# Implementing basic auth for basic license throwing error

**URL:** <https://discuss.elastic.co/t/implementing-basic-auth-for-basic-license-throwing-error/272797>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 12, 2021, 10:44am UTC](https://discuss.elastic.co/t/implementing-basic-auth-for-basic-license-throwing-error/272797 "2021-05-12T10:44:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [May 12, 2021, 10:44am UTC](https://discuss.elastic.co/t/implementing-basic-auth-for-basic-license-throwing-error/272797/1 "2021-05-12T10:44:58Z")

</div>

Hi All,

Our cluster have 6 nodes(1 coordinating, 3 master+data, 2 data nodes). We have implemented basic auth in the coordinating node, as our kibana is calling only coordinating node and it is working fine.

However , we have received a new requirement , where we need to secure all the elasticsearch node. We tried to make one of our master+data node secure.

We enabled below properties.

xpack.security.enabled: true  
xpack.security.transport.ssl.enabled: true

PS : our coordinating node was working with only one property enabled  
xpack.security.enabled: true

After enabling property when we try to run elasticsearch-setup-password, it is throwing below error :

` [master_not_discovered_exception] .`

Can someone please suggest whether there is some different configuration for master+data and coordinating node and why is it mandatory to enable ssl layer as well for master+data node

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 12, 2021, 11:17pm UTC](https://discuss.elastic.co/t/implementing-basic-auth-for-basic-license-throwing-error/272797/2 "2021-05-12T23:17:56Z")

</div>

> [@rohitarorait82](#):
>
> We tried to make one of our master+data node secure.

You need to enable this on _all_ nodes in the cluster, not just one at a time.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 13, 2021, 3:45am UTC](https://discuss.elastic.co/t/implementing-basic-auth-for-basic-license-throwing-error/272797/3 "2021-05-13T03:45:34Z")

</div>

These are the docs for setting up security.

> **[Start the Elastic Stack with security enabled automatically | Elasticsearch...](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-stack-security.html)**

Since you're running a multi-node production cluster, you will need to perform at least the "Basic security" steps.  
If you're following those steps and running into issues, then please indicate which step you got to, and what went wrong.

Based on the settings you have listed as being configured, it doesn't look like you are following those steps, so please start there.

> [@rohitarorait82](#):
>
> why is it mandatory to enable ssl layer as well for master+data node

SSL is the mechanism that we use to ensure that only trusted nodes can connect to your cluster. Without that protection, your security is useless because anyone with access to your network could connect to port `9300` and pretend to be a node.

---

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [May 13, 2021, 1:58pm UTC](https://discuss.elastic.co/t/implementing-basic-auth-for-basic-license-throwing-error/272797/4 "2021-05-13T13:58:34Z")

</div>

Thanks @TimV and @warkolm I will try this and update on this thread

---

<div class="post-metadata">

**Author:** ![rohitarorait82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohitarorait82/32/82981_2.png) [@rohitarorait82](https://discuss.elastic.co/u/rohitarorait82)\
**Post date:** [May 17, 2021, 2:58pm UTC](https://discuss.elastic.co/t/implementing-basic-auth-for-basic-license-throwing-error/272797/5 "2021-05-17T14:58:41Z")

</div>

Now it is working thanks 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2021, 2:58pm UTC](https://discuss.elastic.co/t/implementing-basic-auth-for-basic-license-throwing-error/272797/6 "2021-06-14T14:58:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
