# Enable Security with zero downtime

**URL:** <https://discuss.elastic.co/t/enable-security-with-zero-downtime/190844>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 17, 2019, 12:09am UTC](https://discuss.elastic.co/t/enable-security-with-zero-downtime/190844 "2019-07-17T00:09:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![P\_Gong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/p_gong/32/48475_2.png) [@P\_Gong](https://discuss.elastic.co/u/P_Gong)\
**Post date:** [July 17, 2019, 12:09am UTC](https://discuss.elastic.co/t/enable-security-with-zero-downtime/190844/1 "2019-07-17T00:09:03Z")

</div>

We already have an ES cluster running WITHOUT authentication and TLS. We are trying to enable the security feature.  
Is it possible to achieve this with zero down time? Two aspects of the problem:

1. Cluster internal communication. Once `xpack.security.transport.ssl.enabled` on some nodes are enabled.  
Is it still possible for nodes(disabled) to communicate with nodes(enabled)?  
If it is not possible, will the cluster be in a consistent state after we rolling upgrade all of the nodes?

2. Is there way for ES to have one port for http and another port for https? So we can rolling upgrade application to switch to https(from http)?

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![gabriel\_tessier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel_tessier/32/27911_2.png) [@gabriel\_tessier](https://discuss.elastic.co/u/gabriel_tessier)\
**Post date:** [July 17, 2019, 12:59am UTC](https://discuss.elastic.co/t/enable-security-with-zero-downtime/190844/2 "2019-07-17T00:59:25Z")

</div>

Hi @P_Gong,

According to the documentation you must do a full restart:

> Enabling TLS requires a full cluster restart. Nodes that have TLS enabled cannot communicate with nodes that do not have TLS enabled. You must restart all nodes to maintain communication across the cluster.

As the TLS lower version is from version 6.8 I guess that you may upgrade to at least this version...

> **[Upgrading the Elastic Stack | Installation and Upgrade Guide \[6.8\] | Elastic](https://www.elastic.co/guide/en/elastic-stack/6.8/upgrading-elastic-stack.html)**

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [July 17, 2019, 7:24am UTC](https://discuss.elastic.co/t/enable-security-with-zero-downtime/190844/3 "2019-07-17T07:24:55Z")

</div>

What @gabriel_tessier says is right, but just to add that this is [something we're working on](https://github.com/elastic/elasticsearch/issues/39531).

---

<div class="post-metadata">

**Author:** ![P\_Gong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/p_gong/32/48475_2.png) [@P\_Gong](https://discuss.elastic.co/u/P_Gong)\
**Post date:** [July 17, 2019, 4:21pm UTC](https://discuss.elastic.co/t/enable-security-with-zero-downtime/190844/4 "2019-07-17T16:21:38Z")

</div>

Thanks a lot @gabriel_tessier, @DavidTurner

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2019, 4:33pm UTC](https://discuss.elastic.co/t/enable-security-with-zero-downtime/190844/5 "2019-08-14T16:33:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
