# Enable xpack authentication without TLS with GOLD license

**URL:** <https://discuss.elastic.co/t/enable-xpack-authentication-without-tls-with-gold-license/127974>\
**Category:** Elasticsearch\
**Created:** [April 13, 2018, 12:19pm UTC](https://discuss.elastic.co/t/enable-xpack-authentication-without-tls-with-gold-license/127974 "2018-04-13T12:19:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jgb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jgb/32/26089_2.png) [@jgb](https://discuss.elastic.co/u/jgb)\
**Post date:** [April 13, 2018, 12:19pm UTC](https://discuss.elastic.co/t/enable-xpack-authentication-without-tls-with-gold-license/127974/1 "2018-04-13T12:19:37Z")

</div>

Hello,

In our project we have a GOLD elastic license, but in order to put it into elastic cluster it says that we need to enable TLS or disable security (setting `xpack.security.enabled: false`).

There is a way to use xpack authentication without TLS? Or at least a way to avoid ssl calls from clients? I read this documentation: [https://www.elastic.co/guide/en/elasticsearch/reference/6.2/separating-node-client-traffic.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/separating-node-client-traffic.html) but I can't do it work...

Thanks!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 13, 2018, 1:41pm UTC](https://discuss.elastic.co/t/enable-xpack-authentication-without-tls-with-gold-license/127974/2 "2018-04-13T13:41:01Z")

</div>

Hi José

TLS for the transport layer is a requirement after 6.0 for enabling X-Pack security. However, if for some reason you want your clients to communicate and authenticate to your cluster over plaintext HTTP, you can keep TLS on the http layer disabled (although this is not considered best practice)

See [this](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/configuring-tls.html#tls-transport) for enabling TLS on transport layer only.

Does this satisfy your use case?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2018, 1:41pm UTC](https://discuss.elastic.co/t/enable-xpack-authentication-without-tls-with-gold-license/127974/3 "2018-05-11T13:41:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
