Transport SSL Verification: Full vs Certificate Mode for Dynamic Node Scaling
27.5K reputation · 20 Oct 2025, 14:09 UTC
When configuring node-to-node communication in Elasticsearch (version 8.x), the xpack.security.transport.ssl.verification_mode setting determines how certificates are validated during the SSL handshake. The goal is to maintain a secure transport layer while allowing the cluster to scale across dynamic infrastructure where hostnames may change or be assigned programmatically.
Using full verification ensures the highest security by validating both the certificate chain and the hostname via Subject Alternative Names (SANs). However, this requires precise certificate issuance for every new node. Conversely, certificate mode validates the trust chain but bypasses the hostname check, simplifying deployment in environments with fluid network identities.
- Full Mode: Requires strict SAN alignment to prevent man-in-the-middle attacks.
- Certificate Mode: Reduces configuration overhead but relaxes identity verification.
Which verification mode is more sustainable for a cluster utilizing auto-scaling groups where nodes are frequently replaced? What are the specific security trade-offs when opting for certificate mode over full in a private VPC?