# Xpack.security.authc.api\_key.enabled in ECK with TLS self signed certificate disabled

**URL:** <https://discuss.elastic.co/t/xpack-security-authc-api-key-enabled-in-eck-with-tls-self-signed-certificate-disabled/298767>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 3, 2022, 4:58pm UTC](https://discuss.elastic.co/t/xpack-security-authc-api-key-enabled-in-eck-with-tls-self-signed-certificate-disabled/298767 "2022-03-03T16:58:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![trudesea](https://avatars.discourse-cdn.com/v4/letter/t/e480ec/32.png) [@trudesea](https://discuss.elastic.co/u/trudesea)\
**Post date:** [March 3, 2022, 4:58pm UTC](https://discuss.elastic.co/t/xpack-security-authc-api-key-enabled-in-eck-with-tls-self-signed-certificate-disabled/298767/1 "2022-03-03T16:58:27Z")

</div>

Hi,

I'm using ECK on GKE and terminating SSL with LBs and Google managed certs. I have an issue where I cannot implement Fleet because of TLS being disabled. I remember seeing a post where this requirement would be removed in a later version, but that was a few versions back.

I'm running 7.17.1 and I'm unable to find a workaround

Any ideas on how I can't get this to work or do I need to rethink the implementation?

Thanks

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 4, 2022, 12:18am UTC](https://discuss.elastic.co/t/xpack-security-authc-api-key-enabled-in-eck-with-tls-self-signed-certificate-disabled/298767/2 "2022-03-04T00:18:14Z")

</div>

> I have an issue where I cannot implement Fleet because of TLS being disabled.

In 7.17.1, it is possible to enable API Keys without enabling TLS, but you need to do it manually.

However, I believe Fleet has a specific requirement to enable TLS separate to API Keys, and I don't recall whether they're checking the cluster itself, or the URL protocol.

---

<div class="post-metadata">

**Author:** ![trudesea](https://avatars.discourse-cdn.com/v4/letter/t/e480ec/32.png) [@trudesea](https://discuss.elastic.co/u/trudesea)\
**Post date:** [March 4, 2022, 1:58pm UTC](https://discuss.elastic.co/t/xpack-security-authc-api-key-enabled-in-eck-with-tls-self-signed-certificate-disabled/298767/3 "2022-03-04T13:58:59Z")

</div>

Thanks for the reply Tim, this is probably a game breaker for us with ECK then, a shame in that it was really easy to get setup and running for a production ready systems. If there is a work around, I haven't found it with Google Fu.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2022, 1:59pm UTC](https://discuss.elastic.co/t/xpack-security-authc-api-key-enabled-in-eck-with-tls-self-signed-certificate-disabled/298767/4 "2022-04-01T13:59:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
