# PKCS#12 vs PEM for Elastic Cluster

**URL:** <https://discuss.elastic.co/t/pkcs-12-vs-pem-for-elastic-cluster/336001>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 14, 2023, 4:58pm UTC](https://discuss.elastic.co/t/pkcs-12-vs-pem-for-elastic-cluster/336001 "2023-06-14T16:58:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![algo](https://avatars.discourse-cdn.com/v4/letter/a/e99b99/32.png) [@algo](https://discuss.elastic.co/u/algo)\
**Post date:** [June 14, 2023, 4:58pm UTC](https://discuss.elastic.co/t/pkcs-12-vs-pem-for-elastic-cluster/336001/1 "2023-06-14T16:58:36Z")

</div>

I am running a cluster on 7.17 and am looking at updating the TLS certs for internode communication. Currently, I'm using PEM certs for this, but I saw that the documentation for both [setting up basic security](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/security-basic-setup.html#encrypt-internode-communication) and [updating existing certs](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/update-node-certs-different.html) have instructions based on PKCS#12 and generating a .p12 file instead of .crt/.key files.

I was wondering if there was a reason that the documentation doesn't include any steps for setting up or updating certs via PEM (or if they're out there, can someone point me in the right direction?). Is PEM not recommended/soon-to-be deprecated?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [June 15, 2023, 2:08am UTC](https://discuss.elastic.co/t/pkcs-12-vs-pem-for-elastic-cluster/336001/2 "2023-06-15T02:08:21Z")

</div>

> [@algo](#):
>
> Is PEM not recommended/soon-to-be deprecated?

That is definitely _not_ the case. The documentation uses PKCS12 file as example because it is often easier to manage one file than multiple PEM files.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2023, 2:09am UTC](https://discuss.elastic.co/t/pkcs-12-vs-pem-for-elastic-cluster/336001/3 "2023-07-13T02:09:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
