# Enabling Encryption for Nodes with basic license

**URL:** <https://discuss.elastic.co/t/enabling-encryption-for-nodes-with-basic-license/254071>\
**Category:** Elasticsearch\
**Created:** [November 2, 2020, 6:54pm UTC](https://discuss.elastic.co/t/enabling-encryption-for-nodes-with-basic-license/254071 "2020-11-02T18:54:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nikeee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikeee/32/77500_2.png) [@nikeee](https://discuss.elastic.co/u/nikeee)\
**Post date:** [November 2, 2020, 6:54pm UTC](https://discuss.elastic.co/t/enabling-encryption-for-nodes-with-basic-license/254071/1 "2020-11-02T18:54:46Z")

</div>

The license comparison matrix states:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d314fe800eb9da745b31025e9d3823f7bc7904f7.png)

...so I guess encrypted communication is included in the "basic" license.

[According to the docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-tls.html), `xpack.security.enabled` must be set to `true` for this.

Also according to the docs, `xpack.security.enabled` is set to `false` by default when using the basic license.

Is it possible with a basic license wo set it to `true`? If I do so, I get this error in elastic:

```auto
org.elasticsearch.ElasticsearchSecurityException: current license is non-compliant for [security]"

```

...which lets me think that the thing I'm trying to do is not possible.

I'm trying to downgrade the license of an existing cluster.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 2, 2020, 7:19pm UTC](https://discuss.elastic.co/t/enabling-encryption-for-nodes-with-basic-license/254071/2 "2020-11-02T19:19:07Z")

</div>

What is your version?

---

<div class="post-metadata">

**Author:** ![nikeee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikeee/32/77500_2.png) [@nikeee](https://discuss.elastic.co/u/nikeee)\
**Post date:** [November 2, 2020, 7:20pm UTC](https://discuss.elastic.co/t/enabling-encryption-for-nodes-with-basic-license/254071/3 "2020-11-02T19:20:18Z")

</div>

Sorry for not metioning. It's 7.5.0, deployed via docker.

When enabling security and the basic license, these are the two errors (which print the exception above):

```auto
blocking [cluster:monitor/stats] operation due to expired license.
collector [cluster_stats] failed to collect data

```

More specific, this is the log message:

```auto
{"type": "server", "timestamp": "2020-11-02T19:22:21,592Z", "level": "ERROR", "component": "o.e.x.s.a.f.SecurityActionFilter", "cluster.name": "docker-cluster", "node.name": "redacted", "message": "blocking [cluster:monitor/stats] operation due to expired license. Cluster health, cluster stats and indices stats \noperations are blocked on license expiration. All data operations (read and write) continue to work. \nIf you have a new license, please update it. Otherwise, please reach out to your support contact.", "cluster.uuid": "redacted", "node.id": "redacted" }
{"type": "server", "timestamp": "2020-11-02T19:22:21,592Z", "level": "ERROR", "component": "o.e.x.m.c.c.ClusterStatsCollector", "cluster.name": "docker-cluster", "node.name": "redacted", "message": "collector [cluster_stats] failed to collect data", "cluster.uuid": "redacted", "node.id": "redacted" ,
"stacktrace": ["org.elasticsearch.ElasticsearchSecurityException: current license is non-compliant for [security]",
"at org.elasticsearch.license.LicenseUtils.newComplianceException(LicenseUtils.java:27) ~[?:?]",
"at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.apply(SecurityActionFilter.java:79) ~[?:?]",
"at org.elasticsearch.action.support.TransportAction$RequestFilterChain.proceed(TransportAction.java:151) ~[elasticsearch-7.5.0.jar:7.5.0]",
"at org.elasticsearch.action.support.TransportAction.execute(TransportAction.java:129) ~[elasticsearch-7.5.0.jar:7.5.0]",
"at org.elasticsearch.action.support.TransportAction.execute(TransportAction.java:64) ~[elasticsearch-7.5.0.jar:7.5.0]",
"at org.elasticsearch.client.node.NodeClient.executeLocally(NodeClient.java:83) ~[elasticsearch-7.5.0.jar:7.5.0]",
"at org.elasticsearch.client.node.NodeClient.doExecute(NodeClient.java:72) ~[elasticsearch-7.5.0.jar:7.5.0]",
"at org.elasticsearch.client.support.AbstractClient.execute(AbstractClient.java:396) ~[elasticsearch-7.5.0.jar:7.5.0]",
"at org.elasticsearch.client.support.AbstractClient.execute(AbstractClient.java:385) ~[elasticsearch-7.5.0.jar:7.5.0]",
"at org.elasticsearch.client.support.AbstractClient$ClusterAdmin.execute(AbstractClient.java:679) ~[elasticsearch-7.5.0.jar:7.5.0]",
"at org.elasticsearch.action.ActionRequestBuilder.execute(ActionRequestBuilder.java:45) ~[elasticsearch-7.5.0.jar:7.5.0]",
"at org.elasticsearch.action.ActionRequestBuilder.get(ActionRequestBuilder.java:59) ~[elasticsearch-7.5.0.jar:7.5.0]",
"at org.elasticsearch.xpack.monitoring.collector.cluster.ClusterStatsCollector.lambda$doCollect$0(ClusterStatsCollector.java:95) ~[x-pack-monitoring-7.5.0.jar:7.5.0]",
"at org.elasticsearch.xpack.monitoring.collector.cluster.ClusterStatsCollector.doCollect(ClusterStatsCollector.java:99) ~[x-pack-monitoring-7.5.0.jar:7.5.0]",
"at org.elasticsearch.xpack.monitoring.collector.Collector.collect(Collector.java:88) [x-pack-monitoring-7.5.0.jar:7.5.0]",
"at org.elasticsearch.xpack.monitoring.MonitoringService$MonitoringExecution$1.doRun(MonitoringService.java:242) [x-pack-monitoring-7.5.0.jar:7.5.0]",
"at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-7.5.0.jar:7.5.0]",
"at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:515) [?:?]",
"at java.util.concurrent.FutureTask.run(FutureTask.java:264) [?:?]",
"at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:703) [elasticsearch-7.5.0.jar:7.5.0]",
"at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) [?:?]",
"at java.util.concurrent.ThreadPoolExecutor$Worker.run(Th

```

The env var `xpack.license.self_generated.type` of elasticsearch is set to `basic`.

Edit:  
Turns out that the env var mentioned above alone doesn't do anything. One has to start a basic license:

> **[Start basic API | Elasticsearch Reference \[7.9\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/start-basic.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2020, 7:20pm UTC](https://discuss.elastic.co/t/enabling-encryption-for-nodes-with-basic-license/254071/4 "2020-11-30T19:20:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
