# Encrypting Communications in an Elasticsearch Docker Image

**URL:** <https://discuss.elastic.co/t/encrypting-communications-in-an-elasticsearch-docker-image/119095>\
**Category:** Elasticsearch\
**Created:** [February 8, 2018, 5:18pm UTC](https://discuss.elastic.co/t/encrypting-communications-in-an-elasticsearch-docker-image/119095 "2018-02-08T17:18:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 8, 2018, 5:18pm UTC](https://discuss.elastic.co/t/encrypting-communications-in-an-elasticsearch-docker-image/119095/1 "2018-02-08T17:18:44Z")

</div>

I'm going over [Encrypting Communications in an Elasticsearch Docker Image | Elasticsearch Reference](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-tls-docker.html). While preparing the environment, I had to create `instances.yml` file, which will be used by `create_certs` later on.

Can someone shed some light on what is `dns` vars for, especially localhost part. Is that being part of FQDN for node?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [February 9, 2018, 11:33am UTC](https://discuss.elastic.co/t/encrypting-communications-in-an-elasticsearch-docker-image/119095/2 "2018-02-09T11:33:24Z")

</div>

The content of the `dns` and `ip` section is translated into a [Subject Alternative Name](https://en.wikipedia.org/wiki/Subject_Alternative_name) inside the generated certificates. Usually, you would put the hostname and/or the FQDN of your server here. Under docker, Elasticsearch binds to the `localhost` interface of the container, and external mapping is done via docker. AFAIK, for this to work correctly in a `docker-compose` setup, the IP address (`127.0.0.1`) and DNS name of the `localhost` interface have to be added to the SAN as well.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 9, 2018, 5:00pm UTC](https://discuss.elastic.co/t/encrypting-communications-in-an-elasticsearch-docker-image/119095/3 "2018-02-09T17:00:23Z")

</div>

if I already have wildcard certificate that I'm paying for, would that makes any sense to use that certificate for nodes as well?

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [February 10, 2018, 11:21am UTC](https://discuss.elastic.co/t/encrypting-communications-in-an-elasticsearch-docker-image/119095/4 "2018-02-10T11:21:37Z")

</div>

I haven't tried this myself, yet, to use a wildcard certificate issued by one of the trusted CAs. However, you should be able to adjust the instructions to replace the self-signed certificates with those obtained from your CA.

If things go wrong, there are various settings that change the `ssl.verification_mode`, that can be used to relax the verification policy in use. Depending on where errors occur, you may want to relax the setting to e.g. `certificate`. See the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html) for more details.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2018, 11:21am UTC](https://discuss.elastic.co/t/encrypting-communications-in-an-elasticsearch-docker-image/119095/5 "2018-03-10T11:21:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
