# Generate a security token using a admin token?

**URL:** <https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705>\
**Category:** Elasticsearch\
**Created:** [June 28, 2018, 12:11am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705 "2018-06-28T00:11:54Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![BO\_GAO](https://avatars.discourse-cdn.com/v4/letter/b/cdc98d/32.png) [@BO\_GAO](https://discuss.elastic.co/u/BO_GAO)\
**Post date:** [June 28, 2018, 12:11am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/1 "2018-06-28T00:11:54Z")

</div>

I am trying to generate a security token when a user is logging in. It has been mentioned in the following documentation that "to generate a token" using a query, we need to include a valid "admin" token in the header.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-tokens.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-tokens.html)

However, any security token will expire after 24 hours, including the "admin" token. So the question is that how can we generate an admin token in the server side which will not expire? Probably I am using the wrong strategy to quest a user token using the admin token, but what will be the appropriate way to do this?

Cheers

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 28, 2018, 1:16am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/2 "2018-06-28T01:16:07Z")

</div>

> [@BO\_GAO](#):
>
> I am trying to generate a security token when a user is logging in

I didn't really follow your post.  
Why exactly are you trying to generate a security token?

---

<div class="post-metadata">

**Author:** ![BO\_GAO](https://avatars.discourse-cdn.com/v4/letter/b/cdc98d/32.png) [@BO\_GAO](https://discuss.elastic.co/u/BO_GAO)\
**Post date:** [June 28, 2018, 2:54am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/3 "2018-06-28T02:54:32Z")

</div>

Hi Tim,  
Thanks for the reply. I should simplify my question more here. So I have tried the method on this page for requesting a security token,  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-tokens.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-tokens.html)

 ![Elastic](https://us1.discourse-cdn.com/elastic/original/3X/9/d/9d4c96ab42de070b8b013f031c3d79cdee624f41.png)

However, this method does not work since it require an existing token to perform the request. Which means "we need a token to request a token". My question is that how can we remove this restriction, so we can directly request a token with user name and password only.

Cheers

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 28, 2018, 4:53am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/4 "2018-06-28T04:53:40Z")

</div>

I'm genuinely curious about the reason you're trying to use the token API. A lot of the time when I get questions about how to use it, it turns out that it's not the right fit for the problem that the person wants to use it for.  
If you do have a particular reason for wanting to use this API, then I'd love to understand what it is.

Reading between the lines, I _think_ you are being thrown off course by the error message that Elasticsearch returns if you fail to provide authentication credentials for your request (`"missing authentication token for REST request"`). That error does not specifically refer to tokens from the token management API, it refers to any credentials. You could provide an oauth token, but you can also provide a username+password for [native Elasticsearch](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/native-realm.html) or [LDAP](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/ldap-realm.html) users, or a SSL [PKI](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/pki-realm.html) certificate.

---

<div class="post-metadata">

**Author:** ![Le\_Huy](https://avatars.discourse-cdn.com/v4/letter/l/e68b1a/32.png) [@Le\_Huy](https://discuss.elastic.co/u/Le_Huy)\
**Post date:** [June 28, 2018, 7:54am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/5 "2018-06-28T07:54:04Z")

</div>

Hi Tim,  
I'm currently stuck with the same problem as BO\_GAO when I try to use the User Management APIs to create a new user. From my POV, in order to use those APIs, i have to somehow generate a token but I don't know exactly how. Could you give me any tips?  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [June 28, 2018, 11:19am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/6 "2018-06-28T11:19:18Z")

</div>

Try this with a user and it's password, you can generate a token for `username` `password` given in the request body.  
This is one way to generate token:

For eg. I am using `elastic` user and it's password and I am generating token for user `user1` and password `pass1`

> curl -k -u elastic:password -H "Content-Type: application/json" -XPOST https://:9200/\_xpack/security/oauth2/token -d '{"grant\_type" : "password", "username" : "user1", "password": "pass1"}'

Instead of username password, you can even use token generated earlier if it is valid.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 28, 2018, 11:57am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/7 "2018-06-28T11:57:47Z")

</div>

> [@Le\_Huy](#):
>
> I'm currently stuck with the same problem as BO\_GAO when I try to use the User Management APIs to create a new user

90% of the time when people think that they want to use the token management APIs, they are mistaken. Those APIs serve a very specific purpose, and are rarely the solution to the problem you have.

Please take a step back and describe what you are trying to do, and why you think the token management APIs will help with that.

---

<div class="post-metadata">

**Author:** ![Le\_Huy](https://avatars.discourse-cdn.com/v4/letter/l/e68b1a/32.png) [@Le\_Huy](https://discuss.elastic.co/u/Le_Huy)\
**Post date:** [June 28, 2018, 1:03pm UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/8 "2018-06-28T13:03:25Z")

</div>

I'm trying to protect my Elastic clusters by using User Authentication feature in xpack. I choose native realm to handle my authentication process. So far I've follow this instruction:  
[https://www.elastic.co/guide/en/x-pack/current/native-realm.html](https://www.elastic.co/guide/en/x-pack/current/native-realm.html)  
Setting up native realm is fine for me, but when i try to use User Management APIs to manage my Native users (create, alter, delete), I ran into this error message  
 ![ELS](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c5e327a8d42808648053abb476e4f572d12f1fb2.png)

when trying to execute this:  
curl -X POST "localhost:9200/\_xpack/security/user/jacknich" -H 'Content-Type: application/json' -d'  
{  
"password" : "j@rV1s",  
"roles" : ["admin", "other\_role1"],  
"full\_name" : "Jack Nicholson",  
"email" : "jacknich@example.com",  
"metadata" : {  
"intelligence" : 7  
}  
}  
'  
So i thought somehow i need to generate a token, correct me if i'm wrong since i'm very new to Elasticsearch let alone xpack, kibana and logstash

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [July 2, 2018, 12:30am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/9 "2018-07-02T00:30:49Z")

</div>

Hi @Le_Huy,

Looks like you are trying to create user 'jacknich' but you are not providing credentials(username and password) in curl request to describe who is creating user 'jacknich'.  
The request is missing `Authorization` header.

Ex. curl invocation with credentials [**-u elastic:password**]:

> curl -k -u elastic:password -H "Content-Type: application/json" -XPOST -d'  
> {  
> "password" : "j@rV1s",  
> "roles" : ["admin", "other\_role1"],  
> "full\_name" : "Jack Nicholson",  
> "email" : "[jacknich@example.com](mailto:jacknich@example.com)",  
> "metadata" : {  
> "intelligence" : 7  
> }  
> }'

Hope this helps.  
Thanks, @TimV

Regards,  
Yogesh Gaikwad

---

<div class="post-metadata">

**Author:** ![Le\_Huy](https://avatars.discourse-cdn.com/v4/letter/l/e68b1a/32.png) [@Le\_Huy](https://discuss.elastic.co/u/Le_Huy)\
**Post date:** [July 2, 2018, 7:52am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/10 "2018-07-02T07:52:26Z")

</div>

Hi @Yogesh_Gaikwad,  
Thanks for the advice, I have successfully created a new user, much appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2018, 7:52am UTC](https://discuss.elastic.co/t/generate-a-security-token-using-a-admin-token/137705/11 "2018-07-30T07:52:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
