# Elastic Search 6.3.1: xpack security feature for basic license

**URL:** <https://discuss.elastic.co/t/elastic-search-6-3-1-xpack-security-feature-for-basic-license/216157>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, license\
**Created:** [January 23, 2020, 12:17am UTC](https://discuss.elastic.co/t/elastic-search-6-3-1-xpack-security-feature-for-basic-license/216157 "2020-01-23T00:17:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![NikeshGupta](https://avatars.discourse-cdn.com/v4/letter/n/8edcca/32.png) [@NikeshGupta](https://discuss.elastic.co/u/NikeshGupta)\
**Post date:** [January 23, 2020, 12:17am UTC](https://discuss.elastic.co/t/elastic-search-6-3-1-xpack-security-feature-for-basic-license/216157/1 "2020-01-23T00:17:38Z")

</div>

Hi,

I have installed ES 6.3.1 version and set below relevant properties in elasticsearch.yml during configuration  
xpack.security.enabled: true  
xpack.license.self\_generated.type: basic  
xpack.security.transport.ssl.enabled: true  
xpack.security.http.ssl.enabled: true

- /\_xpack/license returns below response

\<{  
"license" : {  
"status" : "active",  
"uid" : "c51de05d-beb0-4336-a48d-6854ae25ff80",  
"type" : "basic",  
"issue\_date" : "2020-01-02T16:29:17.774Z",  
"issue\_date\_in\_millis" : 1577982557774,  
"max\_nodes" : 1000,  
"issued\_to" : "EIGL\_TST\_ELASTIC\_CLUSTER",  
"issuer" : "elasticsearch",  
"start\_date\_in\_millis" : -1  
}  
}/\>

- And GET /\_xpack/security/\_authenticate?pretty returns below response:  
\<{  
"error" : {  
"root\_cause" : [  
{  
"type" : "security\_exception",  
"reason" : "current license is non-compliant for [security]",  
"license.expired.feature" : "security"  
}  
],  
"type" : "security\_exception",  
"reason" : "current license is non-compliant for [security]",  
"license.expired.feature" : "security"  
},  
"status" : 403  
}/\>

- Interestingly ssl properties enabled in yml file is working fine which matches to free security for basic license as given in [https://www.elastic.co/subscriptions](https://www.elastic.co/subscriptions)

- However "Role-based access control" fails when running the command elasticsearch-setup-passwords interactive with error "It doesn't look like the X-Pack security feature is available on this Elasticsearch node".

Before this setup we had a chat with ElasticSearch Proffessional service as well where we received confirmation that x-pack security features mentioned in above subscription url is also applicable to 6.3.1 version as well. However, it seems to be running partially, where ssl encryption is allowed on transport and http level but user setup/role management is not available.

Could you pls let me know if there is something I am missing or if there is a fix to this issue?

Thanks and Regards,  
Nikesh Gupta

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 23, 2020, 12:35am UTC](https://discuss.elastic.co/t/elastic-search-6-3-1-xpack-security-feature-for-basic-license/216157/2 "2020-01-23T00:35:29Z")

</div>

It's free from 6.8 and up 🙂

> **[Security for Elasticsearch is now free](https://www.elastic.co/blog/security-for-elasticsearch-is-now-free)**
>
> We are thrilled to announce that the core security features of the Elastic Stack -- like TLS encryption, RBAC, and both file and native authentication -- are now free.

---

<div class="post-metadata">

**Author:** ![NikeshGupta](https://avatars.discourse-cdn.com/v4/letter/n/8edcca/32.png) [@NikeshGupta](https://discuss.elastic.co/u/NikeshGupta)\
**Post date:** [January 23, 2020, 1:24pm UTC](https://discuss.elastic.co/t/elastic-search-6-3-1-xpack-security-feature-for-basic-license/216157/3 "2020-01-23T13:24:38Z")

</div>

Thanks for the response Mark. Actually I had the same impression before I got confused after checking on the same with ElasticSearch Professional Service.  
But I wonder why I am able to configure https endpoints for ES as I mentioned below security are configured fine?  
xpack.security.enabled: true  
xpack.license.self\_generated.type: basic  
xpack.security.transport.ssl.enabled: true  
xpack.security.http.ssl.enabled: true

Under what plan we get xpack "Role-based access control (Command command elasticsearch-setup-passwords interactive)" for version 6.3 as it shows basic in current subscription plan.

What happens if we set it Trial to configure the user setup and then chnage it back to Basic? Any help on this direction is really appreciated.

Regards,  
Nikesh Gupta

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 23, 2020, 8:00pm UTC](https://discuss.elastic.co/t/elastic-search-6-3-1-xpack-security-feature-for-basic-license/216157/4 "2020-01-23T20:00:22Z")

</div>

I am not sure what professional you are talking about, were they from Elastic?

Otherwise you need to update to 6.8 for free Security, otherwise you need a subscription.

---

<div class="post-metadata">

**Author:** ![NikeshGupta](https://avatars.discourse-cdn.com/v4/letter/n/8edcca/32.png) [@NikeshGupta](https://discuss.elastic.co/u/NikeshGupta)\
**Post date:** [January 23, 2020, 8:41pm UTC](https://discuss.elastic.co/t/elastic-search-6-3-1-xpack-security-feature-for-basic-license/216157/5 "2020-01-23T20:41:33Z")

</div>

Thanks Mark. We need to use specific version 6.3.1. Which subscription will be needed for Role-based access control security?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 23, 2020, 10:32pm UTC](https://discuss.elastic.co/t/elastic-search-6-3-1-xpack-security-feature-for-basic-license/216157/6 "2020-01-23T22:32:42Z")

</div>

Either Gold or Platinum. You can also use our Elasticsearch Service which includes this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2020, 10:32pm UTC](https://discuss.elastic.co/t/elastic-search-6-3-1-xpack-security-feature-for-basic-license/216157/7 "2020-02-20T22:32:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
