# Elastic Search 8.6.2 SSL enabled with 3rd party certificate

**URL:** <https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [May 30, 2023, 6:37pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713 "2023-05-30T18:37:22Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 6:37pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/1 "2023-05-30T18:37:22Z")

</div>

I have a single instance of Elastic Search 8.6.2 installed on a redhat server. No cloud, No docker and single node, very simple install. We need SSL enabled and configured to use a 3rd party certificate we can't use Elasticsearch self-signed certificate. Could someone please point me in the documentation of Elastic Search for this configuration. Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 30, 2023, 6:59pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/2 "2023-05-30T18:59:36Z")

</div>

Hi @neil.maffitt

Just generate your certs and then make them available and configure and use them. I used lets encrypt below works fine for HTTPS interface. Note it is still recommended to use self-signed for transport or at least use separate certs etc.

All the settings are [HTTP here](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html#http-tls-ssl-settings) and [Transport Here](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html#transport-tls-ssl-settings)

```auto
# Enable security features
xpack.security.enabled: true

xpack.security.http.ssl:
  enabled: true
  certificate: certs/fullchain.pem <!--- Lets Encrypt
  key: certs/privkey.pem

# Enable encryption and mutual authentication between cluster nodes
xpack.security.transport.ssl:
  enabled: true
  verification_mode: certificate
  keystore.path: certs/transport.p12 <!- Self Signed
  truststore.path: certs/transport.p12

```

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 7:06pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/3 "2023-05-30T19:06:03Z")

</div>

Thank you for the quick response. Sorry should have mentioned we can't use http interface. We can only use https and nothing self-signed

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 30, 2023, 7:10pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/4 "2023-05-30T19:10:07Z")

</div>

> [@neil.maffitt](#):
>
> Thank you for the quick response. Sorry should have mentioned we can't use http interface. We can only use https and nothing self-signed

Sorry when I say HTTP I mean HTTP(s)

That example above is HTTPS!

For the transport, you can absolutely use your own certs we just recommend to use separate certs.

Generate your certs, put them in the config folders, make sure they are readable and properly config. Support PEM and P12s

No rocket science just normal cert magic 🙂

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 7:13pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/5 "2023-05-30T19:13:21Z")

</div>

ok will give it a try and let you know how it goes. thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 30, 2023, 7:16pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/6 "2023-05-30T19:16:46Z")

</div>

to be clear this enables SSL on the HTTP REST Interface  
We call it the HTTP interface as transport is binary.  
So technically you enable SSL on the HTTP interface  
Hope that makes sense

> [@stephenb](#):
>
> ```auto
> xpack.security.http.ssl:
> enabled: true
> 
> ```

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 7:24pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/7 "2023-05-30T19:24:01Z")

</div>

yep that makes sense. My goal is to make a curl call using https protocol call to Elasticsearch like this

```auto
curl --location --request GET 'https://servername:9200/engine-int/_search?pretty' --header 'Content-Type: application/json' --header 'Authorization: Basic <base64 user:password>' --data '{
    "query": {
        "match_all": {}
    }
}

```

For http this is working I need it to work https  
Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 30, 2023, 7:36pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/8 "2023-05-30T19:36:03Z")

</div>

Yup ... I use let's encrypt certs and do it all the time.

If you have your own CA it will need to be trusted by your client apps / curl etc

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 7:38pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/9 "2023-05-30T19:38:57Z")

</div>

One last question, I hope 🙂 does user elasticsearch need to be the owner of the pem files in the cert/ directory? Thank

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 30, 2023, 7:42pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/10 "2023-05-30T19:42:36Z")

</div>

They need to be readable by the elasticsearch process, you chose your least privilege model

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 8:33pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/11 "2023-05-30T20:33:14Z")

</div>

Once I got by the file privileges. It is WORKING . Thank you for your help.

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 8:41pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/12 "2023-05-30T20:41:09Z")

</div>

sorry spoke to soon  
'''  
curl performs SSL certificate verification by default, using a "bundle"  
of Certificate Authority (CA) public keys (CA certs). If the default  
bundle file isn't adequate, you can specify an alternate file  
using the --cacert option.  
If this HTTPS server uses a certificate signed by a CA represented in  
the bundle, the certificate verification probably failed due to a  
problem with the certificate (it might be expired, or the name might  
not match the domain name in the URL).  
If you'd like to turn off curl's verification of the certificate, use  
the -k (or --insecure) option.  
'''

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 8:43pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/13 "2023-05-30T20:43:37Z")

</div>

Not working

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 30, 2023, 8:47pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/14 "2023-05-30T20:47:44Z")

</div>

> [@neil.maffitt](#):
>
> using the --cacert option.

So you are using your own CA not public CA.

Try this...

`curl -v -u elastic --cacert /fullpathtoCA.pem https://elastichost:9200`

Your clients will need your CA or it will needed to be added to the clients host CA trust store.

Nothing unusual/ elasticsearch special about this... All Normal cert stuff would be exactly the same if you were using Apache or Nginx.

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 9:03pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/15 "2023-05-30T21:03:52Z")

</div>

I create a CSR uploaded to CA  
Certificate was created and "Download Certificate mv (w/ chain), PEM encoded by Setigo"  
filename setigo.cer  
This not working  
curl -v -u elastic:password --cacert /etc/elastic/cert/setigo.cer [https://elastichost:9200](https://elastichost:9200)

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 9:28pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/16 "2023-05-30T21:28:51Z")

</div>

> [@stephenb](#):
>
> Your clients will need your CA or it will needed to be added to the clients host CA trust store.

The client in this case is curl on remote host

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 30, 2023, 9:44pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/17 "2023-05-30T21:44:18Z")

</div>

First please always show the comand AND response, can't help you without responses.

This needs to be the CA, not the cert.

`--cacert /etc/elastic/cert/setigo.cer`

Get your cert expert to get you the CA

> [@neil.maffitt](#):
>
> The client in this case is curl on remote host

So yes they will need the CA or that CA will need to be part of that host CA Truststore

OR you can run curl `--insecure` or `-k` which does not validate the cert and is not recommended.

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 10:03pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/18 "2023-05-30T22:03:43Z")

</div>

Sorry about that this was the response.

> [@neil.maffitt](#):
>
> curl performs SSL certificate verification by default, using a "bundle"  
> of Certificate Authority (CA) public keys (CA certs). If the default  
> bundle file isn't adequate, you can specify an alternate file  
> using the --cacert option.  
> If this HTTPS server uses a certificate signed by a CA represented in  
> the bundle, the certificate verification probably failed due to a  
> problem with the certificate (it might be expired, or the name might  
> not match the domain name in the URL).  
> If you'd like to turn off curl's verification of the certificate, use  
> the -k (or --insecure) option.

From above in thread you wrote  
"Generate your certs, put them in the config folders, make sure they are readable and properly config. Support PEM and P12s"

So in Elasticsearch yml has reference to pem encoded cert.  
and curl command line --cacert needs to be the CA

Not sure what this "This needs to be the CA" means but I guess that is why you suggested "Get your cert expert to get you the CA" Thank you

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 30, 2023, 10:06pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/19 "2023-05-30T22:06:42Z")

</div>

A CA is a Certificate Authority little explanation.

> **[What Is a Certificate Authority (CA)? - SSL.com](https://www.ssl.com/faqs/what-is-a-certificate-authority/)**
>
> A certificate authority (CA) is a an organization that acts to validate identities and bind them to cryptographic key pairs with digital certificates.

---

<div class="post-metadata">

**Author:** ![neil.maffitt](https://avatars.discourse-cdn.com/v4/letter/n/a5b964/32.png) [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Post date:** [May 30, 2023, 11:56pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713/20 "2023-05-30T23:56:10Z")

</div>

I assumed CA was for Cert Authority I don't under stand your comment in the context of a curl command.

> [@stephenb](#):
>
> This needs to be the CA, not the cert.
> 
> `--cacert /etc/elastic/cert/setigo.cer`

Did you mean the CA store file for the host and not the setigo.cer file?  
Thanks

[Next page](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713.md?page=2)
