# Elasticsearch keystore - question on password protection

**URL:** <https://discuss.elastic.co/t/elasticsearch-keystore-question-on-password-protection/259607>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 24, 2020, 8:29pm UTC](https://discuss.elastic.co/t/elasticsearch-keystore-question-on-password-protection/259607 "2020-12-24T20:29:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Knipmans](https://avatars.discourse-cdn.com/v4/letter/k/ce7236/32.png) [@Knipmans](https://discuss.elastic.co/u/Knipmans)\
**Post date:** [December 24, 2020, 8:29pm UTC](https://discuss.elastic.co/t/elasticsearch-keystore-question-on-password-protection/259607/1 "2020-12-24T20:29:01Z")

</div>

Hi Elastic experts!

A small question on the Elastic keystore:

> **[elasticsearch-keystore | Elasticsearch Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/elasticsearch-keystore.html)**

Is it possible to use —stdin to provide the password?

Something like:

```
echo “mySecret” | bin/elasticsearch-keystore passwd —stdin 

```

Also, another question on:

> **[Install Elasticsearch with RPM | Elasticsearch Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/rpm.html)**

For running Elasticsearch with systemd. It’s explained to put the password in a file, which could be deleted after Elasticsearch is up and running. This is a one time activity, right? And doesn’t need to be repeated after restart of Elasticsearch or the machine?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 29, 2020, 6:10am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-question-on-password-protection/259607/2 "2020-12-29T06:10:48Z")

</div>

> [@Knipmans](#):
>
> Is it possible to use —stdin to provide the password?

Yes, it mentions it in the documentation you link to that it's an option 🙂

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 30, 2020, 6:01am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-question-on-password-protection/259607/3 "2020-12-30T06:01:27Z")

</div>

> [@Knipmans](#):
>
> It’s explained to put the password in a file, which could be deleted after Elasticsearch is up and running. This is a one time activity, right? And doesn’t need to be repeated after restart of Elasticsearch or the machine?

The file needs to exist every time Elasticsearch starts.  
From the docs:

> When the keystore is password-protected, you must supply the password each time Elasticsearch starts.

You can keep the file the permanently or you can write it out each time you restart the service, but Elasticsearch will not start without it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 27, 2021, 6:01am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-question-on-password-protection/259607/4 "2021-01-27T06:01:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
