# Automation adding the password for basic security step #2 in Elasticsearch 7

**URL:** <https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335>\
**Category:** Elastic Security\
**Created:** [May 12, 2023, 7:03pm UTC](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335 "2023-05-12T19:03:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chuck\_Reynolds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chuck_reynolds/32/103607_2.png) [@Chuck\_Reynolds](https://discuss.elastic.co/u/Chuck_Reynolds)\
**Post date:** [May 12, 2023, 7:03pm UTC](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335/1 "2023-05-12T19:03:48Z")

</div>

How can I automate step 2 and pass a password to the following 2 commands?

./bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure\_password.

./bin/elasticsearch-keystore add xpack.security.transport.ssl.truststore.secure\_password

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 12, 2023, 7:12pm UTC](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335/2 "2023-05-12T19:12:37Z")

</div>

Hi @Chuck_Reynolds  
Did you look at [this](https://www.elastic.co/guide/en/elasticsearch/reference/current/elasticsearch-keystore.html#add-string-to-keystore)?

> To pass the settings values through standard input (stdin), use the `--stdin` flag:
> 
> `cat /file/containing/setting/value | bin/elasticsearch-keystore add --stdin the.setting.name.to.set`
> 
> Values for multiple settings must be separated by carriage returns or newlines.

---

<div class="post-metadata">

**Author:** ![Chuck\_Reynolds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chuck_reynolds/32/103607_2.png) [@Chuck\_Reynolds](https://discuss.elastic.co/u/Chuck_Reynolds)\
**Post date:** [May 12, 2023, 7:20pm UTC](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335/3 "2023-05-12T19:20:26Z")

</div>

I didn't but it doesn't really make sense to me.

Step 2 says:

If you entered a password when creating the node certificate, run the following commands to store the password in the Elasticsearch keystore:

then it tells you to enter the following command which prompts you for a password.

I would expect to run the command like this.

./bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure\_password password:password123

but that doesn't work.

I need to use ansible to automate this part of the basic security so I need to have away to pass the password with the command.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 12, 2023, 7:30pm UTC](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335/4 "2023-05-12T19:30:25Z")

</div>

`echo` or write the password into a file then `cat` via `stdin` as shown... that is your only option at the moment...

---

<div class="post-metadata">

**Author:** ![Chuck\_Reynolds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chuck_reynolds/32/103607_2.png) [@Chuck\_Reynolds](https://discuss.elastic.co/u/Chuck_Reynolds)\
**Post date:** [May 12, 2023, 7:51pm UTC](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335/5 "2023-05-12T19:51:15Z")

</div>

When you say  
the.setting.name.to.set

What is the setting name?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 12, 2023, 8:05pm UTC](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335/6 "2023-05-12T20:05:31Z")

</div>

in your example

```auto
echo -e "thepassword" > pw.txt
cat ./pw.txt | bin/elasticsearch-keystore add --stdin xpack.security.transport.ssl.keystore.secure_password

```

That should work I just tested it, that is `bash`... whatever is the equivalent in ansible

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2023, 8:05pm UTC](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335/7 "2023-06-09T20:05:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
