# mTLS only setup for Elasticsearch

**URL:** <https://discuss.elastic.co/t/mtls-only-setup-for-elasticsearch/319576>\
**Category:** Elasticsearch\
**Created:** [November 22, 2022, 4:59pm UTC](https://discuss.elastic.co/t/mtls-only-setup-for-elasticsearch/319576 "2022-11-22T16:59:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rohit\_Shrivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_shrivastava/32/9850_2.png) [@Rohit\_Shrivastava](https://discuss.elastic.co/u/Rohit_Shrivastava)\
**Post date:** [November 22, 2022, 4:59pm UTC](https://discuss.elastic.co/t/mtls-only-setup-for-elasticsearch/319576/1 "2022-11-22T16:59:20Z")

</div>

Is it possible to only use mTLS i.e. only authentication via PKI realm. I almost have the cluster working (using open source helm charts and 7.1.7 images). One issue I have is the pod readiness doesn't succeed as the \_cluster/health endpoint is not accessible anonymously and readiness\_probe script is not making use of TLS certs, I couldn't find it can even be configured to use tls certs and keys while making the request.  
I then thought may be if I put the anonymouse user to monitoring\_user role it should work. So I added below config  
`xpack.security.authc.anonymous.roles: monitoring_user`  
Hoping now to see /\_cluster/health endpoint to work anonymously but it still doesn't allow.

Is there a way to make the readiness probe to work with mTLS pki realm only?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2022, 5:00pm UTC](https://discuss.elastic.co/t/mtls-only-setup-for-elasticsearch/319576/2 "2022-12-20T17:00:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
