# ELK stack elasticsearch FIPS Keytool Certificates

**URL:** <https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 14, 2023, 11:08pm UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088 "2023-09-14T23:08:14Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kris\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_u/32/123566_2.png) [@Kris\_U](https://discuss.elastic.co/u/Kris_U)\
**Post date:** [September 14, 2023, 11:08pm UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088/1 "2023-09-14T23:08:14Z")

</div>

I am setting up an ELK stack version 7.17.12. We have a separate instance for Elasticsearch, Kibana, and Logstash - but only one instance for each. We are using it with a Wazuh Manager instance as well with a Logstash and Wazuh integration. I am testing out making as much of it FIPS compliant as possible starting with Elasticsearch.

Right now we are using the certutil ca command from the Wazuh Distributed  
guides (single node clusters only). Then copying the secure communication certs to the Kibana and Logstash instance. Command to generate example:

`/usr/share/elasticsearch/bin/elasticsearch-certutil cert ca --pem --in instances.yml --keep-ca-key --out ~/certs.zip`

I know for FIPS we need to use the keytool with password, Bouncy Castle, etc. I have seen this post for example: [ElasticSearch FIPS (BouncyCastle)](https://discuss.elastic.co/t/elasticsearch-fips-bouncycastle/303298/6).

I just am not sure how to setup the certificates for secure communication in FIPS mode and add them to the Keystore in the BCFKS format (assuming they do in fact go in the keystore - it's very unclear what's supposed to even be in there) so it all works together. I am coming up pretty empty except for the post above.

Then if I am using the Keystore for the certificates on Elasticsearch - do I need to setup the keystore on Kibana and Logstash too? How would that setup and import be achieved?

Another question is are there any issues with the setup-passwords tool for the default accounts and FIPS? Or would I need to change them after creation if I am using pbkdf2\_stretch in the elasticsearch yaml?

[Elasticsearch FIPS 140-2](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/fips-140-compliance.html#fips-140-compliance)

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 15, 2023, 3:49am UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088/2 "2023-09-15T03:49:05Z")

</div>

> [@Kris\_U](#):
>
> I know for FIPS we need to use the keytool with password, Bouncy Castle, etc.

Why do you believe this to be true?

If you use the BC FIPS security provider then you need to convert the system Keystore/truststore to BCFKS because PKCS#12 is not FIPS compatible, so the BC FIPS provider is not able to read the truststore that ships with the JDK.  
However, I am not aware of any reason why you cannot use PEM certificates and keys on a FIPS mode JVM.

---

<div class="post-metadata">

**Author:** ![Kris\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_u/32/123566_2.png) [@Kris\_U](https://discuss.elastic.co/u/Kris_U)\
**Post date:** [September 15, 2023, 2:11pm UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088/3 "2023-09-15T14:11:09Z")

</div>

Interesting - I will research PEM certificates and FIPS mode. Thanks!

---

<div class="post-metadata">

**Author:** ![Kris\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_u/32/123566_2.png) [@Kris\_U](https://discuss.elastic.co/u/Kris_U)\
**Post date:** [September 15, 2023, 4:40pm UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088/4 "2023-09-15T16:40:47Z")

</div>

Also where do I put the Bouncy Castle .jar file? There is no ext directory in /usr/share/elasticsearch/jdk/lib. Am I missing something here?

---

<div class="post-metadata">

**Author:** ![Kris\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_u/32/123566_2.png) [@Kris\_U](https://discuss.elastic.co/u/Kris_U)\
**Post date:** [September 15, 2023, 4:59pm UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088/5 "2023-09-15T16:59:27Z")

</div>

Yeah, it looks like there's not really a way to generate FIPS pem certificates in Ubuntu 20.04 because they aren't on OpenSSL version 3 yet and the module has only been validated for Ubuntu 22.04 anyway.

[Elasticsearch FIPS 140-2](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/fips-140-compliance.html#fips-140-compliance) specifies that the certutil isn't FIPS compliant either.

If anyone has any steps for setting up the truststore to be FIPS compliant and work with my configuration it would be much appreciated.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 20, 2023, 1:55am UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088/6 "2023-09-20T01:55:24Z")

</div>

Do you need to generate certificates using a FIPS enabled tool chain?  
You can generate the certs somewhere else and copy them over.

---

<div class="post-metadata">

**Author:** ![Kris\_U](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_u/32/123566_2.png) [@Kris\_U](https://discuss.elastic.co/u/Kris_U)\
**Post date:** [September 21, 2023, 11:51pm UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088/7 "2023-09-21T23:51:41Z")

</div>

Actually - I may be wrong about OpenSSL on Ubuntu 20.04 - apparently if it's in FIPS mode it may be validated.

Also the elasticsearch-certutil uses Bouncy Castle OpenSSL - I saw it in the code. However the cryptographic modules that have been verified for Bouncy Castle ran on a VMware OS - not Ubuntu. But then if that matters - how can Bouncy Castle be used on the JVM for FIPS on an Ubuntu operating system? And why can't we use elasticsearch-certutil in Elasticsearch FIPS mode? because everything I can find says it should be validated if Bouncy Castle modules are validated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2023, 11:52pm UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088/8 "2023-10-19T23:52:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
