# Beats issue with keystore and Nginx basic auth

**URL:** <https://discuss.elastic.co/t/beats-issue-with-keystore-and-nginx-basic-auth/174774>\
**Category:** Beats\
**Created:** [April 1, 2019, 11:51am UTC](https://discuss.elastic.co/t/beats-issue-with-keystore-and-nginx-basic-auth/174774 "2019-04-01T11:51:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bigor44](https://avatars.discourse-cdn.com/v4/letter/b/bbce88/32.png) [@bigor44](https://discuss.elastic.co/u/bigor44)\
**Post date:** [April 1, 2019, 11:51am UTC](https://discuss.elastic.co/t/beats-issue-with-keystore-and-nginx-basic-auth/174774/1 "2019-04-01T11:51:10Z")

</div>

Hi,

I have an issue since cluster and beats has bee updated to 6.7  
i have a Nginx front-end that handle basic-auth to access ES.

Steps done:  
Old keystore seems to not be recognized since update. ( filebeat keystore list reply nothing )  
When password is in filebeat.yml (in clear), there is no issue.  
When recreating keystore, Nginx replay with an Error 401.  
Same error on filebeat and metricbeat

filebeat config:

```
filebeat.config:
  inputs:
    enabled: true
    path: /etc/filebeat/inputs.d/*.yml
    reload.enabled: true
    reload.period: 30s
  modules:
    enabled: true
    path: /etc/filebeat/modules.d/*.yml
    reload.enabled: true
    reload.period: 30s

processors:
- add_locale:
    format: abbreviation
- add_cloud_metadata: ~
- add_host_metadata: ~

output.elasticsearch:
  hosts: ["https://ip:port"]
  ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]
  username: "beats"
  password: "$(ES_PWD)"

setup.template.settings:
  index.number_of_shards: 1
  index.number_of_replicas: 0

setup.kibana:
  host: "ip:port"
  protocol: "https"
  ssl.enabled: true
  ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]
  username: kibana
  password: "${KI_PWD}"
```

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [April 1, 2019, 12:22pm UTC](https://discuss.elastic.co/t/beats-issue-with-keystore-and-nginx-basic-auth/174774/2 "2019-04-01T12:22:49Z")

</div>

This is indead a bug in 6.7.0 a fix will be included in 6.7.1, but in the meantime you can use the following workaround. [https://github.com/elastic/beats/issues/11493#issuecomment-477394760](https://github.com/elastic/beats/issues/11493#issuecomment-477394760)

---

<div class="post-metadata">

**Author:** ![bigor44](https://avatars.discourse-cdn.com/v4/letter/b/bbce88/32.png) [@bigor44](https://discuss.elastic.co/u/bigor44)\
**Post date:** [April 1, 2019, 12:39pm UTC](https://discuss.elastic.co/t/beats-issue-with-keystore-and-nginx-basic-auth/174774/3 "2019-04-01T12:39:01Z")

</div>

Thanks for your quick answer, i tried this already and i keep issuing the same error  
i just did a new try  
filebeat test output:

```
elasticsearch: https://ip:port...
  parse url... OK
  connection...
    parse host... OK
    dns lookup... OK
    addresses: ip
    dial up... OK
  TLS...
    security: server's certificate chain verification is enabled
    handshake... OK
    TLS version: TLSv1.2
    dial up... OK
  talk to server... ERROR 401 Unauthorized: <html>
<head><title>401 Authorization Required</title></head>
<body bgcolor="white">
<center><h1>401 Authorization Required</h1></center>
<hr><center>nginx/1.12.2</center>
</body>
</html>
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2019, 2:39pm UTC](https://discuss.elastic.co/t/beats-issue-with-keystore-and-nginx-basic-auth/174774/4 "2019-04-29T14:39:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
