# Inquiry about FIPS 140-2 Compliance for Elasticsearch on Amazon Opensearch Service

**URL:** <https://discuss.elastic.co/t/inquiry-about-fips-140-2-compliance-for-elasticsearch-on-amazon-opensearch-service/360448>\
**Category:** Elasticsearch\
**Created:** [May 29, 2024, 10:53am UTC](https://discuss.elastic.co/t/inquiry-about-fips-140-2-compliance-for-elasticsearch-on-amazon-opensearch-service/360448 "2024-05-29T10:53:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [May 29, 2024, 10:53am UTC](https://discuss.elastic.co/t/inquiry-about-fips-140-2-compliance-for-elasticsearch-on-amazon-opensearch-service/360448/1 "2024-05-29T10:53:26Z")

</div>

Hello,

I am trying to understand if the FIPS 140-2 compliant mode offered by Elasticsearch is applicable when Elasticsearch is used as an Amazon Opensearch service.

In my specific case, Elasticsearch is not installed on-premise or in a similar environment, but is used as an Amazon service. As a result, I do not have direct access to the Elasticsearch machines to verify or modify settings.

Elasticsearch offers a FIPS 140-2 compliant mode and can thus run in a FIPS 140-2 configured JVM in order to guarantee security principles. However, it is unclear whether this mode is available or can be enabled when Elasticsearch is used as an Amazon Opensearch service.

Could you provide further details or clarifications on this?

Thank you in advance for your help.

Best regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2024, 10:53am UTC](https://discuss.elastic.co/t/inquiry-about-fips-140-2-compliance-for-elasticsearch-on-amazon-opensearch-service/360448/2 "2024-05-29T10:53:27Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance. See [What is OpenSearch and the OpenSearch Dashboard? | Elastic](https://www.elastic.co/elasticsearch/opensearch) for more details.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 29, 2024, 12:12pm UTC](https://discuss.elastic.co/t/inquiry-about-fips-140-2-compliance-for-elasticsearch-on-amazon-opensearch-service/360448/3 "2024-05-29T12:12:03Z")

</div>

We can't know what they did.

Did you look at [Cloud by Elastic](https://www.elastic.co/cloud), also available if needed from [AWS Marketplace](https://aws.amazon.com/marketplace/pp/Elasticsearch-Inc-Elasticsearch-Service-on-Elastic/B01N6YCISK), [Azure Marketplace](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/elastic.ec-azure?tab=Overview) and [Google Cloud Marketplace](https://console.cloud.google.com/marketplace/details/endpoints/elasticsearch-service.gcpmarketplace.elastic.co)?

Cloud by elastic is one way to have access to **all features** , all managed by us. Think about what is there yet like Vector Search, Security, Monitoring, Reporting, ES|QL, Canvas, Maps UI, Alerting and built-in solutions named [Observability](https://www.elastic.co/observability), [Security](https://www.elastic.co/security) and what is coming next 🙂 ...
