# Generating the password hash

**URL:** <https://discuss.elastic.co/t/generating-the-password-hash/262432>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 28, 2021, 12:00am UTC](https://discuss.elastic.co/t/generating-the-password-hash/262432 "2021-01-28T00:00:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![mchudinov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mchudinov/32/82618_2.png) [@mchudinov](https://discuss.elastic.co/u/mchudinov)\
**Post date:** [January 28, 2021, 12:00am UTC](https://discuss.elastic.co/t/generating-the-password-hash/262432/1 "2021-01-28T00:00:44Z")

</div>

How to generate a hash for file realm?  
as described here:

> **[File-based user authentication | Elasticsearch Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/file-realm.html)**

I use Elasticsearch in K8S ECK and use this document for define users:

> **[Users and roles | Elastic Cloud on Kubernetes \[1.3\] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-users-and-roles.html)**

```auto
    kind: Secret
    apiVersion: v1
    metadata:
      name: my-filerealm-secret
    stringData:
      users: |-
        rdeniro:$2a$10$BBJ/ILiyJ1eBTYoRKxkqbuDEdYECplvxnqQ47uiowE7yGqvCEgj9W
       WpA/XDMe/xtVgn1r5Sg=
      users_roles: |-
        user:rdeniro

```

How this hash string can be calculated?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 28, 2021, 5:15am UTC](https://discuss.elastic.co/t/generating-the-password-hash/262432/2 "2021-01-28T05:15:40Z")

</div>

You should not generate the hash yourself.

You should use the `elasticsearch-users` tool for this, as mentioned in the ECK docs:

> You can populate the content of both `users` and `users_roles` using the [elasticsearch-users](https://www.elastic.co/guide/en/elasticsearch/reference/current/users-command.html) tool.

Those docs have an example of how to do that using docker.

---

<div class="post-metadata">

**Author:** ![perezjasonr](https://avatars.discourse-cdn.com/v4/letter/p/d2c977/32.png) [@perezjasonr](https://discuss.elastic.co/u/perezjasonr)\
**Post date:** [February 24, 2021, 1:21pm UTC](https://discuss.elastic.co/t/generating-the-password-hash/262432/3 "2021-02-24T13:21:51Z")

</div>

So is there no room for using the bcrypt library ourselves? if I get a salted and hashed password w/ bcrypt can I just plug that value in to the users section? or does it have to be done with the elasticsearch-users helper tool (not sure if something proprietary is going on there).

I guess I'm asking because I tried this, and its not showing up in kibana or using the users api directly doesn't show my user, but also I dont see a particular complaint anywhere. so I'm not sure if it worked or not.

---

<div class="post-metadata">

**Author:** ![mchudinov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mchudinov/32/82618_2.png) [@mchudinov](https://discuss.elastic.co/u/mchudinov)\
**Post date:** [February 24, 2021, 1:41pm UTC](https://discuss.elastic.co/t/generating-the-password-hash/262432/4 "2021-02-24T13:41:14Z")

</div>

Users created that way are not shown in Kibana.  
Here is the answered question

> [@Elasticsearch-users added is not shown in Kibana UI](https://discuss.elastic.co/t/elasticsearch-users-added-is-not-shown-in-kibana-ui/262481):
>
> I have ECK Elasticsearch and Kibana running in k8s (Azure). One pod of each. I made a user with \*bin/elasticsearch-users useradd test123 -p 123456 -r superuser \* # elasticsearch-users useradd test123 -p 123456 -r superuser # elasticsearch-users list test123 : superuser The user can login to Kibana, but is not listed in Kibana UI. Why?

---

<div class="post-metadata">

**Author:** ![perezjasonr](https://avatars.discourse-cdn.com/v4/letter/p/d2c977/32.png) [@perezjasonr](https://discuss.elastic.co/u/perezjasonr)\
**Post date:** [February 24, 2021, 3:45pm UTC](https://discuss.elastic.co/t/generating-the-password-hash/262432/5 "2021-02-24T15:45:37Z")

</div>

Thank you, i found a note in the docs that it indeed cannot be managed/seen in the regular api or kibana ui, but can show up using the elasticsearch-users tool to list. My user did show up there with the mapping, but I get a 401 when that account is used to index...so this brings me back to whether or not one must use the elasticsearch-users tool to add/create the file for the secret (as per the example) or if we can use bcrypt to provide the password ourselves. I don't see that mentioned anywhere. It just assumes you will use the users helper tool. For all we know, it won't accept it unless its done with the users command helper tool.  
@TimV

---

<div class="post-metadata">

**Author:** ![perezjasonr](https://avatars.discourse-cdn.com/v4/letter/p/d2c977/32.png) [@perezjasonr](https://discuss.elastic.co/u/perezjasonr)\
**Post date:** [February 24, 2021, 6:22pm UTC](https://discuss.elastic.co/t/generating-the-password-hash/262432/6 "2021-02-24T18:22:44Z")

</div>

followup:

i couldn't get it to work plugging in user:\<my bcrypt w/ salt generated output\>  
so in the end I did use elasticsearch user helper tool using the same password i provided to bcrypt  
so I dont know what the user tool is doing differently or if it assumes specific params like rounds or stuff surrounding the salt, but the only way I could get my user to work was with the elasticsearch-user tool.

not sure if anyone wants to confirm what exact bcrypt params you'd need to match what its doing but it seems this is the only way it will accept it.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 25, 2021, 3:48am UTC](https://discuss.elastic.co/t/generating-the-password-hash/262432/7 "2021-02-25T03:48:13Z")

</div>

As I said in my earlier reply:

> [@TimV](#):
>
> You should not generate the hash yourself.
> 
> You should use the `elasticsearch-users` tool for this

Technically, of course, Elasticsearch can't tell the difference between a file that was generated by the CLI tool & an identical file that was generated by some other means.

However, we do not make any guarantees about compatibility with files other that those generated by the CLI. The way that you get a file that is compatible with Elasticsearch's file realm is by generating that file using the provided tooling.

---

<div class="post-metadata">

**Author:** ![perezjasonr](https://avatars.discourse-cdn.com/v4/letter/p/d2c977/32.png) [@perezjasonr](https://discuss.elastic.co/u/perezjasonr)\
**Post date:** [February 25, 2021, 2:05pm UTC](https://discuss.elastic.co/t/generating-the-password-hash/262432/8 "2021-02-25T14:05:28Z")

</div>

understood I was just trying to clarify that should was not must. and if you knew what exactly params it was using w/ bcrypt follow the same footsteps. I think thats a fair thing to consider.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2021, 2:06pm UTC](https://discuss.elastic.co/t/generating-the-password-hash/262432/9 "2021-03-25T14:06:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
