# How to use the http.p12, http\_ca.crt and transport.p12 generated by elasticsearch when run as a single node

**URL:** https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913
**Category:** Elasticsearch
**Tags:** elastic-stack-monitoring, elastic-stack-security, elastic-stack-alerting, docker
**Created:** [January 25, 2023, 11:42am UTC](https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913 "2023-01-25T11:42:44Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Raja\_Muneer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raja_muneer/32/115322_2.png) [@Raja\_Muneer](https://discuss.elastic.co/u/Raja_Muneer)
#### Post date: [January 25, 2023, 11:42am UTC](https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913/1 "2023-01-25T11:42:44Z")

</div>

I am trying to enable HTTPS on my elk-stack. While I am able to do so using the following link.

[Configuring ssl,tls and https](https://medium.com/sera-engineering/configuring-ssl-tls-and-https-to-secure-elastic-stack-single-node-4ca54cd8b168)

However, When we run elasticsearch as a single node it generates some default certificates which we can find by getting inside the container as shown below.

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/1/9108beea2a301a9f219f4b206aaa6f55c8945e80.png)

My question is how can we use these certs and keys to enable HTTPS on elasticsearch also is it possible to use the same key and cert for kibana, logstash, and beats for secure communication over HTTPS?

Note: I am running elk stack in docker and using the latest version.

---

<div class="post-metadata">

### Author: ![dadiasish](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadiasish/32/114221_2.png) [@dadiasish](https://discuss.elastic.co/u/dadiasish)
#### Post date: [January 25, 2023, 12:09pm UTC](https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913/2 "2023-01-25T12:09:24Z")

</div>

Hi,

As you can see in the document you pointed out to, you can see some https settings in the elasticsearch.yml file.

```auto
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.key: certs/self-signed-withdns/elasticsearch-singlenode/elasticsearch-singlenode.key
xpack.security.http.ssl.certificate: certs/self-signed-withdns/elasticsearch-singlenode/elasticsearch-singlenode.crt
xpack.security.http.ssl.certificate_authorities: certs/self-signed-withdns/ca/ca.crt

```

Those settings help you enable the https security to your cluster.

I would suggest you follow the Elastic documentation as it's easy and the below doc would answer all your questions.

[Install Elasticsearch on Docker](https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html#elasticsearch-security-certificates)

[Setup basic security](https://www.elastic.co/guide/en/elasticsearch/reference/master/security-basic-setup.html)

[Setup basic security plus HTTPS](https://www.elastic.co/guide/en/elasticsearch/reference/master/security-basic-setup-https.html)

---

<div class="post-metadata">

### Author: ![Raja\_Muneer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raja_muneer/32/115322_2.png) [@Raja\_Muneer](https://discuss.elastic.co/u/Raja_Muneer)
#### Post date: [January 25, 2023, 12:38pm UTC](https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913/3 "2023-01-25T12:38:26Z")

</div>

Thank you for your response. I have already enabled https using the medium link but I am confused about the certificates generated by elasticsearch when I run elasticsearch using docker run command it generates those three certificates as mention in the title of the topic as well as shown in the image. The medium link provides a different way to enable https. I am asking how can I use the certificates generated by elasticsearch to enable https. i.e http\_ca.crt , transport.p12 and http.p12

---

<div class="post-metadata">

### Author: ![dadiasish](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadiasish/32/114221_2.png) [@dadiasish](https://discuss.elastic.co/u/dadiasish)
#### Post date: [January 25, 2023, 12:51pm UTC](https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913/4 "2023-01-25T12:51:25Z")

</div>

Got you.

So basically, if you follow the elastic document given by me, or the 3 certificates which are generated for you are the certificates which are self signed by elastic.

And the way it's shown in the medium is also the same but using a .yml file or you can say using a configuration file.

Both are generated using the elasticsearch-certutil only if you see the command.

`sudo bash /usr/share/elasticsearch/bin/elasticsearch-certutil cert --days 1825 --keep-ca-key --pem --in instance.yml --out self-signed-elastic-stack.zip`

Basically this type of generation is used when you want to give a custom name to the cert file or when you wanted to add multiple dns names in the cert or when you need to generate .csr files and get them signed by other Signing Autorities.

As of now, as you've enabled https, that should be fine.

The generated certs can be ignored in your case currently.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 22, 2023, 12:51pm UTC](https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913/5 "2023-02-22T12:51:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
