# Errors with elasticsearch-users useradd -- 7.17.1

**URL:** <https://discuss.elastic.co/t/errors-with-elasticsearch-users-useradd-7-17-1/312070>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 15, 2022, 2:28am UTC](https://discuss.elastic.co/t/errors-with-elasticsearch-users-useradd-7-17-1/312070 "2022-08-15T02:28:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [August 15, 2022, 2:28am UTC](https://discuss.elastic.co/t/errors-with-elasticsearch-users-useradd-7-17-1/312070/1 "2022-08-15T02:28:49Z")

</div>

I am trying to add a user to the file realm to recover from the elastic user failing to login -- I have no idea why logins started to fail.

From the manual I understand that the file realm is active by default so I don't have to change the config.

```auto
elasticsearch@secesprd02:/usr/share/elasticsearch$ bin/elasticsearch-users useradd my_admin -p mytemp-password -r superuser
Exception in thread "main" java.io.UncheckedIOException: could not write file [/etc/elasticsearch/users]
	at org.elasticsearch.xpack.security.support.SecurityFiles.writeFileAtomically(SecurityFiles.java:72)
	at org.elasticsearch.xpack.security.authc.file.FileUserPasswdStore.writeFile(FileUserPasswdStore.java:180)

elasticsearch@secesprd02:/usr/share/elasticsearch$ id
uid=114(elasticsearch) gid=123(elasticsearch) groups=123(elasticsearch),1042(letsencrypt)
elasticsearch@secesprd02:/usr/share/elasticsearch$ ls -l /etc/elasticsearch/users
-rw-rw---- 1 root elasticsearch 0 Aug 15 13:54 /etc/elasticsearch/users
elasticsearch@secesprd02:/usr/share/elasticsearch$ touch /etc/elasticsearch/users
elasticsearch@secesprd02:/usr/share/elasticsearch$ 

```

The `elasticsearch` user has write access to `/etc/elasticsearch/users` so I at a loss as to why java gets a permissions error when trying to write it.

Any help on this _very much appreciated!_. : )

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [August 15, 2022, 5:05am UTC](https://discuss.elastic.co/t/errors-with-elasticsearch-users-useradd-7-17-1/312070/2 "2022-08-15T05:05:53Z")

</div>

Is the disk full?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 15, 2022, 5:17am UTC](https://discuss.elastic.co/t/errors-with-elasticsearch-users-useradd-7-17-1/312070/3 "2022-08-15T05:17:10Z")

</div>

I suspect this is due to the directory permissions. In order to make an atomic update, the CLI will write to a temporary file in the `/etc/elasticsearch` directory and then rename that file to `users` (unix filesystems provide atomic renames, but not atomic writes).

Unless the `elasticsearch` user can write a new file into the directory, that process will fail.

---

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [August 15, 2022, 7:31pm UTC](https://discuss.elastic.co/t/errors-with-elasticsearch-users-useradd-7-17-1/312070/4 "2022-08-15T19:31:26Z")

</div>

bingo!

```auto
search@secesprd02:~$ ls -ld /etc/elasticsearch/
drwxr-xr-x 5 root root 4096 Aug 8 12:17 /etc/elasticsearch/

```

Thanks Tim!

BTW I was working from the wonderfully detailed instructions that you posted in [this](https://discuss.elastic.co/t/x-pack-authentication-issue/121632) thread.

Just btw those instruction are now slightly out of date: `bin/x-pack/users useradd...` is now ` bin/elasticsearch-users useradd`, at least at 7.17.

An aside: one of the features I dislike in this forum is that threads get closed after a month of inactivity. This prevents good answers being enhanced by new insights or changes in ES. The latter is particularly critical for ES which evolves fast.

Compare this with the Stack Exchange based forums where good answers are frequently updated for years afterward. Also completely new answers are added as new capabilities are added to systems. This again is very relevant to ES!

---

<div class="post-metadata">

**Author:** ![Russell\_Fulton](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russell_fulton/32/62888_2.png) [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Post date:** [August 15, 2022, 11:44pm UTC](https://discuss.elastic.co/t/errors-with-elasticsearch-users-useradd-7-17-1/312070/5 "2022-08-15T23:44:23Z")

</div>

the adduser now works:

```auto
elasticsearch@secesprd02:/usr/share/elasticsearch$ bin/elasticsearch-users useradd my_admin -p xxxxxx -r superuser
WARNING: Owner of file [/etc/elasticsearch/users] used to be [root], but now is [elasticsearch]
WARNING: Owner of file [/etc/elasticsearch/users_roles] used to be [root], but now is [elasticsearch]
elasticsearch@secesprd02:/usr/share/elasticsearch$ ls -l /etc/elasticsearch/users
-rw-rw---- 1 elasticsearch elasticsearch 70 Aug 16 08:35 /etc/elasticsearch/users
elasticsearch@secesprd02:/usr/share/elasticsearch$ logout

```

not sure what the WARNING are about that file was always owned by elasticsearch ?

When I test it I get:

```auto
rful011@secesprd02:~$ curl --noproxy \* -u my_admin -XPUT 'https://secesprd01.its.auckland.ac.nz:9200/_password?pretty' -H 'Content-Type: application/json' -d'{ "password": "xxxxxxxxxxxxxxxxx" }' 
Enter host password for user 'my_admin':
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "unable to authenticate user [my_admin] for REST request [/_password?pretty]",
        "header" : {
          "WWW-Authenticate" : [
            "Basic realm=\"security\" charset=\"UTF-8\"",
            "Bearer realm=\"security\"",
            "ApiKey"
          ]
        }
      }
    ],
 < snip >
  "status" : 401
}

```

I notice that the users file is present only on the node where it was created so I tried copying `users' and `users-roles' to all the other nodes. It made no difference - no great surprise.

I suspect that the problem is `"Basic realm="security"` where as this user was created in realm `"file"`

I have look at various docs about realms and authentication but failed to find anything on specifying the realm when authenticating.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2022, 12:38am UTC](https://discuss.elastic.co/t/errors-with-elasticsearch-users-useradd-7-17-1/312070/7 "2022-09-13T00:38:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
