www.elastic.co/guide/en/cloud-on-k8s/0.9/k8s-accessing-elastic-services.html#k8s-disable-tls).

```
spec:
  http:
    tls:
      selfSignedCertificate:
        disabled: true

```

Basic authentication can be bypassed by enabling anonymous access: [https://www.elastic.co/guide/en/elastic-stack-overview/7.4/anonymous-access.html](https://www.elastic.co/guide/en/elastic-stack-overview/7.4/anonymous-access.html).

```
spec:
  nodes:
  - nodeCount: 1
    config:
      xpack.security.authc:
          anonymous:
            username: anonymous
            roles: superuser
            authz_exception: false

```

Even in a private cluster, we don't recommend to turn off these security layers.  
Obviously, it is up to you to make the decision 🙂

---

_[View the full topic](https://discuss.elastic.co/t/dont-want-to-use-https-and-user-password/202332)._
