# Elastic authentication error

**URL:** <https://discuss.elastic.co/t/elastic-authentication-error/292830>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 23, 2021, 4:11pm UTC](https://discuss.elastic.co/t/elastic-authentication-error/292830 "2021-12-23T16:11:37Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Atul\_Chadha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/atul_chadha/32/75469_2.png) [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Post date:** [December 23, 2021, 4:11pm UTC](https://discuss.elastic.co/t/elastic-authentication-error/292830/1 "2021-12-23T16:11:37Z")

</div>

We are trying to remove Readonly Rest from authentication equation and setup x-pack on ( ES 7.15 )

```auto
[2021-12-23T11:08:27,433][INFO][o.e.x.s.a.AuthenticationService] [XXXX] Authentication of [elastic] was terminated by realm [reserved] - failed to authenticate user [elastic]

[2021-12-23T11:08:27,434][DEBUG][o.e.x.s.r.SecurityRestFilter] [XXXX] Authentication failed for REST request [/]

org.elasticsearch.ElasticsearchSecurityException: unable to authenticate user [elastic] for REST request [/]

```

I have setup the password using `/usr/share/elasticsearch/bin/elasticsearch-setup-passwords interactive` and post that i am seeing the above logs.

I have tried setting up the password from the API however no luck. How can i setup xpack with minimal settings.

---

<div class="post-metadata">

**Author:** ![Atul\_Chadha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/atul_chadha/32/75469_2.png) [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Post date:** [December 25, 2021, 8:18am UTC](https://discuss.elastic.co/t/elastic-authentication-error/292830/2 "2021-12-25T08:18:02Z")

</div>

Checking if anyone has thoughts on this one ?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [December 25, 2021, 9:32am UTC](https://discuss.elastic.co/t/elastic-authentication-error/292830/3 "2021-12-25T09:32:14Z")

</div>

Though I'm not sure what " remove Readonly Rest from authentication equation" really means, the log looks only showing the username ('elastic') and password does not match.  
As the Elasticsearch-setup-passwords uses [`elastic` bootstrap password](https://www.elastic.co/guide/en/elasticsearch/reference/current/built-in-users.html#bootstrap-elastic-passwords), it could not be used after the bootstrap password are changed.

---

<div class="post-metadata">

**Author:** ![Atul\_Chadha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/atul_chadha/32/75469_2.png) [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Post date:** [December 25, 2021, 11:38am UTC](https://discuss.elastic.co/t/elastic-authentication-error/292830/4 "2021-12-25T11:38:10Z")

</div>

Hey @Tomo_M i am trying to use elasticstack by using natively supported authentication ( xpack ) rather than added plugin ( Readonly Rest from Beshu )

I have redone the config in the meantime and i am getting a differnt error in kibana log now, i have already added the `elasticsearch.password` into kibana keystore and have `elasticsearch.username` in my kibana.yml

```auto
{"type":"log","@timestamp":"2021-12-25T06:34:04-05:00","tags":["error","savedobjects-service"],"pid":19145,"message":"Unable to retrieve version information from Elasticsearch nodes. security_

`exception: [security_exception] Reason: missing authentication credentials for REST request [/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip]"}`

```

Not sure what credentials its referring to now

Here are logs from Elasticsearch

```auto
[2021-12-25T06:39:31,940][DEBUG][r.suppressed] [XXXXXX] path: /_nodes, params: {filter_path=nodes.*.version,nodes.*.http.publish_address,nodes.*.ip}
org.elasticsearch.ElasticsearchSecurityException: missing authentication credentials for REST request [/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip]
        at org.elasticsearch.xpack.core.security.support.Exceptions.authenticationError(Exceptions.java:19) ~[x-pack-core-7.15.2.jar:7.15.2]
        at org.elasticsearch.xpack.core.security.authc.DefaultAuthenticationFailureHandler.createAuthenticationError(DefaultAuthenticationFailureHandler.java:164) ~[x-pack-core-7.15.2.jar:7.15.2]

```

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [December 25, 2021, 1:50pm UTC](https://discuss.elastic.co/t/elastic-authentication-error/292830/5 "2021-12-25T13:50:04Z")

</div>

Sorry I don't understand your prerequisites. In the first place, ELK works on its own. How does the plugin relate to your cluster?  
If you want to remove and revert the once installed plugin, ask to the plugin developer will solve the problem sooner.

Anyway, can you access root elasticsearch url and log in to it? If you can and you know the password of user "elastic" (or any other user with appropriate role), you can use "change passwords API" and "create users API".  
I found command line [elasticsearch-reset-password](https://www.elastic.co/guide/en/elasticsearch/reference/8.0/reset-password.html) tool for 8.0, but it is not supported in 7.15.

And I suppose this topic will also help you.

> [@X-Pack Authentication issue](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/7):
>
> This is a revised version of [this post](https://discuss.elastic.co/t/i-lost-the-password-that-has-been-changed/91867/2) Help! I don't have the password for the elastic user! Pre-reading: The password setup in Elasticsearch 6.x depends on a "bootstrap password" that is set on each node in your cluster. This password is documented here: [https://www.elastic.co/guide/en/x-pack/6.2/setting-up-authentication.html#bootstrap-elastic-passwords](https://www.elastic.co/guide/en/x-pack/6.2/setting-up-authentication.html#bootstrap-elastic-passwords) If you do not have a fixed password for the elastic user, then it uses the bootstrap password. X-Pack security includes an API to chan…

I hope some of them work for you.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 25, 2021, 2:59pm UTC](https://discuss.elastic.co/t/elastic-authentication-error/292830/6 "2021-12-25T14:59:59Z")

</div>

Hi @Tomo_M

First I would highly recommend following the docs very carefully step by step [Configuring Security](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/configuring-stack-security.html)

And specifically [this section](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/security-minimal-setup.html) since you are working on authentication

Once you have followed those steps you should validate you can connect to Elasticsearch with the credentials from one of you Elasticsearch nodes.

`curl -u "elastic:yourpassword" http://localhost:9200`

After that you can work connecting Kibana, the steps for that are right there as well.

---

<div class="post-metadata">

**Author:** ![Atul\_Chadha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/atul_chadha/32/75469_2.png) [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Post date:** [December 25, 2021, 3:16pm UTC](https://discuss.elastic.co/t/elastic-authentication-error/292830/7 "2021-12-25T15:16:31Z")

</div>

I think something is messed up on my VM, i have created a fresh machine and it seems to be working better. I am doing some tests to confirm.

This question can be ignored for the time being.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 22, 2022, 3:16pm UTC](https://discuss.elastic.co/t/elastic-authentication-error/292830/8 "2022-01-22T15:16:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
