# How to configure basic security on elastic stack?

**URL:** <https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 12, 2021, 11:09am UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479 "2021-10-12T11:09:54Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mamol27](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mamol27/32/82016_2.png) [@Mamol27](https://discuss.elastic.co/u/Mamol27)\
**Post date:** [October 12, 2021, 11:09am UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479/1 "2021-10-12T11:09:54Z")

</div>

I have elastic stack.  
I need to configure basic security.  
When I add `xpack.security.enabled: true` in `elasticsearch.yml` it fails to start with message  
`bootstrap check failure [1] of [1]: Transport SSL must be enabled if security is enabled on a [basic] license. Please set [xpack.security.transport.ssl.enabled] to [true] or disable security by setting [xpack.security.enabled] to [false]`

When I add `xpack.security.transport.ssl.enabled: true` it writes to me  
`Failed to determine the health of the cluster running at http://172.29.39.145:9200 Unexpected response code [503] from calling GET http://172.29.39.145:9200/_cluster/health?pretty Cause: master_not_discovered_exception`

In your documentation says [Set up minimal security for Elasticsearch | Elasticsearch Guide [7.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-minimal-setup.html#_enable_elasticsearch_security_features) that I need add only ` xpack.security.enabled: true` on every node, what i did.

So how to configure minimal security?

---

<div class="post-metadata">

**Author:** ![n2x4](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@n2x4](https://discuss.elastic.co/u/n2x4)\
**Post date:** [October 12, 2021, 11:36am UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479/2 "2021-10-12T11:36:30Z")

</div>

Not only do you have to enable xpack security in your Elasticsearch.yml for transport, but you also have to do it for http and you need to go through the same process for Kibana. Take a look at this guide - [How to install Elastic SIEM and Elastic EDR - On The Hunt (newtonpaul.com)](https://newtonpaul.com/how-to-install-elastic-siem-and-elastic-edr/)

It covers setting up SSL. There are a few minor tweaks to the configs regarding syntax since it was released, but it should get you where you need to be.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 13, 2021, 1:32am UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479/3 "2021-10-13T01:32:03Z")

</div>

> [@Mamol27](#):
>
> In your documentation says [Set up minimal security for Elasticsearch | Elasticsearch Guide [7.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-minimal-setup.html#_enable_elasticsearch_security_features) that I need add only ` xpack.security.enabled: true` on every node, what i did.

Setting up [minimal security](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-minimal-setup.html#_enable_elasticsearch_security_features) is different from setting up [basic security](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html).

As documented, minimal security is not suitable for production. You should only use it if your cluster is for development purpose, e.g. a single node cluster running locally or all nodes are running locally and bind on localhost.

If your cluster is not suitable for minimal security, you need at least basic security which involves setting up TLS on transport level. This includes configuring `xpack.security.transport.ssl.enabled: true` as well as generating and configuring relevant CA and certificates for which you can follow the instruction of [setting up basic security](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html).

---

<div class="post-metadata">

**Author:** ![Mamol27](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mamol27/32/82016_2.png) [@Mamol27](https://discuss.elastic.co/u/Mamol27)\
**Post date:** [October 13, 2021, 8:16am UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479/4 "2021-10-13T08:16:16Z")

</div>

You want to say, that I should skip minimal security, when am I configuring basic security?

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 13, 2021, 11:11am UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479/5 "2021-10-13T11:11:03Z")

</div>

> [@Mamol27](#):
>
> You want to say, that I should skip minimal security, when am I configuring basic security?

No. The documentations are laid out in a way that stronger security configuration is built on top of previous lesser ones. So if you want basic security, you'd following relevant instruction of minimal security first, then move onto the basic.

---

<div class="post-metadata">

**Author:** ![Martin\_Emanuelsson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_emanuelsson/32/78061_2.png) [@Martin\_Emanuelsson](https://discuss.elastic.co/u/Martin_Emanuelsson)\
**Post date:** [October 21, 2021, 1:33pm UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479/6 "2021-10-21T13:33:12Z")

</div>

I'm experiencing the exact same problem that @Mamol27 is referring to here. Trying to follow the instructions ([Set up minimal security for Elasticsearch | Elasticsearch Guide [7.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/security-minimal-setup.html)) for setting up minimal security prior to going forward with setting up basic security, as you say we should do @Yang_Wang .

In a cluster of three servers I do this:

1. Shut down all instances of Elasticsearch
2. Add the setting `xpack.security.enabled: true`
3. Start Elasticsearch again, this will result in each node shutting down again with the error message ` Transport SSL must be enabled if security is enabled on a [basic] license. Please set [xpack.security.transport.ssl.enabled] to [true] or disable security by setting [xpack.security.enabled] to [false]`
4. So I add the mentioned setting: `xpack.security.transport.ssl.enabled: true`
5. Start Elasticsearch again, this will throw this error message:

```auto
exception caught on transport layer [Netty4TcpChannel{localAddress=0.0.0.0/0.0.0.0:9300, remoteAddress=/10.58.66.139:52938}], closing connection
io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: No available authentication scheme etc.

```

1. If I ignore this error message and go forward with the instructions by calling `elasticsearch-setup-passwords interactive` I get an error message saying `Failed to determine the health of the cluster running at http://localhost:9203 Unexpected response code [503] from calling GET http://localhost:9203/_cluster/health?pretty Cause: master_not_discovered_exception`

Something must be missing in this workflow or did you manage to move forward with this problem @Manol27

Maybe should mention that we're currently running version 7.4.2 of Elasticsearch. Wanted to enable minimal and basic security before moving forward with upgrading to the current version (7.15.1)

Here is also the config on the server where I'm trying to setup passwords:

```auto
bootstrap.memory_lock: true
cluster.name: ClusterName
cluster.initial_master_nodes:
  - node01
discovery.seed_hosts:
  - node01.domain.com
  - node02.domain.com
  - node03.domain.com
http.port: 9203
network.host: node01.domain.com, _local_
node.data: true
node.ingest: true
node.master: true
node.max_local_storage_nodes: 1
node.name: node01
path.data: C:\ProgramData\Elastic\Elasticsearch\data
path.logs: C:\ProgramData\Elastic\Elasticsearch\logs
transport.tcp.port: 9300
xpack.license.self_generated.type: basic
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true

```

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 25, 2021, 4:37am UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479/7 "2021-10-25T04:37:46Z")

</div>

@Martin_Emanuelsson Since your cluster have multiple nodes running on different hosts, minimal security alone is not going to work for you. Please note the documentation says:

> The minimal security scenario is not sufficient for [production mode](https://www.elastic.co/guide/en/elasticsearch/reference/current/bootstrap-checks.html#dev-vs-prod-mode) clusters. If your cluster has multiple nodes, you must enable minimal security and then [configure Transport Layer Security (TLS)](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html) between nodes.

What you need is to following both "minimal security" and "basic security" (in that order) and only restart your cluster at the end of configuring "basic security" (because minimal security alone does not work as you have discovered already)

What your cluster currently missing is TLS related configuration, i.e. TLS certificate, key and CA. You can follow the [relevant section in Basic Security](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html#generate-certificates). I believe they should work for 7.4.2 as well.

---

<div class="post-metadata">

**Author:** ![Mamol27](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mamol27/32/82016_2.png) [@Mamol27](https://discuss.elastic.co/u/Mamol27)\
**Post date:** [October 27, 2021, 8:06am UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479/8 "2021-10-27T08:06:55Z")

</div>

I solve it by removing data folder on each node and run again with **only** minimal security.  
You shouldn't run your cluster before minimal security is on.

You can't generate certificates without minimal security.

---

<div class="post-metadata">

**Author:** ![Martin\_Emanuelsson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_emanuelsson/32/78061_2.png) [@Martin\_Emanuelsson](https://discuss.elastic.co/u/Martin_Emanuelsson)\
**Post date:** [October 28, 2021, 8:03am UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479/9 "2021-10-28T08:03:03Z")

</div>

OK, the part of not starting the nodes in the cluster before finalizing both minimal and basic security has not been very clear to me, thanks for mentioning that, will give that a try.

But, just to be perfectly clear here. I need to take down all nodes in the cluster, set the xpack.security.enabled-setting to true, setup TLS between the nodes. Then start the nodes to be able to create passwords (part of the minimal security settings)?

Can I generate certificates (call Elasticsearch-certutil) without having Elasticsearch running?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 25, 2021, 8:04am UTC](https://discuss.elastic.co/t/how-to-configure-basic-security-on-elastic-stack/286479/10 "2021-11-25T08:04:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
