# Xpack security feature showing inconsistent behavior

**URL:** <https://discuss.elastic.co/t/xpack-security-feature-showing-inconsistent-behavior/206417>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [November 4, 2019, 2:01pm UTC](https://discuss.elastic.co/t/xpack-security-feature-showing-inconsistent-behavior/206417 "2019-11-04T14:01:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajat\_badjatya](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajat_badjatya/32/57104_2.png) [@rajat\_badjatya](https://discuss.elastic.co/u/rajat_badjatya)\
**Post date:** [November 4, 2019, 2:01pm UTC](https://discuss.elastic.co/t/xpack-security-feature-showing-inconsistent-behavior/206417/1 "2019-11-04T14:01:47Z")

</div>

My ES cluster is running in production mode(on Kubernetes). It is accessible only within the organization so, for now, there is no need for securing the connection between ES nodes with certificates. While setting up the cluster I just added `xpack.security.enabled: true` that helped me in setting up a basic Kibana authentication and everything was working as expected. Due to some reason, I restarted my pods for data nodes and now it showing the following error:

```
ERROR: [1] bootstrap checks failed
[1]: Transport SSL must be enabled if security is enabled on a [basic] license. Please set [xpack.security.transport.ssl.enabled] to [true] or disable security by setting [xpack.security.enabled] to [false]

```

I would be glad if someone could help me on this.  
PS: ELK stack version: 7.3.2

---

<div class="post-metadata">

**Author:** ![Bernt\_Rostad](https://avatars.discourse-cdn.com/v4/letter/b/3ab097/32.png) [@Bernt\_Rostad](https://discuss.elastic.co/u/Bernt_Rostad)\
**Post date:** [November 4, 2019, 3:21pm UTC](https://discuss.elastic.co/t/xpack-security-feature-showing-inconsistent-behavior/206417/2 "2019-11-04T15:21:18Z")

</div>

The error message you quote tells us what's wrong: It's not possible to enable xpack security in a multi-node cluster without also enabling transport layer security (TLS) between the nodes - as explained in [the official documentation](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/ssl-tls.html):

> Clusters that do not have encryption enabled send all data in plain text including passwords. If the Elasticsearch security features are enabled, unless you have a trial license, you must configure SSL/TLS for internode-communication.

So you will have to generate unique node certificates for each node in your cluster, to enable TLS between them, before you can set `xpack.security.enabled: true` in the **elasticsearch.yml** files.

Good luck!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 2, 2019, 3:21pm UTC](https://discuss.elastic.co/t/xpack-security-feature-showing-inconsistent-behavior/206417/3 "2019-12-02T15:21:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
