# Using PKI based auth for a cluster created with elastic cloud on k8S

**URL:** <https://discuss.elastic.co/t/using-pki-based-auth-for-a-cluster-created-with-elastic-cloud-on-k8s/254245>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [November 4, 2020, 10:26am UTC](https://discuss.elastic.co/t/using-pki-based-auth-for-a-cluster-created-with-elastic-cloud-on-k8s/254245 "2020-11-04T10:26:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![boranx](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@boranx](https://discuss.elastic.co/u/boranx)\
**Post date:** [November 4, 2020, 10:26am UTC](https://discuss.elastic.co/t/using-pki-based-auth-for-a-cluster-created-with-elastic-cloud-on-k8s/254245/1 "2020-11-04T10:26:04Z")

</div>

Hey folks!

I'd like to ask if using PKI for [elastic cloud on k8S](https://github.com/elastic/cloud-on-k8s) is possible or not. I want to authenticate without a password but using the key and cert file.

---

<div class="post-metadata">

**Author:** ![boranx](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@boranx](https://discuss.elastic.co/u/boranx)\
**Post date:** [November 4, 2020, 11:48am UTC](https://discuss.elastic.co/t/using-pki-based-auth-for-a-cluster-created-with-elastic-cloud-on-k8s/254245/2 "2020-11-04T11:48:20Z")

</div>

eck version 1.2

yaml:

```
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
 name: elasticsearch-sample
spec:
 http:
  tls:
   certificate:
    secretName: quickstart-es-cert
 version: 7.9.3
 nodeSets:
 - name: default
   count: 1
   config:
     xpack.security.http.ssl.enabled: true
     xpack.security.http.ssl.client_authentication: optional
     xpack.security.authc:
         realms:
           pki:
            pki1:
             order: 1
     node.master: true
     node.data: true
     node.ingest: true
     node.store.allow_mmap: false

```

`curl -k -v https://localhost:9200/_xpack/security/_authenticate?pretty --key /usr/share/elasticsearch/config/http-certs/tls.key --cert /usr/share/elasticsearch/config/http-certs/tls.crt --cacert /usr/share/elasticsearch/config/http-certs/ca.crt`

returns 401  
` { "error" : { "root_cause" : [{ "type" : "security_exception", "reason" : "missing authentication credentials for REST request [/_xpack/security/_authenticate?pretty]", "header" : { "WWW-Authenticate" : ["Basic realm=\"security\" charset=\"UTF-8\"", "Bearer realm=\"security\"", "ApiKey"] } } ], "type" : "security_exception", "reason" : "missing authentication credentials for REST request [/_xpack/security/_authenticate?pretty]", "header" : { "WWW-Authenticate" : ["Basic realm=\"security\" charset=\"UTF-8\"", "Bearer realm=\"security\"", "ApiKey"] } }, "status" : 401 }`

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [November 4, 2020, 1:29pm UTC](https://discuss.elastic.co/t/using-pki-based-auth-for-a-cluster-created-with-elastic-cloud-on-k8s/254245/3 "2020-11-04T13:29:17Z")

</div>

Hey @boranx,

I tried a similar setup and it works fine. The PKI realm [requires a GOLD+ license](https://www.elastic.co/subscriptions). Is that the case for your cluster?

I'm having the same error you get, but things work fine as soon as I [apply a trial license](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-licensing.html#k8s-start-trial) to my ECK setup.

---

<div class="post-metadata">

**Author:** ![boranx](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@boranx](https://discuss.elastic.co/u/boranx)\
**Post date:** [November 4, 2020, 4:22pm UTC](https://discuss.elastic.co/t/using-pki-based-auth-for-a-cluster-created-with-elastic-cloud-on-k8s/254245/4 "2020-11-04T16:22:11Z")

</div>

hey @sebgl

Thanks for the quick answer! Yep that was exactly the case. After I applied the trial license as you mentioned, it worked as expected.

Wish you a good week,  
cheers

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [November 4, 2020, 4:46pm UTC](https://discuss.elastic.co/t/using-pki-based-auth-for-a-cluster-created-with-elastic-cloud-on-k8s/254245/5 "2020-11-04T16:46:13Z")

</div>

Elasticsearch issue to make that behaviour more easily discoverable: [https://github.com/elastic/elasticsearch/issues/45728](https://github.com/elastic/elasticsearch/issues/45728).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:16am UTC](https://discuss.elastic.co/t/using-pki-based-auth-for-a-cluster-created-with-elastic-cloud-on-k8s/254245/6 "2022-11-04T08:16:56Z")

</div>


