Upcoming Elastic Changes in 2.3.40 #3449
Locked
TOoSmOotH
announced in
Announcements
Replies: 1 comment
-
Wanted to bring this to the front since 2.3.40 is being released today. Check your integrations with external tools and change them to https. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
We recently posted about the Elastic License changes and how we plan to deal with them. If you haven't already, you should read through it to understand the Elastic License changes and what they mean for you:
https://blog.securityonion.net/2021/02/elastic-license-changes-and-security.html
Starting in the upcoming Security Onion 2.3.40 release, we will use the basic Elastic License. This means you will be running Elastic Features by default. All upgrades and new installs will require you to accept the Elastic License.
The biggest change from a technical standpoint is the use of Elastic Security for encryption. All Elastic communications will be encrypted with TLS/SSL. Enabling HTTPS encryption in Elastic automatically turns on Elastic authentication as well. To maintain the current functionality, we will enable anonymous access to Elasticsearch and Kibana. This anonymous access mimics the access controls of Security Onion today where access is controlled via the firewall for these services. If you are using any external services that are connecting directly to Elasticsearch on port 9200, then you will need to change those to use HTTPS when you upgrade to Security Onion 2.3.40.
You will also notice changes in Kibana. First, you will see several new menu options that come with the new Elastic License. You will also see in the upper right corner that you are logged in as the user "anonymous". In the OSS version of Kibana, you were logged in as anonymous by default, it just doesn't display the user in the upper right corner.
We wanted to make you aware of these changes ahead of time so that you can be prepared. Please let us know if you have any questions or concerns!
Beta Was this translation helpful? Give feedback.
All reactions