# Elastic Cloud Keystore

**URL:** <https://discuss.elastic.co/t/elastic-cloud-keystore/192187>\
**Category:** Beats\
**Tags:** elastic-stack-security\
**Created:** [July 25, 2019, 7:15am UTC](https://discuss.elastic.co/t/elastic-cloud-keystore/192187 "2019-07-25T07:15:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajhstn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajhstn/32/24629_2.png) [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Post date:** [July 25, 2019, 7:15am UTC](https://discuss.elastic.co/t/elastic-cloud-keystore/192187/1 "2019-07-25T07:15:33Z")

</div>

In Elastic cloud i have configured a Keystore setting named `ES_PWD`, its a single string containing a value of `elastic:myelasticpassword`.

I tried to use this in my beat configuration, `cloud.auth: ${ES_PWD}` but when i test the output config it fails, eg: `winlogbeat.exe test output` results in `talk to server... ERROR 401 Unauthorized:`

Am i doing something wrong?

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [July 29, 2019, 3:15pm UTC](https://discuss.elastic.co/t/elastic-cloud-keystore/192187/2 "2019-07-29T15:15:23Z")

</div>

The keystore is just an alternative way of storing sensitive parameters that used to live in the YAML, with all the same restrictions

It doesn't provide any generic key-value storage capabilities (and even if it did, it wouldn't provide them to external services like beats)

I believe you have to store the cloud login details somewhere accessible to beats - it might be worth asking in the beats forum for best practices if you're worried about leaving creds lying around in plaintext?

---

<div class="post-metadata">

**Author:** ![ajhstn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajhstn/32/24629_2.png) [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Post date:** [August 9, 2019, 3:21am UTC](https://discuss.elastic.co/t/elastic-cloud-keystore/192187/3 "2019-08-09T03:21:06Z")

</div>

Hi i have created a beats based keystore

```
PS C:\Program Files\winlogbeat> .\winlogbeat.exe keystore add ES_PWD --force
Created keystore
Enter value for ES_PWD:
Successfully updated the keystore

```

winlogbeat.yml

```
#==== Elastic Hosted CLoud
keystore.path: "${path.config}/winlogbeat.keystore"
cloud.id: xxx
cloud.auth: "elastic:${ES_PWD}"

```

This fails with

`2019-08-09T13:13:54.673+1000	ERROR	pipeline/output.go:100	Failed to connect to backoff(elasticsearch(https://xxx.ap-southeast-2.aws.found.io:443)): 401 Unauthorized: {"error":{"root_cause": [{"type":"security_exception","reason":"action [cluster:monitor/main] requires authentication","header":{"WWW-Authenticate":["Bearer realm=\"security\"","ApiKey","Basic realm=\"security\" charset=\"UTF-8\""]}}],"type":"security_exception","reason":"action [cluster:monitor/main] requires authentication","header":{"WWW-Authenticate":["Bearer realm=\"security\"","ApiKey","Basic realm=\"security\" charset=\"UTF-8\""]}},"status":401}`

any ideas?

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [August 9, 2019, 1:03pm UTC](https://discuss.elastic.co/t/elastic-cloud-keystore/192187/4 "2019-08-09T13:03:37Z")

</div>

I've moved this to beats, since the folks that inhabit the cloud forum aren't necessarily experts in the ins and outs of beats config (eg I just learned about the beats keystore from this post - now _I'm_ going to go start using it everywhere).

You could try setting `cloud.id` to be from the keystore as well, that way since the logs would contain the value and you could confirm whether it's hitting the keystore at all?

(I assume you've tried with `cloud.auth` pasted directly in and confirmed that works?)

---

<div class="post-metadata">

**Author:** ![ajhstn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajhstn/32/24629_2.png) [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Post date:** [August 10, 2019, 3:54am UTC](https://discuss.elastic.co/t/elastic-cloud-keystore/192187/5 "2019-08-10T03:54:24Z")

</div>

Hi thank you - yes when i use the password in the config file it works as expected.

I'm delaying sharing the config to my team, until i can hide the password though, so this is holding me back a bit.

I'll try putting cloud.id into the keystore also which will make my config look like this, and let you know how this goes.

winlogbeat.yml

```
cloud.id: "${CLOUD_ID}"
cloud.auth: "elastic:${ES_PWD}"
```

---

<div class="post-metadata">

**Author:** ![ajhstn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajhstn/32/24629_2.png) [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Post date:** [August 10, 2019, 4:13am UTC](https://discuss.elastic.co/t/elastic-cloud-keystore/192187/6 "2019-08-10T04:13:38Z")

</div>

@Alex_Piggott you are onto a winner here.

I made two changes, firstly as you suggested I created a keystore value for `CLOUD_ID`, tested that with the clear text elastic user password and it worked.

Secondly i included the whole `elastic:password` in the `ES_PWD` keystore as well and now that also works!

Epic thank you.

My final working config is

```
cloud.id: "${CLOUD_ID}"
cloud.auth: "${ES_PWD}"
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2019, 4:13am UTC](https://discuss.elastic.co/t/elastic-cloud-keystore/192187/7 "2019-08-24T04:13:51Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
