# Fail to reset kibana\_system and elastic passwords

**URL:** <https://discuss.elastic.co/t/fail-to-reset-kibana-system-and-elastic-passwords/351525>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 22, 2024, 9:57am UTC](https://discuss.elastic.co/t/fail-to-reset-kibana-system-and-elastic-passwords/351525 "2024-01-22T09:57:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nas/32/130987_2.png) [@nas](https://discuss.elastic.co/u/nas)\
**Post date:** [January 22, 2024, 9:57am UTC](https://discuss.elastic.co/t/fail-to-reset-kibana-system-and-elastic-passwords/351525/1 "2024-01-22T09:57:22Z")

</div>

Hi All,

We run elasticsearch in a clustered mode and recently upgraded from 5 through to version 8.2.0

I tried to enable security TLS and minimal security by following these guides

> **[Set up minimal security for Elasticsearch | Elasticsearch Guide \[8.12\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-minimal-setup.html)**

> **[Set up basic security for the Elastic Stack | Elasticsearch Guide \[8.12\] |...](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html)**

Resulting in the following elasticsearch.yml

```auto
cluster.name: es-cluster
node.name: node-main-1
path.data: "/var/lib/elasticsearch"
path.logs: "/var/log/elasticsearch"
path.home: "/usr/share/elasticsearch"
thread_pool.search.size: 200
thread_pool.search.queue_size: 20000
network.host:
- _ec2_
- _local_
discovery.ec2.groups: elk-access, elk-cluster
discovery.seed_providers: ec2
cluster.initial_master_nodes: node-main-1
node.roles:
- master
- data
- data_content
- data_hot
- data_warm
- data_cold
- data_frozen
- ingest
- ml
- remote_cluster_client
- transform
xpack.security.enabled: true
xpack.security.authc.api_key.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.client_authentication: required
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

```

Problem is when i tried to reset the elastic and kibana\_system users i'm met with the following error

```auto
/usr/share/elasticsearch/bin/elasticsearch-reset-password -i -u elastic

ERROR: unable to determine default URL from settings, please use the -u option to explicitly provide the url

```

I also tried to create an admin user on this particular node and it worked but wasn't propagated to other nodes so the admin user doesn't work on other nodes

output of cluster health

```auto
{
    "cluster_name": "es-cluster",
    "status": "green",
    "timed_out": false,
    "number_of_nodes": 3,
    "number_of_data_nodes": 3,
    "active_primary_shards": 731,
    "active_shards": 1462,
    "relocating_shards": 0,
    "initializing_shards": 0,
    "unassigned_shards": 0,
    "delayed_unassigned_shards": 0,
    "number_of_pending_tasks": 0,
    "number_of_in_flight_fetch": 0,
    "task_max_waiting_in_queue_millis": 0,
    "active_shards_percent_as_number": 100.0
}

```

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 22, 2024, 10:04am UTC](https://discuss.elastic.co/t/fail-to-reset-kibana-system-and-elastic-passwords/351525/2 "2024-01-22T10:04:27Z")

</div>

> [@nas](#):
>
> `network.host:`

Hi,

You can resolve this issue by providing the URL of your Elasticsearch instance using the `-u` option when running the `elasticsearch-reset-password` command. The URL should be in the format `http://hostname:port`. For example:

```auto
/usr/share/elasticsearch/bin/elasticsearch-reset-password -i -u http://localhost:9200 elastic

```

Replace `http://localhost:9200` with the URL of your Elasticsearch instance.

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2024, 10:04am UTC](https://discuss.elastic.co/t/fail-to-reset-kibana-system-and-elastic-passwords/351525/3 "2024-02-19T10:04:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
