# Securing Elastic AMP server, client\_authentication and RUM

**URL:** <https://discuss.elastic.co/t/securing-elastic-amp-server-client-authentication-and-rum/235559>\
**Category:** APM\
**Tags:** rum\
**Created:** [June 3, 2020, 1:28pm UTC](https://discuss.elastic.co/t/securing-elastic-amp-server-client-authentication-and-rum/235559 "2020-06-03T13:28:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [June 3, 2020, 1:28pm UTC](https://discuss.elastic.co/t/securing-elastic-amp-server-client-authentication-and-rum/235559/1 "2020-06-03T13:28:01Z")

</div>

Hello all,

I am trying to secure the Elastic APM server I use for Real User Monitoring.

Some snippets from different documentation

Elastic APM Server - SSL config - [client\_authentication](https://www.elastic.co/guide/en/apm/server/current/agent-server-ssl.html#_client_authentication)

> This option only needs to be configured when the agent is expected to provide a client certificate. Sending client certificates is currently only supported by the RUM agent through the browser and by the Jaeger agent.

Which suggests to me that this should be configurable in the RUM agent..? I can't find any mention of that in the [RUM agent documentation](https://www.elastic.co/guide/en/apm/agent/rum-js/5.x/configuration.html).

Am I making wrong assumptions or looking in the wrong place in the docs?

There is also not anything resembling `server_name` or anything like that which I'm used to configure for web servers when setting the domain name of the service and which is checked against the available certificate. Is the `server_name` just taken from the POST request then? Looks like it from my initial tests...

All suggestions and tips are welcome 🙂

---

<div class="post-metadata">

**Author:** ![Hamidreza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamidreza/32/21369_2.png) [@Hamidreza](https://discuss.elastic.co/u/Hamidreza)\
**Post date:** [June 9, 2020, 12:38pm UTC](https://discuss.elastic.co/t/securing-elastic-amp-server-client-authentication-and-rum/235559/2 "2020-06-09T12:38:17Z")

</div>

Hi @A_B,

Thanks for reaching out.

As is mentioned in the docs the certificate has to be provided by the browser. In other words the certificate needs to be installed on users' machines before hand. This is only provided for scenarios in which you have access to end-users' machines (e.g. an internal network or similar). The certificate can not be configure from the agent since it doesn't (and shouldn't) have access to setting the certificate (the browser handles all that).

Hope this helps.

Cheers,  
Hamid

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [June 9, 2020, 12:48pm UTC](https://discuss.elastic.co/t/securing-elastic-amp-server-client-authentication-and-rum/235559/3 "2020-06-09T12:48:31Z")

</div>

Hello @Hamidreza,

thank you very much for your reply 🙂

So, if you do not control the end-user machines, I should set this?

```
client_authentication: none 

```

I have it as optional at the moment and at least Chrome displays a dialogue where I can choose which cert to use.

I have configured SSL/TLS with certs that are trusted CA signed.

---

<div class="post-metadata">

**Author:** ![Hamidreza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamidreza/32/21369_2.png) [@Hamidreza](https://discuss.elastic.co/u/Hamidreza)\
**Post date:** [June 10, 2020, 12:15pm UTC](https://discuss.elastic.co/t/securing-elastic-amp-server-client-authentication-and-rum/235559/4 "2020-06-10T12:15:13Z")

</div>

That is correct, you should set `client_authentication: none`.  
From our 7.7 stack release we also have changed the default value for that config option to `none`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 1, 2020, 8:15am UTC](https://discuss.elastic.co/t/securing-elastic-amp-server-client-authentication-and-rum/235559/5 "2020-07-01T08:15:16Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
