# Enabling http & https connections to elastic

**URL:** <https://discuss.elastic.co/t/enabling-http-https-connections-to-elastic/276141>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 16, 2021, 12:38pm UTC](https://discuss.elastic.co/t/enabling-http-https-connections-to-elastic/276141 "2021-06-16T12:38:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jdswifty](https://avatars.discourse-cdn.com/v4/letter/j/779978/32.png) [@jdswifty](https://discuss.elastic.co/u/jdswifty)\
**Post date:** [June 16, 2021, 12:38pm UTC](https://discuss.elastic.co/t/enabling-http-https-connections-to-elastic/276141/1 "2021-06-16T12:38:22Z")

</div>

Running Elasticsearch 7.11 & getting towards the end of a piece of work to enable TLS across the platform  
I'm now at the point i need to enable tls on the http connections for the ingest nodes but I need to be able to still allow non tls traffic until I've finished reconfiguring our many logstash outputs.

I cant see anything obvious from the docs on how to do this & testing in our TPOC env it seems to be either tls or not.

My fall back is to only enable TLS on 2 out of the 3 ingest nodes & then reconfigure the logstash pipelines to target the non tls one & slowly then migrate them back over to the TLS enabled  
but that means making 3 updates to each of the pipelines

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 17, 2021, 1:11am UTC](https://discuss.elastic.co/t/enabling-http-https-connections-to-elastic/276141/2 "2021-06-17T01:11:24Z")

</div>

You cannot have some nodes in your cluster running without, so it's an all in one approach unfortunately.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 17, 2021, 1:17am UTC](https://discuss.elastic.co/t/enabling-http-https-connections-to-elastic/276141/3 "2021-06-17T01:17:36Z")

</div>

You will need to enable TLS on the `transport` port (9300) for all nodes.

For HTTP (port 9200), you can have some nodes with TLS and some without.  
However, you need to be careful with that - some features such as access tokens and API keys are only enabled on nodes with HTTPS, so you will have a different feature set between nodes.

You will also need to be careful with how your clients do node selection - if they sniff then they also need to be aware of which nodes use TLS and which ones don't.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2021, 1:18am UTC](https://discuss.elastic.co/t/enabling-http-https-connections-to-elastic/276141/4 "2021-07-15T01:18:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
