# Error creating a new enrollment token

**URL:** <https://discuss.elastic.co/t/error-creating-a-new-enrollment-token/169320>\
**Category:** Beats\
**Tags:** fleet\
**Created:** [February 21, 2019, 4:22am UTC](https://discuss.elastic.co/t/error-creating-a-new-enrollment-token/169320 "2019-02-21T04:22:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 21, 2019, 4:22am UTC](https://discuss.elastic.co/t/error-creating-a-new-enrollment-token/169320/1 "2019-02-21T04:22:01Z")

</div>

Hello World!

I'm using Elastic Stack 6.6.1 and trying to follow [Enroll Beats in central management](https://www.elastic.co/guide/en/beats/filebeat/current/enroll-beats.html#username-password-enrollment) along with [Secrets keystore for secure settings](https://www.elastic.co/guide/en/beats/filebeat/current/keystore.html#add-keys-to-keystore) and running into following issue:

```
# echo changeme | filebeat keystore add ES_PWD --stdin --force
Successfully updated the keystore
# 
# filebeat enroll https://X.X.X:443 --username elastic --password env:ES_PWD
Error creating a new enrollment token: [security_exception] failed to authenticate user [elastic], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } }
# 

```

yet, username:password seems to work:

```
# export ES_PWD=changeme
# curl -s -I https://elastic:$ES_PWD@x.x.x:443 | grep ^HTTP
HTTP/1.1 200 OK
# 

```

Please advise.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [February 21, 2019, 2:26pm UTC](https://discuss.elastic.co/t/error-creating-a-new-enrollment-token/169320/2 "2019-02-21T14:26:40Z")

</div>

Checking the code, the `--password` CLI flag only supports `stdin` and `env` in 6.6. The `env` method does not read from the keystore, but expects you to use an environment variable.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 21, 2019, 5:54pm UTC](https://discuss.elastic.co/t/error-creating-a-new-enrollment-token/169320/3 "2019-02-21T17:54:55Z")

</div>

ok, still getting same security\_exception:

```
# ES_PWD=changeme
# filebeat enroll https://X.X.X:443 --username elastic --password env:ES_PWD
Error creating a new enrollment token: [security_exception] failed to authenticate user [elastic], with { header={ WWW-Authenticate="Basic realm=\"security\" charset=\"UTF-8\"" } }
# curl -s -I https://elastic:$ES_PWD@X.X.X:443 | grep ^HTTP
HTTP/1.1 200 OK
# 

```

yet, following works as expected:

```
# filebeat enroll https://X.X.X:443 --username elastic --password stdin
Enter password: 
This will replace your current settings. Do you want to continue? [Y/n]:y
Saving a copy of current settings to /etc/filebeat/filebeat.yml.bak
Enrolled and ready to retrieve settings from Kibana
#
```

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [February 25, 2019, 3:22pm UTC](https://discuss.elastic.co/t/error-creating-a-new-enrollment-token/169320/4 "2019-02-25T15:22:53Z")

</div>

When you do `ES_PWD=change` the environment variable will be only valid for the current command, if precede the command with the variable like in the next example it will correctly take the environment variable:

```auto
ES_PWD=changeme filebeat enroll https://X.X.X:443 --username elastic --password env:ES_PWD

```

But I still think its a bug, we should report that we cannot retrieve the environment variable.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [February 25, 2019, 3:49pm UTC](https://discuss.elastic.co/t/error-creating-a-new-enrollment-token/169320/5 "2019-02-25T15:49:22Z")

</div>

I have created the following PR to give better feedback [https://github.com/elastic/beats/pull/10936](https://github.com/elastic/beats/pull/10936)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2019, 5:49pm UTC](https://discuss.elastic.co/t/error-creating-a-new-enrollment-token/169320/6 "2019-03-25T17:49:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
