# Faster/easier way to secure a v7 production-mode Cluster without loosing data

**URL:** <https://discuss.elastic.co/t/faster-easier-way-to-secure-a-v7-production-mode-cluster-without-loosing-data/305258>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 20, 2022, 7:37am UTC](https://discuss.elastic.co/t/faster-easier-way-to-secure-a-v7-production-mode-cluster-without-loosing-data/305258 "2022-05-20T07:37:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![hulaux](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@hulaux](https://discuss.elastic.co/u/hulaux)\
**Post date:** [May 20, 2022, 7:37am UTC](https://discuss.elastic.co/t/faster-easier-way-to-secure-a-v7-production-mode-cluster-without-loosing-data/305258/1 "2022-05-20T07:37:03Z")

</div>

Fact is one cannot use Elasticsearch-setup-passwords in a unsecure production-mode Elasticsearch 7.17 Cluster.

I know some people turned each possible master node into a single dev-mode cluster with data apart (so Elasticsearch-setup-passwords works fine) before reverting to a production-mode Cluster but I wonder if a simpler and/or faster way is safe.

For instance, did anybody succeed in using  
// Elasticsearch-setup-passwords interactive  
with the same set of passwords on every node (while ignoring the warning) then activate TLS transport ?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 20, 2022, 7:54am UTC](https://discuss.elastic.co/t/faster-easier-way-to-secure-a-v7-production-mode-cluster-without-loosing-data/305258/2 "2022-05-20T07:54:21Z")

</div>

You simply cannot setup passwords if security is not enabled. The endpoints that it uses will not exist on a cluster that does not have security turned on.

---

<div class="post-metadata">

**Author:** ![hulaux](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@hulaux](https://discuss.elastic.co/u/hulaux)\
**Post date:** [May 20, 2022, 8:32am UTC](https://discuss.elastic.co/t/faster-easier-way-to-secure-a-v7-production-mode-cluster-without-loosing-data/305258/3 "2022-05-20T08:32:50Z")

</div>

Thanks,

So I should fool the passwords setup tool, making it believe each node is a single one in a dev-mode Cluster, so I can get minimal security before shutting down Elasticsearch everywhere.

Of course, nothing new should be indexed meanwhile, so data consistency is preserved.

Then, assuming the set of passwords is the same everywhere, I should have no problem generating CA & common certificate before restarting the initial Cluster in production-mode, getting basic security at last.

Or will I just completely confuse the nodes of this Cluster in the end ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 20, 2022, 8:33am UTC](https://discuss.elastic.co/t/faster-easier-way-to-secure-a-v7-production-mode-cluster-without-loosing-data/305258/4 "2022-05-20T08:33:17Z")

</div>

> [@hulaux](#):
>
> Or will I just completely confuse the nodes of this Cluster in the end ?

Yep, you will.

---

<div class="post-metadata">

**Author:** ![hulaux](https://avatars.discourse-cdn.com/v4/letter/h/839c29/32.png) [@hulaux](https://discuss.elastic.co/u/hulaux)\
**Post date:** [May 20, 2022, 9:37am UTC](https://discuss.elastic.co/t/faster-easier-way-to-secure-a-v7-production-mode-cluster-without-loosing-data/305258/5 "2022-05-20T09:37:19Z")

</div>

Thanks again, another dead end I avoided with your help. 🕶

So, my only option with a reasonbly short performance impact is :

1. Make sure there is a primary shard for every index on the master node and shut down Elasticsearch everywhere
2. Restart this node as a single one in a dev-mode Cluster
3. Apply minimal then basic security setup procedures
4. Restart this node as a single one in a production-mode Cluster
5. Make a fresh install of Elasticsearch on every other node (loosing all previous shards within)
6. Start each of these empty nodes to join the Cluster
7. Wait for shards balancing across the Cluster

Did I miss a step ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2022, 9:37am UTC](https://discuss.elastic.co/t/faster-easier-way-to-secure-a-v7-production-mode-cluster-without-loosing-data/305258/6 "2022-06-17T09:37:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
