# First boot after install fails to display password, token, etc

**URL:** <https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949>\
**Category:** Elasticsearch\
**Created:** [June 12, 2022, 12:05am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949 "2022-06-12T00:05:40Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jack\_Park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_park/32/30787_2.png) [@Jack\_Park](https://discuss.elastic.co/u/Jack_Park)\
**Post date:** [June 12, 2022, 12:05am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/1 "2022-06-12T00:05:40Z")

</div>

Version 8.2.2

Since I installed before but failed to grab those values, I started over.  
What this is telling me is that ES maintains a hidden record, which I cannot find.  
This is on a Mac. There is no ~/.elastic fie anywhere.  
In a sense, I'm asking how to purge my computer of the old install besides just deleting the directory.

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [June 12, 2022, 12:26am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/2 "2022-06-12T00:26:20Z")

</div>

What I’ve found is that if you haven’t purged Elasticsearch, that is if you have leftover Elasticsearch.yml config file the next reinstall will use the settings from the file.  
It won’t try to bootstrap or setup security like on a fresh clean install

---

<div class="post-metadata">

**Author:** ![Jack\_Park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_park/32/30787_2.png) [@Jack\_Park](https://discuss.elastic.co/u/Jack_Park)\
**Post date:** [June 12, 2022, 1:10am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/3 "2022-06-12T01:10:52Z")

</div>

Thanks! In my case I sent the entire folder to the trash and emptied it. AFIK, the old installation is gone entirely. what is now interesting is this: the trash was not empty before. Now that it is empty, a boot gave all the data I need.  
It looks to me like the solution was to ensure that the old install was vaporized before booting a fresh install.  
Thanks!

---

<div class="post-metadata">

**Author:** ![Jack\_Park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_park/32/30787_2.png) [@Jack\_Park](https://discuss.elastic.co/u/Jack_Park)\
**Post date:** [June 12, 2022, 1:19am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/4 "2022-06-12T01:19:09Z")

</div>

I am not out of the water. Kibana does not like the password. Maybe I'll have to open another request; it's not clear what the default username is for kibana.  
a lot of the googleverse thinks it's "admin" but that doesn't work.  
Elastic 8+ doc suggests "elastic" but that doesn't work.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 12, 2022, 1:48am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/5 "2022-06-12T01:48:30Z")

</div>

The default user to log in with is `elastic` plus the password generated when Elasticsearch was started...

Did you enroll or re-enroll Kibana with the enrollment token?

In other words, did you clean up Kibana and reinstall it as well??

I assume you're using the `tar.gz` installs and not homebrew or something?

---

<div class="post-metadata">

**Author:** ![Jack\_Park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_park/32/30787_2.png) [@Jack\_Park](https://discuss.elastic.co/u/Jack_Park)\
**Post date:** [June 12, 2022, 2:02am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/6 "2022-06-12T02:02:54Z")

</div>

Great reply. Thanks  
Kibana was purged from the system and reinstalled. Yes from the tgz downloads.  
I used elastic and precisely the password handed to me in the console. I'm not yet to the token submission.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 12, 2022, 2:13am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/7 "2022-06-12T02:13:05Z")

</div>

The Kibana token comes **before** it ask for a username and password.... so I am confused.

This comes before

 ![Screen Shot 2022-06-11 at 7.08.22 PM](https://us1.discourse-cdn.com/elastic/original/3X/b/3/b38b8b7c77ea551761b8fae29079c3a843fb49ab.png)

This

 ![Screen Shot 2022-06-11 at 7.10.38 PM](https://us1.discourse-cdn.com/elastic/original/3X/0/5/0509f8cfc76c5ceb3223771ea99d91f53956f0b0.png)

I suspect there are old autogenerated configurations in your kibana.yml

that looks something like this... the below gets added \*_After_ you past the enrollment token in ... if it is already there ... its leftover from a pervious configuration.

```auto
# This section was automatically generated during setup.
elasticsearch.hosts: ['https://192.168.1.159:9200']
elasticsearch.serviceAccountToken: AAEAAWVsYXN0aWMva2liYW5hL2Vucm9sbC1wcm9jZXNzLXRva2VuLTE2NTQ5OTk4MDk3NDY6a29NYVRMSlJSU085cldONTdjNHNDUQ
elasticsearch.ssl.certificateAuthorities: [/Users/sbrown/workspace/elastic-install/8.2.2/kibana-8.2.2/data/ca_1654999810637.crt]
xpack.fleet.outputs: [{id: fleet-default-output, name: default, is_default: true, is_default_monitoring: true, type: elasticsearch, hosts: ['https://192.168.1.159:9200'], ca_trusted_fingerprint: 8056fc1d72a4848676f66a328745fc3d10e7067be595740f196fb68803e7cb83}]

```

---

<div class="post-metadata">

**Author:** ![Jack\_Park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_park/32/30787_2.png) [@Jack\_Park](https://discuss.elastic.co/u/Jack_Park)\
**Post date:** [June 12, 2022, 2:16am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/8 "2022-06-12T02:16:21Z")

</div>

That's right. I did not notice that; it seems clear to me that the old token I put in from before is still around. I guess I need to purge kibana one more time and try again. Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 12, 2022, 2:20am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/9 "2022-06-12T02:20:20Z")

</div>

Old token probably will not work... they are only good for 30 mins.

I would `rm -fr` both the Elasticsearch and kibana directory.

Untar again.

go to elastseach directory

`./bin/elasticsearch`

copy all the setup info into a file.

in another window go to the kibana directory

`./bin/kibana`

click on the link it provide looks like this

```auto
Kibana has not been configured.

Go to http://localhost:5601/?code=387164 to get started.

```

paste in the enrollment token from Elasticsearch startup

login with `elastic` and password provided when you started Elasticsearch.

I just re-did this all on my mac .. about 2 mins.

---

<div class="post-metadata">

**Author:** ![Jack\_Park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_park/32/30787_2.png) [@Jack\_Park](https://discuss.elastic.co/u/Jack_Park)\
**Post date:** [June 12, 2022, 2:22am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/10 "2022-06-12T02:22:18Z")

</div>

So, I think the 30 minute timeout hit. I need to generate a fresh token

---

<div class="post-metadata">

**Author:** ![Jack\_Park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_park/32/30787_2.png) [@Jack\_Park](https://discuss.elastic.co/u/Jack_Park)\
**Post date:** [June 12, 2022, 2:25am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/11 "2022-06-12T02:25:27Z")

</div>

It is running now. Many thanks to each of you who kindly replied.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 12, 2022, 2:33am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/12 "2022-06-12T02:33:11Z")

</div>

> [@Jack\_Park](#):
>
> So, I think the 30 minute timeout hit. I need to generate a fresh token

Cool glad you got it running...

In case this happens again and you do not want to lose data you can just clean out the autogenerate stuff at the bottom of the `kibana.yml` and from elasticsearch directory run

`./bin/elasticsearch-create-enrollment-token -s kibana`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2022, 2:33am UTC](https://discuss.elastic.co/t/first-boot-after-install-fails-to-display-password-token-etc/306949/13 "2022-07-10T02:33:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
