# SSL and Elastic API

**URL:** <https://discuss.elastic.co/t/ssl-and-elastic-api/224201>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 19, 2020, 12:01am UTC](https://discuss.elastic.co/t/ssl-and-elastic-api/224201 "2020-03-19T00:01:34Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [March 19, 2020, 12:01am UTC](https://discuss.elastic.co/t/ssl-and-elastic-api/224201/1 "2020-03-19T00:01:34Z")

</div>

Hi, I have enabled SSL in elastic search, then using Postman I try to make a request to elastic and didn't work, I have to turn off 'SSL certificate verification' in Postman to make the request.

That means that the programers, that get data from elastic API, will need some kind of file to acces the api?

If the last is true, what files will they need? and where do I get them?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 19, 2020, 12:07am UTC](https://discuss.elastic.co/t/ssl-and-elastic-api/224201/2 "2020-03-19T00:07:21Z")

</div>

Ignoring SSL verification means that it won't validate the entire certificate chain. This is not ideal as it means the certificate could be fake and you'd never know.

How did you create the certificate?

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [March 19, 2020, 12:13am UTC](https://discuss.elastic.co/t/ssl-and-elastic-api/224201/3 "2020-03-19T00:13:07Z")

</div>

Hi warkolm I create it with the commands:

```auto
bin/elasticsearch-certutil ca

and

bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12

```

and get two files elastic-certificates.p12 and elastic-stack-ca.p12

I use elastic-certificates.p12 to enable ssl in elasticsearch.yml

```auto
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: elastic-certificates.p12
xpack.security.http.ssl.truststore.path: elastic-certificates.p12

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 19, 2020, 6:29am UTC](https://discuss.elastic.co/t/ssl-and-elastic-api/224201/4 "2020-03-19T06:29:25Z")

</div>

These ( the certificates in `elastic-certificates.p12` ) are certificates that are signed by an autogenerated CA ( `elastic-stack-ca.p12` ) and that means that your operating system ( and by extension postman ) doesn't know if it should trust them or not . This is why you need to turn off SSL verification in postman in order to make requests, otherwise it fails.

Depending on how you are going to deploy your Elasticsearch cluster and who will be accessing it you have a few options:

- Get a certificate that is signed by your company's / organization CA. This is what you (or your IT department) would do for any other internal company wide service that is deployed. The OS/Browsers of the users should have been configured to trust that CA so that they can verify the authenticity of the Elasticsearch's certificate
- Get a certificate signed by a well known and trusted CA that your browser and OS already trust ( This is what all widely accessible services do. Take for example `https://discuss.elastic.co` which uses a certificate signed by Let's Encrypt and your browser trusts it because it trusts Let's Encrypt ). This is advisable if your users are not just internal to an organization
- If you expect just a handful of users, it might be acceptable to hand them the `elastic-stack-ca.p12` file and tell them to add this as a trusted CA in their browser/postman/
-

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [March 19, 2020, 12:43pm UTC](https://discuss.elastic.co/t/ssl-and-elastic-api/224201/5 "2020-03-19T12:43:28Z")

</div>

Thanks Ikakavas for your comprehensive answer, so if I get a external (own company or Let's encript) certificate, I just add the file in the machine and his path in the configuration?

```auto
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: external-cert.p12
xpack.security.http.ssl.truststore.path: external-cert.p12

```

there will be no problem to have a certificate generated by elastic in the trasport, and external certificate in http?

like this?

```auto
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.keystore.type: PKCS12
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.type: PKCS12

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: external-cert.p12
xpack.security.http.ssl.truststore.path: external-cert.p12

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 19, 2020, 1:54pm UTC](https://discuss.elastic.co/t/ssl-and-elastic-api/224201/6 "2020-03-19T13:54:52Z")

</div>

> [@Incauto](#):
>
> I just add the file in the machine and his path in the configuration?

Yes, if you have them as a PKCS#12 container. If you have them as PEM encoded files you would need to adjust to something like :

```auto
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.key: external-cert.key
xpack.security.http.ssl.certificate: external-cert.crt
xpack.security.http.ssl.certificate_authorities: ["your/ca/cert.crt"]

```

See also [our docs](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/configuring-tls.html#tls-http)

> [@Incauto](#):
>
> there will be no problem to have a certificate generated by elastic in the trasport, and external certificate in http?

No problem at all

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2020, 1:54pm UTC](https://discuss.elastic.co/t/ssl-and-elastic-api/224201/7 "2020-04-16T13:54:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
