# Set up basic security for the Elastic Stack plus secured HTTPS traffic |

**URL:** <https://discuss.elastic.co/t/set-up-basic-security-for-the-elastic-stack-plus-secured-https-traffic/309857>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 18, 2022, 8:08am UTC](https://discuss.elastic.co/t/set-up-basic-security-for-the-elastic-stack-plus-secured-https-traffic/309857 "2022-07-18T08:08:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AGiles102](https://avatars.discourse-cdn.com/v4/letter/a/b2d939/32.png) [@AGiles102](https://discuss.elastic.co/u/AGiles102)\
**Post date:** [July 18, 2022, 8:08am UTC](https://discuss.elastic.co/t/set-up-basic-security-for-the-elastic-stack-plus-secured-https-traffic/309857/1 "2022-07-18T08:08:57Z")

</div>

> **[Set up basic security for the Elastic Stack plus secured HTTPS traffic |...](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/security-basic-setup-https.html)**

Hi all, I have set up two of the three security layers of Elasticsearch. I am now trying to implement HTTPS, and after speaking to our in-house infrastructure, they can't offer us "Sign certificates with a central CA" on our domain. However, they can give us a signed SSL certificate from a third party (with ca file etc.. if required). Is there a way I can implement a third-party certificate, or is the only option we have remaining to sign our certificates?

thank you.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [July 19, 2022, 12:44am UTC](https://discuss.elastic.co/t/set-up-basic-security-for-the-elastic-stack-plus-secured-https-traffic/309857/2 "2022-07-19T00:44:30Z")

</div>

On the HTTP layer, it's totally fine to use any SSL certificate and CA that make sense to your organisation. Just be sure you need both the signed certificate and the associated private key for configuring HTTPS.

---

<div class="post-metadata">

**Author:** ![AGiles102](https://avatars.discourse-cdn.com/v4/letter/a/b2d939/32.png) [@AGiles102](https://discuss.elastic.co/u/AGiles102)\
**Post date:** [July 19, 2022, 7:58am UTC](https://discuss.elastic.co/t/set-up-basic-security-for-the-elastic-stack-plus-secured-https-traffic/309857/3 "2022-07-19T07:58:19Z")

</div>

@Yang_Wang - Thank you for getting back to me.  
Do you have a list of steps required to apply a third party SSl / privatekey?  
Regards, Alan

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [July 20, 2022, 12:53am UTC](https://discuss.elastic.co/t/set-up-basic-security-for-the-elastic-stack-plus-secured-https-traffic/309857/4 "2022-07-20T00:53:24Z")

</div>

> [@AGiles102](#):
>
> Do you have a list of steps required to apply a third party SSl / privatekey?

Do you mean "steps of applying for cert/private key from a 3rd party provider" or "apply the certs and private keys from the 3rd party to a ES cluster"?

I cannot help with the former because it is outside of ES.

For the later, you just need configure [relevant settings](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html#security-http-tls-ssl-key-trusted-certificate-settings) to the cert and key file(s). This [guide](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/security-basic-setup-https.html) for setting up basic security and HTTPs can still be helpful. Just skip all parts about generating your own cert/key.

---

<div class="post-metadata">

**Author:** ![AGiles102](https://avatars.discourse-cdn.com/v4/letter/a/b2d939/32.png) [@AGiles102](https://discuss.elastic.co/u/AGiles102)\
**Post date:** [July 21, 2022, 1:18pm UTC](https://discuss.elastic.co/t/set-up-basic-security-for-the-elastic-stack-plus-secured-https-traffic/309857/5 "2022-07-21T13:18:28Z")

</div>

@Yang_Wang - thank you for your help. I've got it working

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2022, 1:18pm UTC](https://discuss.elastic.co/t/set-up-basic-security-for-the-elastic-stack-plus-secured-https-traffic/309857/6 "2022-08-18T13:18:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
