# mTLS under basic license

**URL:** <https://discuss.elastic.co/t/mtls-under-basic-license/313375>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 31, 2022, 3:43pm UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375 "2022-08-31T15:43:21Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rohit\_Shrivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_shrivastava/32/9850_2.png) [@Rohit\_Shrivastava](https://discuss.elastic.co/u/Rohit_Shrivastava)\
**Post date:** [August 31, 2022, 3:43pm UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/1 "2022-08-31T15:43:21Z")

</div>

Hi

I am trying to setup mTLS and using basic license. However not able to understand how should I grant access to kibana CN?

My goal is to create cert for kibana and use mTLS between elasticsearch and kibana. But for this, I think I need to grant some roles to kibana CN?

The link below states that mTLS is part of basic but I am wondering how mTLS is supposed to work in absence of PKI realm.

[PKI security realm lisence - Elastic Stack / Elasticsearch - Discuss the Elastic Stack](https://discuss.elastic.co/t/pki-security-realm-lisence/273392)

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [September 1, 2022, 1:32am UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/2 "2022-09-01T01:32:24Z")

</div>

Please refer to the doc [Mutual TLS authentication between Kibana and Elasticsearch | Kibana Guide [8.4] | Elastic](https://www.elastic.co/guide/en/kibana/current/elasticsearch-mutual-tls.html#_configure_kibana_and_elasticsearch_to_use_mutual_tls_authentication)

---

<div class="post-metadata">

**Author:** ![Rohit\_Shrivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_shrivastava/32/9850_2.png) [@Rohit\_Shrivastava](https://discuss.elastic.co/u/Rohit_Shrivastava)\
**Post date:** [September 1, 2022, 8:24am UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/3 "2022-09-01T08:24:04Z")

</div>

Thanks @Yang_Wang my question is are the steps 3 & 6 on the docs achievable on Basic license?  
As per other link which I shared it says mTLS is covered under Basic but to achieve if one need to have the PKI realm and role mapping which are part of Gold / Platinum then mTLS is not part of the Basic. I would need a confirmation on this puzzle, can one setup mTLS on basic license?

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [September 1, 2022, 8:37am UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/4 "2022-09-01T08:37:36Z")

</div>

> [@Rohit\_Shrivastava](#):
>
> my question is are the steps 3 & 6 on the docs achievable on Basic license?

Ah ok. Sorry I missed the steps for PKI realm. No PKI realm is not available for basic license. But you don't need PKI for mTLS. In your case, I think you can just skip step 3 and 6 and change step 4 to be `xpack.security.http.ssl.client_authentication: "required"`.

---

<div class="post-metadata">

**Author:** ![Rohit\_Shrivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_shrivastava/32/9850_2.png) [@Rohit\_Shrivastava](https://discuss.elastic.co/u/Rohit_Shrivastava)\
**Post date:** [September 1, 2022, 2:53pm UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/5 "2022-09-01T14:53:00Z")

</div>

my question is if I skip 3 & 6 then how does CN=kibana gets access to Elasticsearch without updating the userroles and no PKI realm.  
Kibana will remain authenticated with no access to anything? no?

---

<div class="post-metadata">

**Author:** ![Justin\_Cranford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_cranford/32/85302_2.png) [@Justin\_Cranford](https://discuss.elastic.co/u/Justin_Cranford)\
**Post date:** [September 1, 2022, 4:06pm UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/6 "2022-09-01T16:06:46Z")

</div>

I think you are correct, mTLS from Kibana to Elasticsearch requires PKI realm, because you need a role mapping rule to map TLS client cert to kibana\_system role. Basic license does not allow PKI realm, but you can use service account token (preferred) or username/password.

Service Account token example:

```auto
POST /_security/service/elastic/kibana/credential/token/mytoken?pretty=true

```

Username/password example:

```auto
printf "Y\nkibana_system\nkibana_system\n"| bin/elasticsearch-reset-password -i -u kibana_system

```

The corresponding settings for kibana.yml or kibana-keystore would be:

```auto
elasticsearch.serviceAccountToken

elasticsearch.username
elasticsearch.password

```

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [September 2, 2022, 12:03am UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/7 "2022-09-02T00:03:44Z")

</div>

> [@Justin\_Cranford](#):
>
> mTLS from Kibana to Elasticsearch requires PKI realm

No. Using mTLS as a network level control does _not_ require PKI realm and can totally work with the Basic license. A simplified configuration like the following works:

```yaml
# elasticsearch.yml

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.verification_mode: certificate
xpack.security.http.ssl.key: http.key
xpack.security.http.ssl.certificate: http.cert
xpack.security.http.ssl.certificate_authorities: ["http-ca.cert"]
xpack.security.http.ssl.client_authentication: required

```

```yaml
# kibana.yml

elasticsearch.hosts: ["https://localhost:9200"]
elasticsearch.serviceAccountToken: "CREATE_YOUR_OWN_SERVICE_TOKEN"
elasticsearch.ssl.certificate: http.cert
elasticsearch.ssl.key: http.key
elasticsearch.ssl.alwaysPresentCertificate: true
elasticsearch.ssl.certificateAuthorities: ["http-ca.cert"]
elasticsearch.ssl.verificationMode: certificate

```

For simplicity, the above configuration uses the same pair of cert/key for both Elasticsearch and Kibana. But you can configure them to be different. The configuration uses mTLS as network layer control and Kibana service token as application level authentication and authorization.

---

<div class="post-metadata">

**Author:** ![Justin\_Cranford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_cranford/32/85302_2.png) [@Justin\_Cranford](https://discuss.elastic.co/u/Justin_Cranford)\
**Post date:** [September 2, 2022, 2:32am UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/8 "2022-09-02T02:32:00Z")

</div>

Thank you for the clarification @Yang_Wang. If I were to summarize, does this look correct?

Assumption: Elasticsearch is configured to use HTTPS:

1. Kibana uses elastic/kibana service token =\> Basic license
2. Kibana uses kibana\_system reserved user =\> Basic license
3. Kibana uses TLS client cert + elastic/kibana service token =\> Basic license
4. Kibana uses TLS client cert + kibana\_system reserved user =\> Basic license
5. Kibana uses TLS client cert =\> Gold license (PKI realm for role mapping)

Note: Gold is deprecated so next license level is Platinum.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [September 5, 2022, 1:47am UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/9 "2022-09-05T01:47:32Z")

</div>

> [@Justin\_Cranford](#):
>
> does this look correct?

That is correct.

---

<div class="post-metadata">

**Author:** ![Rohit\_Shrivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_shrivastava/32/9850_2.png) [@Rohit\_Shrivastava](https://discuss.elastic.co/u/Rohit_Shrivastava)\
**Post date:** [September 5, 2022, 1:35pm UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/10 "2022-09-05T13:35:10Z")

</div>

Thanks @Justin_Cranford @Yang_Wang

> [@Justin\_Cranford](#):
>
> 1. Kibana uses TLS client cert =\> Gold license (PKI realm for role mapping)

Does bullet 5 mean I must have a paid subscription to setup mTLS?  
Not sure If I understand if both serviceToken and cert will be used to identify kibana's identity by elasticsearch, if I am using serviceToken then whats the use of Kibana's tls client cert?

Is there a example on how to create the / automate the serviceToken for kibana\_system if I am deploying ELK using helm charts?

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [September 5, 2022, 2:09pm UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/11 "2022-09-05T14:09:29Z")

</div>

> [@Rohit\_Shrivastava](#):
>
> Does bullet 5 mean I must have a paid subscription to setup mTLS?

No you don't. Both point 3 and 4 are mTLS. Piont 5 is mTls plus it uses client cert for kibana identity at application level which is **not** an inherent part of mTLS.

> [@Rohit\_Shrivastava](#):
>
> Not sure If I understand if both serviceToken and cert will be used to identify kibana's identity by elasticsearch, if I am using serviceToken then whats the use of Kibana's tls client cert?

You don't really need client cert for kibana if you use service token. mTLS does **not** provide extra security compared to server TLS + service token. You started the question with mTLS. I assumed you need it. But if you just wanted client cert for Kibana identity at application level, it is not necessary. Service token or plain old kibana\_system username+password works just fine. There are certain environments where mTLS and PKI is mandated. But apparently your enviroment is not like that. So you don't have configure it like that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2022, 2:09pm UTC](https://discuss.elastic.co/t/mtls-under-basic-license/313375/12 "2022-10-03T14:09:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
