# Elasticsearch Accessible Without Authentication

**URL:** <https://discuss.elastic.co/t/elasticsearch-accessible-without-authentication/204895>\
**Category:** Elasticsearch\
**Created:** [October 23, 2019, 2:56pm UTC](https://discuss.elastic.co/t/elasticsearch-accessible-without-authentication/204895 "2019-10-23T14:56:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [October 23, 2019, 2:56pm UTC](https://discuss.elastic.co/t/elasticsearch-accessible-without-authentication/204895/1 "2019-10-23T14:56:41Z")

</div>

How can we close or secure the accessibility of Elasticsearch? We are using Ubuntu servers and are using Elasticsearch 6.7.2. We are a custom Angular front end. Anybody seems to be able to reach or manipulate or do anything to the Elastic program if they have the host names. How can we go about updating or changing this.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 23, 2019, 3:32pm UTC](https://discuss.elastic.co/t/elasticsearch-accessible-without-authentication/204895/2 "2019-10-23T15:32:25Z")

</div>

From 6.8 some security features are available with the basic default license.

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [October 23, 2019, 3:34pm UTC](https://discuss.elastic.co/t/elasticsearch-accessible-without-authentication/204895/3 "2019-10-23T15:34:09Z")

</div>

Are there any with the 6.7.2 open source version? Or is there something that can be recommended for this version?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 23, 2019, 4:07pm UTC](https://discuss.elastic.co/t/elasticsearch-accessible-without-authentication/204895/4 "2019-10-23T16:07:29Z")

</div>

Upgrading should be easy.

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [October 23, 2019, 5:31pm UTC](https://discuss.elastic.co/t/elasticsearch-accessible-without-authentication/204895/5 "2019-10-23T17:31:13Z")

</div>

Does the 7.2 version have basic authentication features that are free?

Also what would be the steps to upgrade from 6.7.2. (installed).

How can we configure the basic authentication in the upgraded version?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 23, 2019, 6:40pm UTC](https://discuss.elastic.co/t/elasticsearch-accessible-without-authentication/204895/6 "2019-10-23T18:40:18Z")

</div>

> [@edster](#):
>
> Does the 7.2 version have basic authentication features that are free?

Yes. But you should upgrade then to 7.4.

> Also what would be the steps to upgrade from 6.7.2. (installed).

Read [Upgrade Elasticsearch | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-upgrade.html)

> How can we configure the basic authentication in the upgraded version?

Read [Configure security in Elasticsearch | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-security.html)

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [October 23, 2019, 8:10pm UTC](https://discuss.elastic.co/t/elasticsearch-accessible-without-authentication/204895/7 "2019-10-23T20:10:18Z")

</div>

Thank you very much. Much appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2019, 8:10pm UTC](https://discuss.elastic.co/t/elasticsearch-accessible-without-authentication/204895/8 "2019-11-20T20:10:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
