# searchguard.ssl.transport.enabled must be set to 'true'

**URL:** https://forum.search-guard.com/t/searchguard-ssl-transport-enabled-must-be-set-to-true/403
**Category:** Search Guard
**Created:** [February 28, 2017, 7:57am UTC](https://forum.search-guard.com/t/searchguard-ssl-transport-enabled-must-be-set-to-true/403 "2017-02-28T07:57:08Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![pc\_c](https://avatars.discourse-cdn.com/v4/letter/p/47e85d/32.png) [@pc\_c](https://forum.search-guard.com/u/pc_c)
#### Post date: [February 28, 2017, 7:57am UTC](https://forum.search-guard.com/t/searchguard-ssl-transport-enabled-must-be-set-to-true/403/1 "2017-02-28T07:57:08Z")

</div>

I am using ES 5.0.2 and SG 5.0.2-11.

I am installing Search Guard for security purpose. I am trying to skip configuring transport layer security but got error message searchguard.ssl.transport.enabled must be set to ‘true’. I don’t think it necessary for me to make transport layer secure, because our system only uses HTTP to communicate with ES cluster. Transport layer is only used between ES nodes.

We decide to disable 9300 ports from outside of cluster. So any communication with ES cluster is always through HTTP, and HTTP is secured by SG. Clients can not use transport protocol, because it’s blocked by iptables. In this way, ES cluster is secure enough even if transport layer SSL is disabled.

So the question is:

1. Is it secure when I disable transport layer SSL and block 9300 ports?

2. How to disable transport layer SSL?

---

<div class="post-metadata">

### Author: ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)
#### Post date: [February 28, 2017, 12:00pm UTC](https://forum.search-guard.com/t/searchguard-ssl-transport-enabled-must-be-set-to-true/403/2 "2017-02-28T12:00:56Z")

</div>

> **[Security and Alerting for Elasticsearch and Kibana | Search Guard](https://search-guard.com/)**
>
> Search Guard is an Open Source security plugin for Elasticsearch, Kibana and the entire ELK stack. Search Guard offers encryption, authentication, authorization, audit logging, compliance as well as alerting and anomaly detection features.

[https://groups.google.com/forum/#!topic/search-guard/TBV7XHLNrf8](https://groups.google.com/forum/#!topic/search-guard/TBV7XHLNrf8)  
[https://github.com/floragunncom/search-guard-ssl/issues/49](https://github.com/floragunncom/search-guard-ssl/issues/49)

> **···**
>
> On Tuesday, 28 February 2017 08:57:08 UTC+1, pc c wrote:
> 
> > I am using ES 5.0.2 and SG 5.0.2-11.
> 
> > 
> 
> > I am installing Search Guard for security purpose. I am trying to skip configuring transport layer security but got error message searchguard.ssl.transport.enabled must be set to ‘true’. I don’t think it necessary for me to make transport layer secure, because our system only uses HTTP to communicate with ES cluster. Transport layer is only used between ES nodes.
> 
> > We decide to disable 9300 ports from outside of cluster. So any communication with ES cluster is always through HTTP, and HTTP is secured by SG. Clients can not use transport protocol, because it’s blocked by iptables. In this way, ES cluster is secure enough even if transport layer SSL is disabled.
> 
> > 
> 
> > So the question is:
> 
> > 1. Is it secure when I disable transport layer SSL and block 9300 ports?
> 
> > 1. How to disable transport layer SSL?
> 
> >
