IMPORTANT: Version 6.3 of Elasticsearch has passed its maintenance date.
This documentation is no longer being updated. For the latest information, see the current release documentation.
You can configure X-Pack security to use Public Key Infrastructure (PKI) certificates to authenticate users in Elasticsearch. This requires clients to present X.509 certificates.
You cannot use PKI certificates to authenticate users in Kibana.
To use PKI in Elasticsearch, you configure a PKI realm, enable client authentication on the desired network layers (transport or http), and map the Distinguished Names (DNs) from the user certificates to X-Pack security roles in the role mapping file.
See PKI realm settings.