# Securing indexed data

**URL:** <https://discuss.elastic.co/t/securing-indexed-data/11404>\
**Category:** Elasticsearch\
**Created:** [April 1, 2013, 6:48pm UTC](https://discuss.elastic.co/t/securing-indexed-data/11404 "2013-04-01T18:48:22Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cocowalla](https://avatars.discourse-cdn.com/v4/letter/c/e36b37/32.png) [@cocowalla](https://discuss.elastic.co/u/cocowalla)\
**Post date:** [April 1, 2013, 6:48pm UTC](https://discuss.elastic.co/t/securing-indexed-data/11404/1 "2013-04-01T18:48:22Z")

</div>

Is it possible to make data in Elasticsearch indices tamper-proof? For  
example, does it have the capability to cryptographically sign blocks of  
data?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![ppearcy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppearcy/32/980_2.png) [@ppearcy](https://discuss.elastic.co/u/ppearcy)\
**Post date:** [April 1, 2013, 9:54pm UTC](https://discuss.elastic.co/t/securing-indexed-data/11404/2 "2013-04-01T21:54:39Z")

</div>

I don't believe Lucene or elasticsearch provide this. This article has some  
details:  
[https://support.lucidworks.com/entries/22014021-Encrypting-Solr-Lucene-indexes](https://support.lucidworks.com/entries/22014021-Encrypting-Solr-Lucene-indexes)

Likely the best you can do is encrypt at the filesystem level and have all  
communication pass over a secure connection.

I believe Lucene 4.0+ has some codec stuff exposed that you might be able  
to hook into via a plugin in ES, but am really not sure if that is  
feasible.

Best Regards,  
Paul

On Monday, April 1, 2013 12:48:22 PM UTC-6, cocowalla wrote:

> Is it possible to make data in Elasticsearch indices tamper-proof? For  
> example, does it have the capability to cryptographically sign blocks of  
> data?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![otisg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/otisg/32/492_2.png) [@otisg](https://discuss.elastic.co/u/otisg)\
**Post date:** [April 2, 2013, 3:37am UTC](https://discuss.elastic.co/t/securing-indexed-data/11404/3 "2013-04-02T03:37:13Z")

</div>

Hi,

ES doesn't encrypt, but some file systems can do that. I think when I  
first set up my MacBook, I think I was asked if I want to encrypt my FS,  
for example. [Encrypting File System - Wikipedia](http://en.wikipedia.org/wiki/Encrypting_File_System)

## Otis

ELASTICSEARCH Performance Monitoring - [Sematext Monitoring | Infrastructure Monitoring Service](http://sematext.com/spm/index.html)

On Monday, April 1, 2013 2:48:22 PM UTC-4, cocowalla wrote:

> Is it possible to make data in Elasticsearch indices tamper-proof? For  
> example, does it have the capability to cryptographically sign blocks of  
> data?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Anurag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anurag/32/2286_2.png) [@Anurag](https://discuss.elastic.co/u/Anurag)\
**Post date:** [April 2, 2013, 8:57am UTC](https://discuss.elastic.co/t/securing-indexed-data/11404/4 "2013-04-02T08:57:02Z")

</div>

Several linux distros give an option for encrypted filesystems. Fedora for  
example, can be set up on an encrypted partition while installing.

On Tue, Apr 2, 2013 at 9:07 AM, Otis Gospodnetic \<[otis.gospodnetic@gmail.com](mailto:otis.gospodnetic@gmail.com)

> wrote:

> Hi,
> 
> ES doesn't encrypt, but some file systems can do that. I think when I  
> first set up my MacBook, I think I was asked if I want to encrypt my FS,  
> for example. [Encrypting File System - Wikipedia](http://en.wikipedia.org/wiki/Encrypting_File_System)
> 
> ## Otis
> 
> ELASTICSEARCH Performance Monitoring - [Sematext Monitoring | Infrastructure Monitoring Service](http://sematext.com/spm/index.html)
> 
> On Monday, April 1, 2013 2:48:22 PM UTC-4, cocowalla wrote:
> 
> > Is it possible to make data in Elasticsearch indices tamper-proof? For  
> > example, does it have the capability to cryptographically sign blocks of  
> > data?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Anurag \<0xB20A82C1\>  
[http://web.gnuer.org/blog/](http://web.gnuer.org/blog/)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![cocowalla](https://avatars.discourse-cdn.com/v4/letter/c/e36b37/32.png) [@cocowalla](https://discuss.elastic.co/u/cocowalla)\
**Post date:** [April 2, 2013, 1:14pm UTC](https://discuss.elastic.co/t/securing-indexed-data/11404/5 "2013-04-02T13:14:11Z")

</div>

Actually, I was more thinking of cryptographic signatures or keyed hashing  
(HMAC), rather than encryption?

I will look into doing encryption at the filesystem level though, thanks.

On Monday, April 1, 2013 10:54:39 PM UTC+1, ppearcy wrote:

> I don't believe Lucene or elasticsearch provide this. This article has  
> some details:
> 
> [https://support.lucidworks.com/entries/22014021-Encrypting-Solr-Lucene-indexes](https://support.lucidworks.com/entries/22014021-Encrypting-Solr-Lucene-indexes)
> 
> Likely the best you can do is encrypt at the filesystem level and have all  
> communication pass over a secure connection.
> 
> I believe Lucene 4.0+ has some codec stuff exposed that you might be able  
> to hook into via a plugin in ES, but am really not sure if that is  
> feasible.
> 
> Best Regards,  
> Paul
> 
> On Monday, April 1, 2013 12:48:22 PM UTC-6, cocowalla wrote:
> 
> > Is it possible to make data in Elasticsearch indices tamper-proof? For  
> > example, does it have the capability to cryptographically sign blocks of  
> > data?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Billy\_Te](https://avatars.discourse-cdn.com/v4/letter/b/eada6e/32.png) [@Billy\_Te](https://discuss.elastic.co/u/Billy_Te)\
**Post date:** [October 12, 2013, 8:45pm UTC](https://discuss.elastic.co/t/securing-indexed-data/11404/6 "2013-10-12T20:45:21Z")

</div>

Why not store a hash of your data alongside the data? If the data is  
tampered with, you'll know cause the hash doesn't match. Of course, that  
would require that your hash secret isn't stolen along with your data -  
which would mean the key should originate from a different identity (say if  
it is a particular user's data, the key should live with the user, and  
never be transmitted to the server).

On Tuesday, April 2, 2013 6:14:11 AM UTC-7, cocowalla wrote:

> Actually, I was more thinking of cryptographic signatures or keyed hashing  
> (HMAC), rather than encryption?
> 
> I will look into doing encryption at the filesystem level though, thanks.
> 
> On Monday, April 1, 2013 10:54:39 PM UTC+1, ppearcy wrote:
> 
> > I don't believe Lucene or elasticsearch provide this. This article has  
> > some details:
> > 
> > [https://support.lucidworks.com/entries/22014021-Encrypting-Solr-Lucene-indexes](https://support.lucidworks.com/entries/22014021-Encrypting-Solr-Lucene-indexes)
> > 
> > Likely the best you can do is encrypt at the filesystem level and have  
> > all communication pass over a secure connection.
> > 
> > I believe Lucene 4.0+ has some codec stuff exposed that you might be able  
> > to hook into via a plugin in ES, but am really not sure if that is  
> > feasible.
> > 
> > Best Regards,  
> > Paul
> > 
> > On Monday, April 1, 2013 12:48:22 PM UTC-6, cocowalla wrote:
> > 
> > > Is it possible to make data in Elasticsearch indices tamper-proof? For  
> > > example, does it have the capability to cryptographically sign blocks of  
> > > data?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Billy\_Te](https://avatars.discourse-cdn.com/v4/letter/b/eada6e/32.png) [@Billy\_Te](https://discuss.elastic.co/u/Billy_Te)\
**Post date:** [October 12, 2013, 8:46pm UTC](https://discuss.elastic.co/t/securing-indexed-data/11404/7 "2013-10-12T20:46:14Z")

</div>

And by "hash secret isn't stolen along with your data" I meant "hash secret  
isn't accessible to the tamperer".

On Saturday, October 12, 2013 1:45:21 PM UTC-7, Billy Te wrote:

> Why not store a hash of your data alongside the data? If the data is  
> tampered with, you'll know cause the hash doesn't match. Of course, that  
> would require that your hash secret isn't stolen along with your data -  
> which would mean the key should originate from a different identity (say if  
> it is a particular user's data, the key should live with the user, and  
> never be transmitted to the server).
> 
> On Tuesday, April 2, 2013 6:14:11 AM UTC-7, cocowalla wrote:
> 
> > Actually, I was more thinking of cryptographic signatures or keyed  
> > hashing (HMAC), rather than encryption?
> > 
> > I will look into doing encryption at the filesystem level though, thanks.
> > 
> > On Monday, April 1, 2013 10:54:39 PM UTC+1, ppearcy wrote:
> > 
> > > I don't believe Lucene or elasticsearch provide this. This article has  
> > > some details:
> > > 
> > > [https://support.lucidworks.com/entries/22014021-Encrypting-Solr-Lucene-indexes](https://support.lucidworks.com/entries/22014021-Encrypting-Solr-Lucene-indexes)
> > > 
> > > Likely the best you can do is encrypt at the filesystem level and have  
> > > all communication pass over a secure connection.
> > > 
> > > I believe Lucene 4.0+ has some codec stuff exposed that you might be  
> > > able to hook into via a plugin in ES, but am really not sure if that is  
> > > feasible.
> > > 
> > > Best Regards,  
> > > Paul
> > > 
> > > On Monday, April 1, 2013 12:48:22 PM UTC-6, cocowalla wrote:
> > > 
> > > > Is it possible to make data in Elasticsearch indices tamper-proof? For  
> > > > example, does it have the capability to cryptographically sign blocks of  
> > > > data?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:12am UTC](https://discuss.elastic.co/t/securing-indexed-data/11404/8 "2017-07-06T02:12:46Z")

</div>


