# Account authentication settings must use the keystore

**URL:** <https://discuss.elastic.co/t/account-authentication-settings-must-use-the-keystore/189549>\
**Category:** Elasticsearch\
**Created:** [July 9, 2019, 12:41pm UTC](https://discuss.elastic.co/t/account-authentication-settings-must-use-the-keystore/189549 "2019-07-09T12:41:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![swapnali](https://avatars.discourse-cdn.com/v4/letter/s/b5a626/32.png) [@swapnali](https://discuss.elastic.co/u/swapnali)\
**Post date:** [July 9, 2019, 12:41pm UTC](https://discuss.elastic.co/t/account-authentication-settings-must-use-the-keystore/189549/1 "2019-07-09T12:41:17Z")

</div>

Hi,

I Am trying to update my elasticsearch 6.7.1 to 7.0 assistant suggest me to change  
**account authentication settings must use the keystore**  
From document i got to know i need to do changes as below mentioned

- ` **xpack.notification.email.account.<id>.smtp.password** ` , instead use ` **xpack.notification.email.account.<id>.smtp.secure_password** `

But What is the meaning of "id" how i will achieve below mentioned  
**Watcher notification accounts' authentication settings must be defined securely**

thanks

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [July 9, 2019, 10:04pm UTC](https://discuss.elastic.co/t/account-authentication-settings-must-use-the-keystore/189549/2 "2019-07-09T22:04:50Z")

</div>

The `<id>` here is the id/name of the account. You can configure multiple email accounts, each with a different id. For example, taking an example configuration from [the docs](https://www.elastic.co/guide/en/elastic-stack-overview/current/actions-email.html#configuring-email):

```auto
xpack.notification.email.account:
    gmail_account:
        profile: gmail
        smtp:
            auth: true
            starttls.enable: true
            host: smtp.gmail.com
            port: 587
            user: <username>

```

In the above case, the id of the account would be `gmail_account`. This id is fairly arbitrary and can be whatever you like, but it must be the same between the settings in `elasticsearch.yml` and the settings in the keystore.

---

<div class="post-metadata">

**Author:** ![swapnali](https://avatars.discourse-cdn.com/v4/letter/s/b5a626/32.png) [@swapnali](https://discuss.elastic.co/u/swapnali)\
**Post date:** [July 10, 2019, 5:37am UTC](https://discuss.elastic.co/t/account-authentication-settings-must-use-the-keystore/189549/3 "2019-07-10T05:37:28Z")

</div>

thank you

---

<div class="post-metadata">

**Author:** ![swapnali](https://avatars.discourse-cdn.com/v4/letter/s/b5a626/32.png) [@swapnali](https://discuss.elastic.co/u/swapnali)\
**Post date:** [July 10, 2019, 9:18am UTC](https://discuss.elastic.co/t/account-authentication-settings-must-use-the-keystore/189549/4 "2019-07-10T09:18:20Z")

</div>

Hi,

As per your suggestion i did following steps

Go to /usr/share/elasticsearch and run below command to add email account in ket store of elasticsearch

**bin/elasticsearch-keystore add xpack.notification.email.account.exchange\_account.smtp.secure\_password**  
Here I put as exchange account because in my elasticsearch.yml I have congifure exchange account

In elasticsearch.yml

xpack.notification.email.account:  
exchange\_account:  
profile: outlook  
#email\_defaults:  
# from: xxx.co.in  
smtp:  
auth: true  
starttls.enable: true  
host: devmail  
port: 25  
user:x@x.co.in  
password: "xxxx"

I have no error in elasticsearch log but still it shows in assistant 7.0 that **:Watcher notification accounts' authentication settings must be defined securely**

---

<div class="post-metadata">

**Author:** ![gbrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gbrown/32/34482_2.png) [@gbrown](https://discuss.elastic.co/u/gbrown)\
**Post date:** [July 10, 2019, 6:52pm UTC](https://discuss.elastic.co/t/account-authentication-settings-must-use-the-keystore/189549/5 "2019-07-10T18:52:27Z")

</div>

That warning is telling you that you still have authentication information (in this case, the password) in your `elasticsearch.yml` (even if you also have it in the keystore). You'll need to remove the password from the `elasticsearch.yml` in order to get rid of that warning, because Elasticsearch 7.x will refuse to start if it's still there when you upgrade. The warning should be a little clearer about that part of it.

---

<div class="post-metadata">

**Author:** ![swapnali](https://avatars.discourse-cdn.com/v4/letter/s/b5a626/32.png) [@swapnali](https://discuss.elastic.co/u/swapnali)\
**Post date:** [July 11, 2019, 6:14am UTC](https://discuss.elastic.co/t/account-authentication-settings-must-use-the-keystore/189549/6 "2019-07-11T06:14:44Z")

</div>

Thanks its work!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2019, 6:25am UTC](https://discuss.elastic.co/t/account-authentication-settings-must-use-the-keystore/189549/7 "2019-08-08T06:25:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
