# Can't setup password for Elasticsearch cluster with multiple master nodes

**URL:** <https://discuss.elastic.co/t/cant-setup-password-for-elasticsearch-cluster-with-multiple-master-nodes/199686>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 16, 2019, 3:04pm UTC](https://discuss.elastic.co/t/cant-setup-password-for-elasticsearch-cluster-with-multiple-master-nodes/199686 "2019-09-16T15:04:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![avinash9999](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/avinash9999/32/91409_2.png) [@avinash9999](https://discuss.elastic.co/u/avinash9999)\
**Post date:** [September 16, 2019, 3:04pm UTC](https://discuss.elastic.co/t/cant-setup-password-for-elasticsearch-cluster-with-multiple-master-nodes/199686/1 "2019-09-16T15:04:36Z")

</div>

**Not able to setup password for Elasticsearch cluster with 3 (master + data) nodes.**

`I took advice from various post of many Elasticsearch Engineers to create cluster with 3 minimum nodes so I have create my cluster with 3 nodes with these configuration --`

**node 1**

> cluster.name: elasticsearch  
> node.name: server1  
> node.master: true  
> node.data: true  
> discovery.zen.ping.unicast.hosts: ["ip\_of\_server1","ip\_of\_server2","ip\_of\_server3"]  
> network.host: ip\_of\_server1  
> discovery.zen.minimum\_master\_nodes: 2

**node 2**

> cluster.name: elasticsearch  
> node.name: server2  
> node.master: true  
> node.data: true  
> discovery.zen.ping.unicast.hosts: ["ip\_of\_server1","ip\_of\_server2","ip\_of\_server3"]  
> network.host: ip\_of\_server1  
> discovery.zen.minimum\_master\_nodes: 2

**node 3**

> cluster.name: elasticsearch  
> node.name: server3  
> node.master: true  
> node.data: true  
> discovery.zen.ping.unicast.hosts: ["ip\_of\_server1","ip\_of\_server2","ip\_of\_server3"]  
> network.host: ip\_of\_server1  
> discovery.zen.minimum\_master\_nodes: 2

**I have created certificates on all server--**

> bin/elasticsearch-certutil cert -out config/elastic-certificates.p12 -pass ""

**I have also added these configuration on all 3 nodes yml--**

> xpack.security.enabled: true  
> xpack.security.transport.ssl.enabled: true  
> xpack.security.transport.ssl.verification\_mode: certificate  
> xpack.security.transport.ssl.keystore.path: elastic-certificates.p12  
> xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

**After all of these I am using this command --**

> bin/elasticsearch-setup-passwords auto --verbose

**But getting the following error --**

> Trying user password change call http://\*\*\*\*\*\*\*\*:9200/\_security/user/apm\_system/\_password?pretty  
> {  
> "error" : {  
> "root\_cause" : [  
> {  
> "type" : "status\_exception",  
> "reason" : "Cluster state has not been recovered yet, cannot write to the [null] index"  
> }  
> ],  
> "type" : "status\_exception",  
> "reason" : "Cluster state has not been recovered yet, cannot write to the [null] index"  
> },  
> "status" : 503  
> }
> 
> Unexpected response code [503] from calling PUT http://\*\*\*\*\*\*\*\*\*:9200/\_security/user/apm\_system/\_password?pretty  
> Cause: Cluster state has not been recovered yet, cannot write to the [null] index

**Plese help, Thanks in advance!!**

\*\*Apart from Setting password my cluster is working fine handling failover

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 24, 2019, 9:22pm UTC](https://discuss.elastic.co/t/cant-setup-password-for-elasticsearch-cluster-with-multiple-master-nodes/199686/2 "2019-09-24T21:22:08Z")

</div>

what is the output of this

curl -XGET hostname:9200/\_cluster/health?pretty

curl -XGET -u username hostname:9200/\_cluster/health?pretty

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 25, 2019, 3:23am UTC](https://discuss.elastic.co/t/cant-setup-password-for-elasticsearch-cluster-with-multiple-master-nodes/199686/3 "2019-09-25T03:23:00Z")

</div>

> [@avinash9999](#):
>
> **I have created certificates on all server--**
> 
> > bin/elasticsearch-certutil cert -out config/elastic-certificates.p12 -pass ""

This is where you have made a mistake.  
If you generate a separate certificate like this on each server, then there is no relationship between those certificates and they nodes will not trust one another.

You need to generate a single CA for your cluster first, and then use that to generate certificates that are all issued by that one CA.  
See [Configure TLS | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-tls.html#node-certificates)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2019, 3:23am UTC](https://discuss.elastic.co/t/cant-setup-password-for-elasticsearch-cluster-with-multiple-master-nodes/199686/4 "2019-10-23T03:23:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
