# Puzzled about message: Configuring TLS will be required to apply a Gold or Platinum license when security is enabled

**URL:** <https://discuss.elastic.co/t/puzzled-about-message-configuring-tls-will-be-required-to-apply-a-gold-or-platinum-license-when-security-is-enabled/130520>\
**Category:** Elasticsearch\
**Created:** [May 3, 2018, 7:56pm UTC](https://discuss.elastic.co/t/puzzled-about-message-configuring-tls-will-be-required-to-apply-a-gold-or-platinum-license-when-security-is-enabled/130520 "2018-05-03T19:56:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mlemartien](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mlemartien/32/30958_2.png) [@mlemartien](https://discuss.elastic.co/u/mlemartien)\
**Post date:** [May 3, 2018, 7:56pm UTC](https://discuss.elastic.co/t/puzzled-about-message-configuring-tls-will-be-required-to-apply-a-gold-or-platinum-license-when-security-is-enabled/130520/1 "2018-05-03T19:56:21Z")

</div>

Hi,

I am trying Elasticsearch and Kibana 6.2.4 with X-Pack. I have successfully configured TLS at all levels (node, kibana to cluster, browser to Kibana).

I am puzzled by the cluster alert that remains visible in Kibana:  
"Configuring TLS will be required to apply a Gold or Platinum license when security is enabled."

Is this something that will disappear once I installed our Platinum license, or is there anything else I need to do, i.e. the alert is really relevant?

Many thanks in advance.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 8, 2018, 8:15am UTC](https://discuss.elastic.co/t/puzzled-about-message-configuring-tls-will-be-required-to-apply-a-gold-or-platinum-license-when-security-is-enabled/130520/2 "2018-05-08T08:15:49Z")

</div>

Hi

You should be only getting this message if you are one a trial license with X-Pack security enabled and have **not** enabled TLS on the transport layer of Elasticsearch. It means that when you move to a Gold or Platinum license, TLS for transport layer will be **required**

> [@mlemartien](#):
>
> I am trying Elasticsearch and Kibana 6.2.4 with X-Pack. I have successfully configured TLS at all levels (node, kibana to cluster, browser to Kibana).

Does the `node` part above indicate transport TLS ? Can you share the relevant part of the config ?

---

<div class="post-metadata">

**Author:** ![mlemartien](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mlemartien/32/30958_2.png) [@mlemartien](https://discuss.elastic.co/u/mlemartien)\
**Post date:** [May 8, 2018, 5:54pm UTC](https://discuss.elastic.co/t/puzzled-about-message-configuring-tls-will-be-required-to-apply-a-gold-or-platinum-license-when-security-is-enabled/130520/3 "2018-05-08T17:54:44Z")

</div>

Thanks for your response. As a matter of fact, all nodes of the cluster use TLS, hence my surprised. Please find elasticsearch.yml file:

cluster.name: eLABsticsearch  
node.name: elastic01

node.data: True  
node.master: True  
node.ingest: True  
node.ml: False  
search.remote.connect: false

path.data: /var/lib/elasticsearch  
path.logs: /var/log/elasticsearch

network.host: 172.28.128.11  
http.port: 9200

discovery.zen.ping.unicast.hosts: ["172.28.128.11","172.28.128.12","172.28.128.13"]  
discovery.zen.minimum\_master\_nodes: 2

xpack.security.transport.ssl.verification\_mode: full  
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/elastic01.p12  
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/elastic01.p12

xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.keystore.path: /etc/elasticsearch/elastic01.p12  
xpack.security.http.ssl.truststore.path: /etc/elasticsearch/elastic01.p12

---

<div class="post-metadata">

**Author:** ![mlemartien](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mlemartien/32/30958_2.png) [@mlemartien](https://discuss.elastic.co/u/mlemartien)\
**Post date:** [May 8, 2018, 6:17pm UTC](https://discuss.elastic.co/t/puzzled-about-message-configuring-tls-will-be-required-to-apply-a-gold-or-platinum-license-when-security-is-enabled/130520/4 "2018-05-08T18:17:38Z")

</div>

OK I think I figured... It was stupid on my side. I forgot to add:

xpack.security.transport.ssl.enabled: true

To my config. Thanks for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2018, 6:17pm UTC](https://discuss.elastic.co/t/puzzled-about-message-configuring-tls-will-be-required-to-apply-a-gold-or-platinum-license-when-security-is-enabled/130520/5 "2018-06-05T18:17:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
