# Enable TLS between ES and Kibana on an existing cluster

**URL:** <https://discuss.elastic.co/t/enable-tls-between-es-and-kibana-on-an-existing-cluster/266770>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [March 10, 2021, 8:08am UTC](https://discuss.elastic.co/t/enable-tls-between-es-and-kibana-on-an-existing-cluster/266770 "2021-03-10T08:08:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![xcompass](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xcompass/32/85289_2.png) [@xcompass](https://discuss.elastic.co/u/xcompass)\
**Post date:** [March 10, 2021, 8:08am UTC](https://discuss.elastic.co/t/enable-tls-between-es-and-kibana-on-an-existing-cluster/266770/1 "2021-03-10T08:08:05Z")

</div>

Hi,

I have a running ECK cluster (ES+Kibana) provisioned with `http.tls.selfSignedCertificate.disabled: true`.  
Now, I would like to try out alerts, which requires TLS to be enabled. I tried to change the above settings to:

```auto
    http:
      tls:
        selfSignedCertificate:
          #disabled: true
          # add a list of SANs into the self-signed HTTP certificate
          subjectAltNames:
          - dns: elasticsearch-logging-es-http
          - dns: elasticsearch-logging-es-http.default.svc
          - dns: elasticsearch-logging-es-http.default.svc.cluster.local

```

and did `kubectl apply -f es.yaml`. The es cluster still on http.

```auto
▶ k describe svc elasticsearch-logging-es-http -n logging
Name: elasticsearch-logging-es-http
Namespace: logging
Labels: common.k8s.elastic.co/type=elasticsearch
                   elasticsearch.k8s.elastic.co/cluster-name=elasticsearch-logging
Annotations: <none>
Selector: common.k8s.elastic.co/type=elasticsearch,elasticsearch.k8s.elastic.co/cluster-name=elasticsearch-logging
Type: ClusterIP
IP: 10.3.0.156
Port: http 9200/TCP
TargetPort: 9200/TCP
Endpoints: 10.2.115.5:9200,10.2.117.5:9200,10.2.39.5:9200
Session Affinity: None
Events: <none>

```

Also tried to delete the svc and it was recreated with http again.

Anyway I can enable TLS on an existing cluster? Thanks.

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [March 10, 2021, 8:40am UTC](https://discuss.elastic.co/t/enable-tls-between-es-and-kibana-on-an-existing-cluster/266770/2 "2021-03-10T08:40:06Z")

</div>

Hey @xcompass,  
What you did looks correct. The service keeps its name `*-es-http` though (it is still the HTTP protocol, even though encrypted with TLS), but Elasticsearch itself should only be reachable through HTTPS. You can `curl` the endpoint using https to verify that's the case.

---

<div class="post-metadata">

**Author:** ![xcompass](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xcompass/32/85289_2.png) [@xcompass](https://discuss.elastic.co/u/xcompass)\
**Post date:** [March 10, 2021, 7:38pm UTC](https://discuss.elastic.co/t/enable-tls-between-es-and-kibana-on-an-existing-cluster/266770/3 "2021-03-10T19:38:47Z")

</div>

Thanks @sebgl for the reply. I actually did test https with curl, and got the following error:

```auto
[root@elasticsearch-logging-es-default-2 elasticsearch]# curl https://localhost:9200
curl: (35) error:1408F10B:SSL routines:ssl3_get_record:wrong version number

```

If I use http, I got correct response:

```auto
[root@elasticsearch-logging-es-default-2 elasticsearch]# curl http://localhost:9200
{"error":{"root_cause":[{"type":"security_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":"Basic realm=\"security\" charset=\"UTF-8\""}}],"type":"security_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":"Basic realm=\"security\" charset=\"UTF-8\""}},"status":401}

```

I did more testing and found out I have to change the following to force ES to be on https:

```auto
spec:
  nodeSets:
    - name: default
      config:
        xpack.security.http.ssl.enabled: true # I know this is not recommended
      podTemplate:
        spec:
          containers:
            - name: elasticsearch
              env:
                - name: READINESS_PROBE_PROTOCOL
                  value: "https"

```

But the svc still use shows http under port as shown in my original post. (I understand the svc name contains http and it doesn't matter)

```auto
Port: http 9200/TCP

```

I deployed a new "quickstart" cluster and the svc shown as https:

```auto
▶ k describe svc quickstart-es-http
Name: quickstart-es-http
Namespace: default
Labels: common.k8s.elastic.co/type=elasticsearch
                   elasticsearch.k8s.elastic.co/cluster-name=quickstart
Annotations: <none>
Selector: common.k8s.elastic.co/type=elasticsearch,elasticsearch.k8s.elastic.co/cluster-name=quickstart
Type: ClusterIP
IP: 10.3.0.171
Port: https 9200/TCP
TargetPort: 9200/TCP
Endpoints: 10.2.10.8:9200
Session Affinity: None
Events: <none>

```

I think this causes kibana to connect ES using http instead of https. Is there a way to force operator generate https on the svc so kibana can get the correct reference? Or is it a bug that operator didn't pick up the change and generate the correct svc?

---

<div class="post-metadata">

**Author:** ![xcompass](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xcompass/32/85289_2.png) [@xcompass](https://discuss.elastic.co/u/xcompass)\
**Post date:** [March 10, 2021, 8:20pm UTC](https://discuss.elastic.co/t/enable-tls-between-es-and-kibana-on-an-existing-cluster/266770/4 "2021-03-10T20:20:06Z")

</div>

I was able to fix the issue by setting

```auto
    http:
      tls:
        selfSignedCertificate:
          disabled: false

```

explicitly. No other setting needed. Not sure why it didn't work last night. I must miss something.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2021, 8:20pm UTC](https://discuss.elastic.co/t/enable-tls-between-es-and-kibana-on-an-existing-cluster/266770/5 "2021-04-07T20:20:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
