# Has anyone been successful configuring "free" TLS in 7.1?

**URL:** https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343
**Category:** Elasticsearch
**Created:** [May 23, 2019, 5:20am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343 "2019-05-23T05:20:18Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![mwarren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mwarren/32/47776_2.png) [@mwarren](https://discuss.elastic.co/u/mwarren)
#### Post date: [May 23, 2019, 5:20am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343/1 "2019-05-23T05:20:18Z")

</div>

I had xpack security working on a six node cluster using a trial of v6. But now I find the documentation is unclear on how to configure the non xpack security. I used this blog as a guide but it got me no where. Is there any other clear examples I can reference?

> **[Secure Elasticsearch with TLS encryption and role-based access control](https://www.elastic.co/blog/getting-started-with-elasticsearch-security)**
>
> Secure your Elasticsearch clusters -- and the other components of the Elastic Stack -- with node-to-node TLS and role-based access control (RBAC). These features and more are now available free with the default distribution of Elasticsearch and...

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [May 23, 2019, 5:35am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343/2 "2019-05-23T05:35:14Z")

</div>

There is an online training available: [https://training.elastic.co/elearning/elastic-stack-management/fundamentals-of-securing-elasticsearch-launch-promo](https://training.elastic.co/elearning/elastic-stack-management/fundamentals-of-securing-elasticsearch-launch-promo)

It's free before May 31st. May be do that?

Otherwise I think you need to exactly describe what you did and what is failing. Also share logs, config would help.

---

<div class="post-metadata">

### Author: ![mwarren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mwarren/32/47776_2.png) [@mwarren](https://discuss.elastic.co/u/mwarren)
#### Post date: [May 23, 2019, 6:02am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343/3 "2019-05-23T06:02:17Z")

</div>

Thanks David. I registered for the elearning offer. I have done many steps but here is a basic question. To use the free security features, do I set the following to true or false in elasticsearch.yml?  
**xpack.security.enabled: true**

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [May 23, 2019, 6:04am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343/4 "2019-05-23T06:04:09Z")

</div>

You set it to true. Security is configured exactky the same way as before as it is only the licence level required that has changed.

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [May 24, 2019, 2:25am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343/5 "2019-05-24T02:25:43Z")

</div>

> [@mwarren](#):
>
> how to configure the non xpack security

The confusion here seems to stem from a misunderstanding of terminology.  
There is no "non xpack security" in our packages, there is just "Security" which is a part of X-Pack, and for which we have recently moved some features from being paid to being free.

X-Pack refers to all the features that we offer that are under our Elastic license rather than the (OSS) Apache License.  
Some of those features are free, and some require a paid license, but they are all "X-Pack".

---

<div class="post-metadata">

### Author: ![mwarren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mwarren/32/47776_2.png) [@mwarren](https://discuss.elastic.co/u/mwarren)
#### Post date: [May 24, 2019, 3:00am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343/6 "2019-05-24T03:00:09Z")

</div>

Thanks Tom for clarifying. I should be ok from here, but I would recommend some ppl validate the blog details in my original post for correctness as following it as a guide and adjusting the steps to my environment resulted in a fail.

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [May 24, 2019, 4:37am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343/7 "2019-05-24T04:37:15Z")

</div>

> [@mwarren](#):
>
> following it as a guide and adjusting the steps to my environment resulted in a fail.

Can you tell us what failed?  
Everything in that blog post was tested as it was written, and it all looks fine to me. It may be that there is someting unusual about your environment that requires special steps, but without knowing what problems you ran into, it's hard to know what we could change.

---

<div class="post-metadata">

### Author: ![mwarren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mwarren/32/47776_2.png) [@mwarren](https://discuss.elastic.co/u/mwarren)
#### Post date: [May 24, 2019, 4:49am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343/8 "2019-05-24T04:49:52Z")

</div>

My log file is too long to post... but isn't true that inter-communication on same server doesn't use external encrypted channels? If true, I'm wondering how the blog example demonstrates as an example of encryption. I mean won't it always work?

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [May 24, 2019, 5:31am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343/9 "2019-05-24T05:31:58Z")

</div>

> [@mwarren](#):
>
> but isn't true that inter-communication on same server doesn't use external encrypted channels?

No, that isn't true.  
Two nodes on the same server will communicate via TCP/IP. The Operating System should optimise that case and not actually send anything over the physical network, but we will still do full TLS handshaking and encryption on that channel.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 21, 2019, 5:32am UTC](https://discuss.elastic.co/t/has-anyone-been-successful-configuring-free-tls-in-7-1/182343/10 "2019-06-21T05:32:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
