# Elasticsearch credentials for Kibana from keystore for ES 5.6

**URL:** <https://discuss.elastic.co/t/elasticsearch-credentials-for-kibana-from-keystore-for-es-5-6/161639>\
**Category:** Elasticsearch\
**Created:** [December 20, 2018, 7:57am UTC](https://discuss.elastic.co/t/elasticsearch-credentials-for-kibana-from-keystore-for-es-5-6/161639 "2018-12-20T07:57:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jrdtrstn](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jrdtrstn](https://discuss.elastic.co/u/jrdtrstn)\
**Post date:** [December 20, 2018, 7:57am UTC](https://discuss.elastic.co/t/elasticsearch-credentials-for-kibana-from-keystore-for-es-5-6/161639/1 "2018-12-20T07:57:09Z")

</div>

I don't want to put the property elasticsearch.password in my kibana.yml. When I try to add this setting into the keystore, ES won't start up with the following error:

> Suppressed: java.lang.IllegalArgumentException: unknown secure setting [elasticsearch.password] please check that any required plugins are installed, or check the breaking changes documentation for removed settings

Is this feature supported for 5.6?

Assuming my ES will actually startup, do I still need to put some property in my kibana.yml? I read somewhere that I need to put the following in the yml file:

> `elasticsearch.username: ${elasticsearch.username}`  
> `elasticsearch.password: ${elasticsearch.password}`

Is this still required or do I just omit these from the config file?

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [December 20, 2018, 11:14am UTC](https://discuss.elastic.co/t/elasticsearch-credentials-for-kibana-from-keystore-for-es-5-6/161639/2 "2018-12-20T11:14:43Z")

</div>

To securely store Kibana settings, you should use the [Kibana keystore](https://www.elastic.co/guide/en/kibana/current/secure-settings.html), instead of the Elasticsearch keystore. Every tool in the Elastic Stack has its own keystore.

The Kibana keystore has only been available since version 6.1, so you will have to upgrade first.

Once you apply settings to the Kibana keystore, there is no need to also put those in the kibana.yml file.

---

<div class="post-metadata">

**Author:** ![jrdtrstn](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jrdtrstn](https://discuss.elastic.co/u/jrdtrstn)\
**Post date:** [December 21, 2018, 1:48am UTC](https://discuss.elastic.co/t/elasticsearch-credentials-for-kibana-from-keystore-for-es-5-6/161639/3 "2018-12-21T01:48:30Z")

</div>

Thanks! Unfortunately, this ES cluster is a component for a vendor solution where the vendor has said that the application has only been tested and verified with ES 5.x, thus upgrading might not be an option. Are there other ways to secure this password for ES 5.6?

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [December 21, 2018, 8:39am UTC](https://discuss.elastic.co/t/elasticsearch-credentials-for-kibana-from-keystore-for-es-5-6/161639/4 "2018-12-21T08:39:47Z")

</div>

I don't think there's a way to do this in 5.6.

It's time for your vendor to get on the version 6 bandwagon 🙂. Version 6 has been out for over a year. And an alpha for version 7 has been released already, so it won't be too long until version 7 is out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2019, 8:39am UTC](https://discuss.elastic.co/t/elasticsearch-credentials-for-kibana-from-keystore-for-es-5-6/161639/5 "2019-01-18T08:39:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
