# Setting xpack.security.enabled = true

**URL:** <https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 26, 2019, 9:06am UTC](https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791 "2019-05-26T09:06:28Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hooman\_Bahreini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hooman_bahreini/32/29500_2.png) [@Hooman\_Bahreini](https://discuss.elastic.co/u/Hooman_Bahreini)\
**Post date:** [May 26, 2019, 9:06am UTC](https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791/1 "2019-05-26T09:06:29Z")

</div>

I have installed Elasticsearch 7, on Ubuntu. I believe x-pack is installed by default, buy I need to enable it.

in which file should I set this setting?

My cluster settings are in:`/etc/elasticsearch/elasticsearch.yml` and `/etc/default/elasticsearch`

But I cannot see any commented `Setting xpack.security.enabled` variable in any of these files...

Also, will I be able to continue protecting my cluster with username/password with the Basic (free license) after the trial period is over?

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [May 26, 2019, 11:16am UTC](https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791/2 "2019-05-26T11:16:09Z")

</div>

@Hooman_Bahreini you can follow this blog post that explain how to use security starting from version 7.1 [https://www.elastic.co/fr/blog/getting-started-with-elasticsearch-security](https://www.elastic.co/fr/blog/getting-started-with-elasticsearch-security)

---

<div class="post-metadata">

**Author:** ![Hooman\_Bahreini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hooman_bahreini/32/29500_2.png) [@Hooman\_Bahreini](https://discuss.elastic.co/u/Hooman_Bahreini)\
**Post date:** [May 26, 2019, 11:41am UTC](https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791/3 "2019-05-26T11:41:32Z")

</div>

Thanks a lot. So I am using the basic version and I believe I need to set xpack.security.transport.ssl.enabled = true

I see the document that you have included that I can use elasticsearch certl util, but does it mean that I have to install a SSL certificate on my webserver too to communicate with ES Cluster?

I just want to password protect the cluster, is it possible to achieve this without setting all these security variables?

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [May 26, 2019, 11:45am UTC](https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791/4 "2019-05-26T11:45:05Z")

</div>

Yes, you can just enable x-pack security in elasticsearch.yml with xpack.security.enabled: true  
Run your node, and run use this tool elasticsearch-setup-passwords to setup passwords

---

<div class="post-metadata">

**Author:** ![Hooman\_Bahreini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hooman_bahreini/32/29500_2.png) [@Hooman\_Bahreini](https://discuss.elastic.co/u/Hooman_Bahreini)\
**Post date:** [May 26, 2019, 11:50am UTC](https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791/5 "2019-05-26T11:50:57Z")

</div>

Thanks, when I set xpack.security.enabled: true, I get message from elastic search saying I need to set xpack.security.transport.ssl.enabled: true if I am using the basic version...

I believe once xpack.security.transport.ssl.enabled is enabled I need to install some SSL certificates on the nodes (which I can see how it is done in the document that you have included). I am just wondering if I need to install an SSL certificate on my WebServer as well to communicate with the nodes? (I don't want an SSL on the web server as they are all inside a private network).

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [May 26, 2019, 12:13pm UTC](https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791/6 "2019-05-26T12:13:10Z")

</div>

Make sure you are using version 7.1.0

---

<div class="post-metadata">

**Author:** ![Hooman\_Bahreini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hooman_bahreini/32/29500_2.png) [@Hooman\_Bahreini](https://discuss.elastic.co/u/Hooman_Bahreini)\
**Post date:** [May 26, 2019, 11:23pm UTC](https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791/7 "2019-05-26T23:23:11Z")

</div>

I am using elasticsearch 7.1

If I set `xpack.security.enabled: true` then I will get the following message:

Transport SSL must be enabled if security is enabled on a [basic] license. Please set [xpack.security.transport.ssl.enabled] to [true] or disable security by setting [xpack.security.enabled]

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [June 1, 2019, 6:50pm UTC](https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791/8 "2019-06-01T18:50:00Z")

</div>

For a cluster that is running in [production mode](https://www.elastic.co/guide/en/elasticsearch/reference/current/bootstrap-checks.html#_development_vs_production_mode) with a production license, once security is enabled, transport TLS/SSL must also be enabled. On the other hand, if we are running with a trial license, then transport TLS/SSL is not obligatory.

If we are running with a production license and we attempt to start the cluster with security enabled before we have enabled transport TLS/SSL, we will see the following error message:

Transport SSL must be enabled for setups with production licenses. Please set [xpack.security.transport.ssl.enabled] to [true] or disable security by setting [xpack.security.enabled] to [false]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2019, 6:50pm UTC](https://discuss.elastic.co/t/setting-xpack-security-enabled-true/182791/9 "2019-06-29T18:50:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
