# Simple HTTPS connection to ES

**URL:** <https://discuss.elastic.co/t/simple-https-connection-to-es/194827>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 12, 2019, 10:29am UTC](https://discuss.elastic.co/t/simple-https-connection-to-es/194827 "2019-08-12T10:29:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lincoln\_dev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lincoln_dev/32/52101_2.png) [@Lincoln\_dev](https://discuss.elastic.co/u/Lincoln_dev)\
**Post date:** [August 12, 2019, 10:29am UTC](https://discuss.elastic.co/t/simple-https-connection-to-es/194827/1 "2019-08-12T10:29:42Z")

</div>

Hello !

It's my first time here, so I hope I have done things well.

I am currently working on a project using ES.

I have the following setup :

- One serveur where ES is running in HTTP : ES\_SERVER
- One Website in HTTP : CLIENT
- One Website in HTTPS : ADMINISTRATION

The CLIENT website perform http request to ES\_SERVER in AJAX from the browser.

I want to perform the followin evolution :

I want the ADMINISTRATION website to be able to perform request to the ES\_SERVER.

At the beggining, I wanted to do it in ajax, from the browser.  
However, it is not possible to perform request to a server without encryption from an HTTPS connection.

So, I decided to put SSL and HTTPS to my ES\_SERVER.

Now that it is done, I understand that it is not possible to just call "https://ES\_SERVER"

So my questions are the following :

- Is it possible to perform an AJAX call, from the browser, to an ES\_SERVER in HTTPS ? (I think I understand it is not possible)

- What is the right way to interact from a browser to a ES\_SERVER using HTTPS ? (I think using a curl request from the server side is better than I currently do with the ajax request client-side)

- is there any way to connect to ES\_SERVER without any password or user ? (Then again, if from server side, it is not really an issue)

If the situation is not clear, feel free to ask any questions.

Thank you for your answeres,

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 12, 2019, 11:01am UTC](https://discuss.elastic.co/t/simple-https-connection-to-es/194827/2 "2019-08-12T11:01:48Z")

</div>

> [@Lincoln\_dev](#):
>
> Now that it is done, I understand that it is not possible to just call "https://ES\_SERVER"

Why is that ? What issue did you encounter that lead you to think that?

> [@Lincoln\_dev](#):
>
> Is it possible to perform an AJAX call, from the browser, to an ES\_SERVER in HTTPS ? (I think I understand it is not possible)

Yes, it is. See also the CORS related settings in [HTTP | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-http.html).

> [@Lincoln\_dev](#):
>
> What is the right way to interact from a browser to a ES\_SERVER using HTTPS ? (I think using a curl request from the server side is better than I currently do with the ajax request client-side)

I'm not really sure we can answer this question for you. From a functionality/feature perspective, It depends on your use case . From a security perspective there are potential risks with both approaches and, as usual, the devil is in the implementation details. A very prominent difference that might help you select what's best for you is that with the ajax request option, you need to give Elasticsearch credentials ( i.e. replicate all your ADMINISTRATION users to Elasticsearch and keep their passwords in sync) to _all_ your ADMINISTRATION website users as they will make the requests via their browsers. On the contrary, if you handle requests on the backend side with i.e. curl, then you can keep your existing authentication scheme for the ADMINISTRATION website and use a single ES user to make all the requests to ES ( Note that this can be tricky if not all your users should have the same access to the same data in Elasticsearch )

> [@Lincoln\_dev](#):
>
> is there any way to connect to ES\_SERVER without any password or user ? (Then again, if from server side, it is not really an issue)

You can enable anonymous access as described in [Enabling anonymous access | Elasticsearch Guide [7.3] | Elastic](https://www.elastic.co/guide/en/elastic-stack-overview/7.3/anonymous-access.html) if that fits your use case/requirements.

---

<div class="post-metadata">

**Author:** ![Lincoln\_dev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lincoln_dev/32/52101_2.png) [@Lincoln\_dev](https://discuss.elastic.co/u/Lincoln_dev)\
**Post date:** [August 12, 2019, 1:27pm UTC](https://discuss.elastic.co/t/simple-https-connection-to-es/194827/3 "2019-08-12T13:27:04Z")

</div>

Thanks a lot for your answerers !

> [@ikakavas](#):
>
> Why is that ? What issue did you encounter that lead you to think that?

Well, I have this error in the browser : net::ERR\_CONNECTION\_REFUSED

But I give no credential in any way in my ajax request.  
That's what led me to think my implementation was wrong to begin with.

> [@ikakavas](#):
>
> Yes, it is. See also the CORS related settings in [HTTP | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-http.html).

Thanks, I did not tried with http.cors.allow-credentials.

The way things work for my project,

There is one ADMINISTRATION server with different users, and there is multiple CLIENT website, who use the same ES\_SERVER, but with different indexes. The client is public and accessible for everyone, whereas the ADMINISTRATION is for a selected few.

Either way, If I understand you correctly

> [@ikakavas](#):
>
> with the ajax request option, you need to give Elasticsearch credentials

I'm not security expert, but I think it is a risk to let the public thing with no protection whatsoever have the credentials.

I think it is not an issue to use the same ES user, since all data are compartimented within indexes, and if I set everything in curl, there is no simple way for the client to access other's data.

So If I understand clearly :

I have to use the auth system of ES, creat ONE ES user with rights for everything, but set every request serverside with CURL.

Do I have to set PKI realm for that purpose ?

Can I do that with .p12 file ?

Thank you !

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 13, 2019, 6:50am UTC](https://discuss.elastic.co/t/simple-https-connection-to-es/194827/4 "2019-08-13T06:50:55Z")

</div>

> [@Lincoln\_dev](#):
>
> I'm not security expert, but I think it is a risk to let the public thing with no protection whatsoever have the credentials.

I didn't mean that you should give your Elasticsearch credentials to all your users. I meant that you could create users ( one for every one of your existing user ) so every user can make requests to Elasticsearch on their own with any of the permissions you want to allow them to have.

> [@Lincoln\_dev](#):
>
> I think it is not an issue to use the same ES user, since all data are compartimented within indexes, and if I set everything in curl, there is no simple way for the client to access other's data.

There is no point to have a single ES user that has read access to everything from every CLIENT WEBSITE. If one of your CLIENT websites gets compromised, then an attacker gets access to all the data in Elasticsearch. Since your data is already compartmentalized, you should probably better create 1 Elasticsearch user per CLIENT website and give each one read access to only the specific index that it will need to make queries for, for the given CLIENT website.

> [@Lincoln\_dev](#):
>
> So If I understand clearly :
> 
> I have to use the auth system of ES, creat ONE ES user with rights for everything, but set every request serverside with CURL.

No, not exactly, see above.

> [@Lincoln\_dev](#):
>
> Do I have to set PKI realm for that purpose ?

No, you can use any of the existing realms that your license level covers to authenticate your users to Elasticsearch.

> [@Lincoln\_dev](#):
>
> Can I do that with .p12 file ?

I'm not sure I understand this question.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2019, 7:04am UTC](https://discuss.elastic.co/t/simple-https-connection-to-es/194827/5 "2019-09-10T07:04:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
