# Python PKI authentication

**URL:** <https://discuss.elastic.co/t/python-pki-authentication/93479>\
**Category:** Elasticsearch\
**Created:** [July 18, 2017, 12:35am UTC](https://discuss.elastic.co/t/python-pki-authentication/93479 "2017-07-18T00:35:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aclose](https://avatars.discourse-cdn.com/v4/letter/a/e9bcb4/32.png) [@Aclose](https://discuss.elastic.co/u/Aclose)\
**Post date:** [July 18, 2017, 12:35am UTC](https://discuss.elastic.co/t/python-pki-authentication/93479/1 "2017-07-18T00:35:12Z")

</div>

Hi,

Apologies if this is simple but I'm pretty new to worrying about security. X-Pack's Security functionality comes with out of the box PKI authentication - which is great. But I can only find Python examples for httpauth (basic username and password). Can anyone advise how to use PKI authentication with Python?

Thanks,

Alex

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 18, 2017, 4:41am UTC](https://discuss.elastic.co/t/python-pki-authentication/93479/2 "2017-07-18T04:41:17Z")

</div>

Since you're specifically asking about the python side, I'll restrict my answer to that, but if you have any questions about setting up the Elasticsearch side, or generating client certificates, please ask.

Also, it's not clear what version of python you're running, and whether you are using an Elasticsearch client library or not.

If you want to use the the official elasticsearch python client, it provides an example of using a client certificate here: [http://elasticsearch-py.readthedocs.io/en/master/#ssl-and-authentication](http://elasticsearch-py.readthedocs.io/en/master/#ssl-and-authentication). You can drop the `http_auth` if you just want to use PKI authentication.

If you're not using an ES library, and just want to use builtin modules, then you can do something like this with `http.client` (in python 3)

```auto
import ssl
import http.client

context = ssl.create_default_context(cafile="server/ca/ca.crt")
context.load_cert_chain( "client/app01.crt" , keyfile="client/app01.key" , password="secret" )

connection = http.client.HTTPSConnection(host = "localhost" , port = 9200 , context = context )
connection.request("GET", "_xpack/security/_authenticate")

resp = connection.getresponse()
print( resp.read() )

connection.close()

```

That assumes that the CA certificate for your elasticsearch cluster is in `server/ca/ca.crt` and your client certificate is `client/app01.crt`  
See: [https://docs.python.org/3/library/http.client.html](https://docs.python.org/3/library/http.client.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2017, 4:41am UTC](https://discuss.elastic.co/t/python-pki-authentication/93479/3 "2017-08-15T04:41:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
