# Setting up HTTPS for Elasticsearch 7.1

**URL:** <https://discuss.elastic.co/t/setting-up-https-for-elasticsearch-7-1/181913>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 20, 2019, 10:54pm UTC](https://discuss.elastic.co/t/setting-up-https-for-elasticsearch-7-1/181913 "2019-05-20T22:54:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krushna\_Bagde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krushna_bagde/32/46509_2.png) [@Krushna\_Bagde](https://discuss.elastic.co/u/Krushna_Bagde)\
**Post date:** [May 20, 2019, 10:54pm UTC](https://discuss.elastic.co/t/setting-up-https-for-elasticsearch-7-1/181913/1 "2019-05-20T22:54:43Z")

</div>

Hello,

It looks like the basic elastic license allows encrypted communications as listed here - [https://www.elastic.co/subscriptions](https://www.elastic.co/subscriptions) but the documentation says security is only available as a part of x-pack ([https://www.elastic.co/guide/en/elastic-stack-overview/current/elasticsearch-security.html](https://www.elastic.co/guide/en/elastic-stack-overview/current/elasticsearch-security.html)).  
Is the basic license enough for just SSL support? I am not looking at RBAC or anything else.

Regards,

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 21, 2019, 12:03am UTC](https://discuss.elastic.co/t/setting-up-https-for-elasticsearch-7-1/181913/2 "2019-05-21T00:03:35Z")

</div>

> [@Krushna\_Bagde](#):
>
> Is the basic license enough for just SSL support? I am not looking at RBAC or anything else.

Yes, see the first link for what is included in a Basic license.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 21, 2019, 12:56am UTC](https://discuss.elastic.co/t/setting-up-https-for-elasticsearch-7-1/181913/3 "2019-05-21T00:56:29Z")

</div>

> [@Krushna\_Bagde](#):
>
> basic elastic license allows encrypted communications ... but the documentation says security is only available as a part of x-pack

For clarity, the basic license is part of X-Pack.

Our product features are separated into Open Source and X-Pack.  
Some of X-Pack (like TLS, Native Authentication, and RBAC) is free on a basic license, and some of X-Pack requires a paid license.

---

<div class="post-metadata">

**Author:** ![Krushna\_Bagde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krushna_bagde/32/46509_2.png) [@Krushna\_Bagde](https://discuss.elastic.co/u/Krushna_Bagde)\
**Post date:** [May 21, 2019, 2:23am UTC](https://discuss.elastic.co/t/setting-up-https-for-elasticsearch-7-1/181913/4 "2019-05-21T02:23:35Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![piero](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@piero](https://discuss.elastic.co/u/piero)\
**Post date:** [May 23, 2019, 9:52pm UTC](https://discuss.elastic.co/t/setting-up-https-for-elasticsearch-7-1/181913/5 "2019-05-23T21:52:38Z")

</div>

hi @Krushna_Bagde,  
are you so kind to give us some details about how you configure elasticsearch.yml to manage https on elasticsearch url?  
How do you create certificate chain?  
thanks in advance

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 24, 2019, 2:10am UTC](https://discuss.elastic.co/t/setting-up-https-for-elasticsearch-7-1/181913/6 "2019-05-24T02:10:40Z")

</div>

There is documentation here:

- [https://www.elastic.co/guide/en/elasticsearch/reference/7.1/configuring-tls.html#tls-http](https://www.elastic.co/guide/en/elasticsearch/reference/7.1/configuring-tls.html#tls-http)

Are you running into a particular problem?

---

<div class="post-metadata">

**Author:** ![piero](https://avatars.discourse-cdn.com/v4/letter/p/b5e925/32.png) [@piero](https://discuss.elastic.co/u/piero)\
**Post date:** [May 24, 2019, 6:46am UTC](https://discuss.elastic.co/t/setting-up-https-for-elasticsearch-7-1/181913/7 "2019-05-24T06:46:19Z")

</div>

@TimV thanks for the link  
I'm working with the 6.8 version so i read the same info about this versioning  
I have errors as kibana and logstash try to connect to elasticsearch in https.

Till now i'm just configure basic authentication and it's working fine, but i don't understand how create the working certificate that i will write in these lines on elastic.yml:  
( I choose pem certificates)

xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.key: /home/es/config/node01.key  
xpack.security.http.ssl.certificate: /home/es/config/node01.crt  
xpack.security.http.ssl.certificate\_authorities: ["/home/es/config/ca.crt"]

Can i use the same certificate on the three nodes elastic cluster?  
Which are the correct commands to create it?  
Maybe do I have to use the same certificate indicated in this elasticsearch.yml lines?

xpack.security.enabled: true  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12  
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

( I know these are for communication between nodes and this part it's working fine because i check with GET \_cat/nodes )

thanks for your attention

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2019, 6:58am UTC](https://discuss.elastic.co/t/setting-up-https-for-elasticsearch-7-1/181913/8 "2019-06-21T06:58:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
