# I'm struggling set up the minimal Security and the configure the TLS

**URL:** <https://discuss.elastic.co/t/im-struggling-set-up-the-minimal-security-and-the-configure-the-tls/321851>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 22, 2022, 2:59pm UTC](https://discuss.elastic.co/t/im-struggling-set-up-the-minimal-security-and-the-configure-the-tls/321851 "2022-12-22T14:59:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anonym123](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Anonym123](https://discuss.elastic.co/u/Anonym123)\
**Post date:** [December 22, 2022, 2:59pm UTC](https://discuss.elastic.co/t/im-struggling-set-up-the-minimal-security-and-the-configure-the-tls/321851/1 "2022-12-22T14:59:40Z")

</div>

What im using:  
The offical Helm Chart verion 7.17.3 from [artifacthub.io](http://artifacthub.io)  
Image version is also 7.17.3

My Problem:  
I'm struggling set up the minimal Security and the configure the TLS  
My Steps:

1. Create the p12  
`elasticsearch@elasticsearch-master-0:~$ bin/elasticsearch-certutil cert -out -- elastic-certificates.p12 -pass ""`
2. Copy the p12 to the local computer  
`kubectl cp elasticsearch-master-0:elastic-certificates.p12 elastic-certificates.p12`
3. Create a K8S Secret  
`kubectl create secret generic elastic-certificates --from-file=elastic-certificates.p12`
4. Stop Elasticsearch and Kibana  
`helm uninstall elasticsearch`  
equal with Kibana
5. Edit Elasticsearch valus.yaml

```auto
elasticsearch.yaml |
    xpack.security.enabled: true
    xpack.security.transport.ssl.enabled: true
    xpack.security.transport.ssl.verification_mode: none 
    xpack.security.http.ssl.verification_mode: none
    xpack.security.transport.ssl.client_authentication: required
    xpack.security.transport.ssl.keystore.path: /usr/share/elasticsearch/config/certs/elastic-certificates.p12
    xpack.security.transport.ssl.truststore.path: /usr/share/elasticsearch/config/certs/elastic-certificates.p12
    xpack.security.http.ssl.enabled: true
    xpack.security.http.ssl.truststore.path: /usr/share/elasticsearch/config/certs/elastic-certificates.p12
    xpack.security.http.ssl.keystore.path: /usr/share/elasticsearch/config/certs/elastic-certificates.p12 
protocol: https
secretMounts:
  - name: elastic-certificates
    secretName: elastic-certificates
    path: /usr/share/elasticsearch/config/certs

```

1. Restart Elasticsearch  
`helm install elasticsearch .`
2. Set up Passwords

```auto
elasticsearch@elasticsearch-master-0:~$ bin/elasticsearch-setup-passwords auto
	Changed password for user
       ...

```

Afterwards I get this errors

Error log from the Pod  
`elasticsearch-master-0: {"type": "server", "timestamp": "XXXX-XX-XXTXX:XX:XX,XXXZ", "level": "INFO", "component": "o.e.x.s.a.RealmsAuthenticator", "cluster.name": "XXXXXXXX", "node.name": "elasticsearch-master-0", "message": "Authentication of [elastic] was terminated by realm [reserved] - failed to authenticate user [elastic]", "cluster.uuid": "XXXXXXXXXXX", "node.id": "XXXXXXXXXXX" }`

Error log from the Cluster  
`Readiness probe failed: Waiting for elasticsearch cluster to become ready (request params: "wait_for_status=green&timeout=1s" ) Cluster is not yet ready (request params: "wait_for_status=green&timeout=1s" )`

I think I need to set the elastic user and password some where but where and how can I set this in the Helm Chart?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 22, 2022, 3:27pm UTC](https://discuss.elastic.co/t/im-struggling-set-up-the-minimal-security-and-the-configure-the-tls/321851/2 "2022-12-22T15:27:17Z")

</div>

You need to check the logs of your elasticsearch nodes, to be able to authenticate your cluster needs to be running, from the logs you shared it seems that it is not running.

The cluster does not need user/password to run, the user/password is just to authenticate users, the nodes communicate with each other using the certificates.

---

<div class="post-metadata">

**Author:** ![Anonym123](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Anonym123](https://discuss.elastic.co/u/Anonym123)\
**Post date:** [December 22, 2022, 3:31pm UTC](https://discuss.elastic.co/t/im-struggling-set-up-the-minimal-security-and-the-configure-the-tls/321851/3 "2022-12-22T15:31:33Z")

</div>

After Step 7

```auto
elasticsearch@elasticsearch-master-0:~$ bin/elasticsearch-setup-passwords auto
	Changed password for user
       ...

```

My pods changed from status green to yellow after Step 7. Before this step my pods were running.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 22, 2022, 4:18pm UTC](https://discuss.elastic.co/t/im-struggling-set-up-the-minimal-security-and-the-configure-the-tls/321851/4 "2022-12-22T16:18:39Z")

</div>

You need to check the logs of your elasticsearch nodes.

How many data nodes you have? I do not use k8s, but a yellow status means that one of the replicas is not allocated, this does not impact you being able to log in or not, so you need to check the logs for every elasticsearch node you have.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 23, 2022, 3:17am UTC](https://discuss.elastic.co/t/im-struggling-set-up-the-minimal-security-and-the-configure-the-tls/321851/5 "2022-12-23T03:17:07Z")

</div>

> [@Anonym123](#):
>
> My pods changed from status green to yellow after Step 7. Before this step my pods were running.

How did you observe that change in status?

It might be because the probe in the helm chart uses one of the builtin users, and relies on knowing the password via environment variables. When you setup the passwords, you prevented the health probe from connecting to the cluster.

---

<div class="post-metadata">

**Author:** ![Anonym123](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Anonym123](https://discuss.elastic.co/u/Anonym123)\
**Post date:** [December 23, 2022, 8:58am UTC](https://discuss.elastic.co/t/im-struggling-set-up-the-minimal-security-and-the-configure-the-tls/321851/6 "2022-12-23T08:58:17Z")

</div>

Thank you Tim this was the solution.  
I really appreciate this advice.

The readiness probe use the Elastic user but the passwords changed. Set the new password as a k8s secret and restart elastic helped.  
This was a stupid bug from my side.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 20, 2023, 8:58am UTC](https://discuss.elastic.co/t/im-struggling-set-up-the-minimal-security-and-the-configure-the-tls/321851/7 "2023-01-20T08:58:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
