# How to set up third party https requests to Elasticsearch

**URL:** <https://discuss.elastic.co/t/how-to-set-up-third-party-https-requests-to-elasticsearch/363560>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 22, 2024, 1:33pm UTC](https://discuss.elastic.co/t/how-to-set-up-third-party-https-requests-to-elasticsearch/363560 "2024-07-22T13:33:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Knut\_Knackwurst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/knut_knackwurst/32/124748_2.png) [@Knut\_Knackwurst](https://discuss.elastic.co/u/Knut_Knackwurst)\
**Post date:** [July 22, 2024, 1:33pm UTC](https://discuss.elastic.co/t/how-to-set-up-third-party-https-requests-to-elasticsearch/363560/1 "2024-07-22T13:33:59Z")

</div>

Hi,

I followed both of these tutorials: [Set up basic security for the Elastic Stack](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html) and [Set up basic security for the Elastic Stack plus secured HTTPS traffic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup-https.html).

Now i want to set up the ability for a third party app (I need this for another app but for test purposes I use cUrl/Postman) to send https Requests to my single elasticsearch node.  
For the App i want to send the requests from I need a client certificate and a private key in .pem format.

How do i get this certificate and how do I set up this kind of communication?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 23, 2024, 3:21am UTC](https://discuss.elastic.co/t/how-to-set-up-third-party-https-requests-to-elasticsearch/363560/2 "2024-07-23T03:21:24Z")

</div>

> [@Knut\_Knackwurst](#):
>
> For the App i want to send the requests from I need a client certificate and a private key in .pem format.

What do you mean by "need" ?

The tutorials you followed did not set up client authentication, so it will not process certificates from client.,

Do you mean:

- You want to turn on client authentication (mTLS) so that clients are required to provide a certificate?
- The client documentation tells you that it needs a PEM certificate & key?
- Or you just want to make the client work with what you've configured so far? (in which case it doesn't need a client certificate)

---

<div class="post-metadata">

**Author:** ![Knut\_Knackwurst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/knut_knackwurst/32/124748_2.png) [@Knut\_Knackwurst](https://discuss.elastic.co/u/Knut_Knackwurst)\
**Post date:** [July 23, 2024, 8:40am UTC](https://discuss.elastic.co/t/how-to-set-up-third-party-https-requests-to-elasticsearch/363560/3 "2024-07-23T08:40:14Z")

</div>

Hi @TimV,  
I misunderstood something, my third party application as you mentioned already works with what I have configured so far.  
Thanks for your help!
