# Automate Elasticsearch-reset-password in bash script

**URL:** <https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 25, 2022, 4:58pm UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429 "2022-10-25T16:58:17Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 25, 2022, 4:58pm UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/1 "2022-10-25T16:58:17Z")

</div>

I am running the latest elasticsearch version via a script, and I am trying to automate the reset password process via this method recommended @TimV back in 2018, but it seems to no longer work with the latest version: [How to set passwords for built-in users in batch mode?](https://discuss.elastic.co/t/how-to-set-passwords-for-built-in-users-in-batch-mode/119655/6).

This is what the script looks like: I am trying to change the password to `elk-demo`. I want to disable any form of user interaction and completely automate the whole process:

```auto
cd /usr/share/elasticsearch/bin
 printf "elk-demo" | elasticsearch-keystore add -x
sudo curl -uelastic -XPUT -H 'Content-Type: application/json' 'http://localhost:9200/_xpack/security/user/kibana/_password' -d '{ "password":new-kibana-password" }'

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2022, 1:08am UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/2 "2022-10-26T01:08:51Z")

</div>

> [@Chma](#):
>
> but it seems to no longer work with the latest version

Can you elaborate a little more on what's happening, the output from your script, including the response from Elasticsearch would be ideal.

---

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 26, 2022, 2:05am UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/3 "2022-10-26T02:05:12Z")

</div>

I am automating the installation and configuration of elasticsearch and kibana. Following the post from 2018 - [How to set passwords for built-in users in batch mode?](https://discuss.elastic.co/t/how-to-set-passwords-for-built-in-users-in-batch-mode/119655/6) - I should be able to automate ` elasticsearch-reset-password` by running the following commands:

```auto
cd /usr/share/elasticsearch/bin
 printf "elk-demo" | elasticsearch-keystore add -x
sudo curl -uelastic -XPUT -H 'Content-Type: application/json' 'http://localhost:9200/_xpack/security/user/kibana/_password' -d '{ "password":new-kibana-password" }'

```

but when I did this, I got the message:  
`elasticsearch-keystore: command not found`

I also tried:  
`sudo printf "elk-demo" | bin/elasticsearch-reset-password -i -b`  
but I got the error:

```auto
Enter password for [elastic]: Re-enter password for [elastic]: 
ERROR: unable to read from standard input; is standard input open and a tty attached?

```

What i am trying to achieve is reset the password through a script without any user interaction or request to type in password or re-enter password. There are no helpful elasticsearch logs. Just long list of warnings saying:

```auto
received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=

```

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 26, 2022, 2:14am UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/4 "2022-10-26T02:14:11Z")

</div>

> [@Chma](#):
>
> `printf "elk-demo" | elasticsearch-keystore add -x`

I don't how this command could ever work. It should be something like

```auto
printf "elk-demo" | elasticsearch-keystore add "bootstrap.password" -x

```

For this error message `elasticsearch-keystore: command not found`. You might want to try:

```auto
cd /usr/share/elasticsearch
printf "elk-demo" | ./bin/elasticsearch-keystore add "bootstrap.password" -x

```

---

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 26, 2022, 2:33am UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/5 "2022-10-26T02:33:29Z")

</div>

This worked, thanks. But when i test that my elasticsearch is running, I get authentication error.

`sudo curl --cacert /etc/elasticsearch/certs/http_ca.crt -u elastic https://localhost:9200`  
When I am asked to `Enter host password for user 'elastic':` I enter the `elk-demo` password, but I get the below error message:

```auto
{"error":{"root_cause":[{"type":"security_exception","reason":"unable to authenticate user [elastic] for REST request [/]","header":{"WWW-Authenticate":["Basic realm=\"security\" charset=\"UTF-8\"","Bearer realm=\"security\"","ApiKey"]}}],"type":"security_exception","reason":"unable to authenticate user [elastic] for REST request [/]","header":{"WWW-Authenticate":["Basic realm=\"security\" charset=\"UTF-8\"","Bearer realm=\"security\"","ApiKey"]}},"status":401}root@ip-10-0-15-147:/usr/share/elasticsearch# 

```

Perhaps, I am missing something?

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 26, 2022, 2:56am UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/6 "2022-10-26T02:56:08Z")

</div>

It likely means that you have already reset the password via API, which takes precedence over the bootstrap.password.

In that case you can use `elasticsearch-reset-password` with something like

```auto
cd /usr/share/elasticsearch
printf "elk-demo\nelk-demo" | ./bin/elasticsearch-reset-password -b -i -u elastic

```

---

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 26, 2022, 5:27am UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/7 "2022-10-26T05:27:23Z")

</div>

Thanks! This worked.

---

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 26, 2022, 11:00pm UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/8 "2022-10-26T23:00:39Z")

</div>

@Yang_Wang is there a way to run  
`printf "elk-demo\nelk-demo" | ./bin/elasticsearch-reset-password -b -i -u elastic` without having to run `sudo -i` first?

I tried `sudo printf "elk-demo\nelk-demo" | ./bin/elasticsearch-reset-password -b -i -u elastic` but I got:

```auto
./bin/elasticsearch-env: line 86: cd: /etc/elasticsearch: Permission denied

ERROR: File realm configuration file [/usr/share/elasticsearch/users] is missing , File realm configuration file [/usr/share/elasticsearch/users_roles] is missing

```

It only works when I run `sudo -i` first.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 26, 2022, 11:48pm UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/9 "2022-10-26T23:48:42Z")

</div>

You should not need `sudo` to run these command. The relevant files and directories should be accessible (readable or writable or both depending on the files) by the `elasticsearch` user. You should fix the permissions instead of tryint to rely on `sudo`.

---

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 26, 2022, 11:56pm UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/10 "2022-10-26T23:56:58Z")

</div>

How can I fix the permissions? My logstash and kibana are failing to start and I can't view the logs because `permission is denied`.

```auto
**logstash.service: Failed to execute /usr/share/logstash/bin/logstash: Permission denied**

q systemd[20199]: **logstash.service: Failed at step EXEC spawning /usr/share/logstash/bin/logstash: Permission denied**

****kibana.service: Changing to the requested working directory failed: Permission denied****

**systemd[19671]:**kibana.service: Failed at step CHDIR spawning /usr/share/kibana/bin/kibana: Permission denied ****

```

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 27, 2022, 12:20am UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/11 "2022-10-27T00:20:45Z")

</div>

One way to fix file permissions is to use `chown` command:

```auto
sudo chown elasticsearch: YOUR_FILE

```

or

```auto
sudo chown -R elasticsearch: YOUR_DIRECTORY

```

Please note these issues are out scope of Elastic stack. You might also want to consult with your local Linux experts.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2022, 12:20am UTC](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/12 "2022-11-24T00:20:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
