# Configuration issue: "xpack.security.enrollment.enabled must be set to true"

**URL:** <https://discuss.elastic.co/t/configuration-issue-xpack-security-enrollment-enabled-must-be-set-to-true/310626>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [July 26, 2022, 10:42am UTC](https://discuss.elastic.co/t/configuration-issue-xpack-security-enrollment-enabled-must-be-set-to-true/310626 "2022-07-26T10:42:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![najmiehsa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/najmiehsa/32/105130_2.png) [@najmiehsa](https://discuss.elastic.co/u/najmiehsa)\
**Post date:** [July 26, 2022, 10:42am UTC](https://discuss.elastic.co/t/configuration-issue-xpack-security-enrollment-enabled-must-be-set-to-true/310626/1 "2022-07-26T10:42:40Z")

</div>

Hi,  
I wanted to install the commercial version of kibana, but I was initially given only one enrollment token when I started using Docker for building purposes.

Now I want to generate a new enrollment token via the enrollment generator tool in the bin directory of the Elasticsearch, but every single time I use the tool I encounter this error:

 ![1](https://us1.discourse-cdn.com/elastic/original/3X/2/6/266d70c674b0ec44cc88ebbf59876f1042a566f7.jpeg)

I tried to add **xpack.security.enrollment.enabled: true** to the **Elasticsearch yml** file but I got the same exact error as above.

Any suggestions on how to solve this issue?

The other issue I am facing is when I want to use kibana for building purposes on Docker, I get the error message " **could not fetch**" after I insert both the enrollment token and the verification key.

The second problem also needs some help.

I also understand that this service is blocked in my region. I just need clarification because my installation process has been difficult.

Thank you.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [July 26, 2022, 11:37am UTC](https://discuss.elastic.co/t/configuration-issue-xpack-security-enrollment-enabled-must-be-set-to-true/310626/2 "2022-07-26T11:37:33Z")

</div>

> [@najmiehsa](#):
>
> Now I want to generate a new enrollment token via the enrollment generator tool in the bin directory of the Elasticsearch, but every single time I use the tool I encounter this error:

How _exactly_ do you run the `elasticsearch-create-enrollment-token` tool ? Is your elasticsearch node running in Docker too ? How do you spin the container up and how have you configured it ?

---

<div class="post-metadata">

**Author:** ![najmiehsa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/najmiehsa/32/105130_2.png) [@najmiehsa](https://discuss.elastic.co/u/najmiehsa)\
**Post date:** [July 26, 2022, 12:15pm UTC](https://discuss.elastic.co/t/configuration-issue-xpack-security-enrollment-enabled-must-be-set-to-true/310626/3 "2022-07-26T12:15:21Z")

</div>

For this issue here:

> Now I want to generate a new enrollment token via the enrollment generator tool in the bin directory of the Elasticsearch, but every single time I use the tool I encounter this error:

I used CMD and not Docker terminal. I downloaded the latest version from here [Download Kibana Free | Get Started Now | Elastic](https://www.elastic.co/downloads/kibana) and run **.\bin\kibana.bat** in the root directory in cmd to install kibana.

To generate the enrollment token I used the **bin\elasticsearch-create-enrollment-token.bat --scope kibana** (This is the windows version of the command which I run in cmd) in the root directory of elastic and I encountered this error:

 ![1](https://us1.discourse-cdn.com/elastic/original/3X/2/6/266d70c674b0ec44cc88ebbf59876f1042a566f7.jpeg)

I added the **xpack.security.enrollment.enabled: true** to the **Elasticsearch yml** file and had the same error as above.

For Docker, I pulled both images and run the kibana and Elasticsearch containers.

I used ES Docker terminal to generate the enrollment token (I used **bin/elasticsearch-create-enrollment-token -s kibana** ) and Kibana terminal to get the verification keys (for that I used **bin/kibana-verification-code** ).

for the enrollment token generator tool, I changed to the bin directory of ES and typed the name of the tool.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2022, 12:15pm UTC](https://discuss.elastic.co/t/configuration-issue-xpack-security-enrollment-enabled-must-be-set-to-true/310626/4 "2022-08-23T12:15:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
