# Elasticsearch.yml and Keystore examples

**URL:** <https://discuss.elastic.co/t/elasticsearch-yml-and-keystore-examples/183185>\
**Category:** Elasticsearch\
**Created:** [May 28, 2019, 8:22pm UTC](https://discuss.elastic.co/t/elasticsearch-yml-and-keystore-examples/183185 "2019-05-28T20:22:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [May 28, 2019, 8:22pm UTC](https://discuss.elastic.co/t/elasticsearch-yml-and-keystore-examples/183185/1 "2019-05-28T20:22:46Z")

</div>

Does anyone have an example of how to call the keystore password from the yml file?

I'm clear on how to create the keystore from the link below, but unsure how to call the password from inside the elasticsearch.yml file. Help. Thanks.

[https://www.elastic.co/guide/en/elasticsearch/reference/5.6/secure-settings.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/secure-settings.html)

---

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [May 28, 2019, 8:31pm UTC](https://discuss.elastic.co/t/elasticsearch-yml-and-keystore-examples/183185/2 "2019-05-28T20:31:16Z")

</div>

I should clarify, this password is for my email configuration. Below is an excerpt from my yml file.

```
xpack.notification.email.account:
  exchange_account:
    profile: dion
    email_defaults:
      from: dion@domain.com
    smtp:
      auth: true
      starttls.enable: true
      host: smtp.domain.com
      port: 25
      user: dion@domain.com
      password: "password"
```

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [May 31, 2019, 6:07am UTC](https://discuss.elastic.co/t/elasticsearch-yml-and-keystore-examples/183185/3 "2019-05-31T06:07:43Z")

</div>

The elasticsearch keystore works by the elasticsearch code looking up setting values directly in the keystore. There are no references to keystore values inside elasticsearch.yml.

In your case, check the [email notification docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/notification-settings.html) (specifically the `secure_password` setting). You would set it with a keystore command like this:

```auto
echo "mypassword" | bin/elasticsearch-keystore add --stdin xpack.notification.email.account.exchange_account.smtp.secure_password

```

---

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [June 3, 2019, 7:13pm UTC](https://discuss.elastic.co/t/elasticsearch-yml-and-keystore-examples/183185/4 "2019-06-03T19:13:53Z")

</div>

Thanks Ryan. I don't think I have this capability in 5.6. Looks like the keystore command is only available after 6.x

Currently, neither Watcher nor Shield provide a mechanism to encrypt settings in `elasticsearch.yml` . Because the email account credentials appear in plain text, you should limit access to `elasticsearch.yml` to the user that you use to run Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 1, 2019, 7:14pm UTC](https://discuss.elastic.co/t/elasticsearch-yml-and-keystore-examples/183185/5 "2019-07-01T19:14:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
