# How to disable SSL locally?

**URL:** <https://forum.opensearch.org/t/how-to-disable-ssl-locally/6656>\
**Category:** Security\
**Created:** [July 29, 2021, 4:54pm UTC](https://forum.opensearch.org/t/how-to-disable-ssl-locally/6656 "2021-07-29T16:54:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![heck0045](https://avatars.discourse-cdn.com/v4/letter/h/e274bd/32.png) [@heck0045](https://forum.opensearch.org/u/heck0045)\
**Post date:** [July 29, 2021, 4:54pm UTC](https://forum.opensearch.org/t/how-to-disable-ssl-locally/6656/1 "2021-07-29T16:54:52Z")

</div>

Hey all - I have a single test instance of opensearch running locally via this docker command:

`docker run -d --name os1 -p 9200:9200 -p 9300:9300 -e "plugins.security.disabled: true" -e "opendistro_security.ssl.http.enabled: false" -e "discovery.type=single-node" -e "script.painless.regex.enabled=true" opensearchproject/opensearch:1.0.0`

I am not able to get the regular response running `curl localhost:9200` - it is always throwing this exception:

`io.netty.handler.codec.DecoderException: io.netty.handler.ssl.NotSslRecordException: not an SSL/TLS record`

I thought I disabled what I needed in the docker run command (`opendistro_security.ssl.http.enabled: false` and `plugins.security.disabled: true`), but perhaps not?

Would love any tips. Thanks!  
Tim

---

<div class="post-metadata">

**Author:** ![heck0045](https://avatars.discourse-cdn.com/v4/letter/h/e274bd/32.png) [@heck0045](https://forum.opensearch.org/u/heck0045)\
**Post date:** [July 29, 2021, 5:54pm UTC](https://forum.opensearch.org/t/how-to-disable-ssl-locally/6656/2 "2021-07-29T17:54:47Z")

</div>

FWIW, passing these params via `docker run` didn’t work - I had to ssh into the docker container using `docker exec -it <container-id> /bin/bash` and then modified the `/usr/share/opensearch/config/opensearch.yml` file – I just replaced all the demo security config settings in there with a single line `plugins.security.disabled: true`

Stopping and starting the container with the same command then caused the `curl localhost:9200` to come back without the SSL exception.

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [July 30, 2021, 12:17pm UTC](https://forum.opensearch.org/t/how-to-disable-ssl-locally/6656/3 "2021-07-30T12:17:10Z")

</div>

@heck0045

Alternatively, you could attach opensearch.yml file with desired settings to your `docker run` and avoid doing it manually inside the docker.

---

<div class="post-metadata">

**Author:** ![cyberwombat](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/cyberwombat/32/4183_2.png) [@cyberwombat](https://forum.opensearch.org/u/cyberwombat)\
**Post date:** [September 4, 2022, 11:26pm UTC](https://forum.opensearch.org/t/how-to-disable-ssl-locally/6656/4 "2022-09-04T23:26:34Z")

</div>

Do you have a sample for this? I am trying to disable security using just the run command as well.

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [September 5, 2022, 10:17am UTC](https://forum.opensearch.org/t/how-to-disable-ssl-locally/6656/5 "2022-09-05T10:17:42Z")

</div>

@cyberwombat Could you open a new thread and describe how you deploy your cluster?  
Do you want to disable the security plugin or SSL connection to the cluster?

---

<div class="post-metadata">

**Author:** ![cyberwombat](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/cyberwombat/32/4183_2.png) [@cyberwombat](https://forum.opensearch.org/u/cyberwombat)\
**Post date:** [September 5, 2022, 3:38pm UTC](https://forum.opensearch.org/t/how-to-disable-ssl-locally/6656/6 "2022-09-05T15:38:06Z")

</div>

@pablo [How do disable SSL/security using a single line npm script on start](https://forum.opensearch.org/t/how-do-disable-ssl-security-using-a-single-line-npm-script-on-start/10829)

---

<div class="post-metadata">

**Author:** ![multikoop](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/multikoop/32/4939_2.png) [@multikoop](https://forum.opensearch.org/u/multikoop)\
**Post date:** [February 23, 2023, 11:59am UTC](https://forum.opensearch.org/t/how-to-disable-ssl-locally/6656/7 "2023-02-23T11:59:10Z")

</div>

For me the correct setting of the env var worked to turn off ssl and security. No need to ssh into the container etc…

```auto
-e "plugins.security.disabled=true"

```
