# Credentials for elastic-operator

**URL:** <https://discuss.elastic.co/t/credentials-for-elastic-operator/212628>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** elastic-stack-security\
**Created:** [December 20, 2019, 8:39am UTC](https://discuss.elastic.co/t/credentials-for-elastic-operator/212628 "2019-12-20T08:39:25Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![charith-elastic](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@charith-elastic](https://discuss.elastic.co/u/charith-elastic)\
**Post date:** [December 20, 2019, 4:19pm UTC](https://discuss.elastic.co/t/credentials-for-elastic-operator/212628/4 "2019-12-20T16:19:29Z")

</div>

If I understand correctly, this plugin disables xpack security and takes over the user management of Elasticsearch? If that's the case, I think you might have to re-create the operator accounts using the plugin and give them exactly the same passwords as the operator generated passwords stored in `[cluster]-es-elastic-user` and `[cluster]-es-internal-users` secrets. Please note that this is not something we recommend you do in production and the behaviour could change without notice in the future.

I will raise an issue to discuss the possibility of allowing user-defined credentials in a future release.

---

_[View the full topic](https://discuss.elastic.co/t/credentials-for-elastic-operator/212628)._
