# How to disable X-Pack http basic auth keeping SSL?

**URL:** <https://discuss.elastic.co/t/how-to-disable-x-pack-http-basic-auth-keeping-ssl/123957>\
**Category:** Elasticsearch\
**Created:** [March 14, 2018, 5:01pm UTC](https://discuss.elastic.co/t/how-to-disable-x-pack-http-basic-auth-keeping-ssl/123957 "2018-03-14T17:01:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mglebka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mglebka/32/28907_2.png) [@mglebka](https://discuss.elastic.co/u/mglebka)\
**Post date:** [March 14, 2018, 5:01pm UTC](https://discuss.elastic.co/t/how-to-disable-x-pack-http-basic-auth-keeping-ssl/123957/1 "2018-03-14T17:01:38Z")

</div>

Hi ,

I have the following use case:  
I need to use https/ssl in elasticsearch but disable http basic auth.

My configuration is following:

`cluster.name: "docker-cluster"`  
`network.host: 0.0.0.0`  
`discovery.zen.minimum_master_nodes: 1`  
`xpack.ssl.key: /usr/share/elasticsearch/config/x-pack//node1.key`  
`xpack.ssl.certificate: /usr/share/elasticsearch/config/x-pack/node1.crt`  
`xpack.ssl.certificate_authorities: ["/usr/share/elasticsearch/config/x-pack/ca.crt"]`  
`xpack.security.transport.ssl.enabled: true`  
`xpack.security.http.ssl.enabled: true`  
`xpack.security.transport.ssl.verification_mode: certificate`

What are the means to do this ?

Thank you in advance !

Regards,  
Gleb

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 14, 2018, 11:34pm UTC](https://discuss.elastic.co/t/how-to-disable-x-pack-http-basic-auth-keeping-ssl/123957/2 "2018-03-14T23:34:49Z")

</div>

> [@mglebka](#):
>
> What are the means to do this ?

You need to implement this by enabling anonymous access.

SSL is tied into the same feature setting as authentication, so you cannot enable SSL without also enabling authentication.

First, a warning:  
**Are you really sure you want to do this?**  
It seems quite strange to want to use the confidentiality and integrity features that SSL provides, but then have absolutely no authentication or access controls on your data.  
If you think you need `https`, then you should really consider enabling authentication as well.

Now, for enabling anonymous access, see here: [Action [cluster:monitor/main] is unauthorized for user - #2 by Turbo\_Fredriksson](https://discuss.elastic.co/t/action-cluster-monitor-main-is-unauthorized-for-user/119074/2)

---

<div class="post-metadata">

**Author:** ![mglebka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mglebka/32/28907_2.png) [@mglebka](https://discuss.elastic.co/u/mglebka)\
**Post date:** [March 15, 2018, 6:10pm UTC](https://discuss.elastic.co/t/how-to-disable-x-pack-http-basic-auth-keeping-ssl/123957/3 "2018-03-15T18:10:02Z")

</div>

@TimV, thank you for response , solution that you provided works !  
Unfortunately, I need to disable basic authentication because of requirements.

Thanks !

Regards,  
Gleb

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2018, 6:10pm UTC](https://discuss.elastic.co/t/how-to-disable-x-pack-http-basic-auth-keeping-ssl/123957/4 "2018-04-12T18:10:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
