# Hashing passwords in the Elasticsearch config?

**URL:** <https://discuss.elastic.co/t/hashing-passwords-in-the-elasticsearch-config/38185>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 30, 2015, 3:27pm UTC](https://discuss.elastic.co/t/hashing-passwords-in-the-elasticsearch-config/38185 "2015-12-30T15:27:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![y2kade](https://avatars.discourse-cdn.com/v4/letter/y/c5a1d2/32.png) [@y2kade](https://discuss.elastic.co/u/y2kade)\
**Post date:** [December 30, 2015, 3:27pm UTC](https://discuss.elastic.co/t/hashing-passwords-in-the-elasticsearch-config/38185/1 "2015-12-30T15:27:08Z")

</div>

I've just installed Shield (1.3.3) on my two node Elasticsearch (1.7.2) cluster and was wondering if it was possible to mask/hash the Java KeyStore password in the elasticsearch.yml config file? Thanks in advance.

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [December 30, 2015, 3:50pm UTC](https://discuss.elastic.co/t/hashing-passwords-in-the-elasticsearch-config/38185/2 "2015-12-30T15:50:58Z")

</div>

The most secure option is to use prompting support that was added to Elasticsearch:

[https://www.elastic.co/guide/en/elasticsearch/reference/1.6/setup-configuration.html#styles](https://www.elastic.co/guide/en/elasticsearch/reference/1.6/setup-configuration.html#styles)

You can use ${prompt.secret} or ${prompt.text} in your elasticsearch.yml and ES will prompt you to enter these values at startup. This also allows you to wrap the ES startup and provide these values programmatically and securely at ES startup.

---

<div class="post-metadata">

**Author:** ![y2kade](https://avatars.discourse-cdn.com/v4/letter/y/c5a1d2/32.png) [@y2kade](https://discuss.elastic.co/u/y2kade)\
**Post date:** [December 30, 2015, 5:13pm UTC](https://discuss.elastic.co/t/hashing-passwords-in-the-elasticsearch-config/38185/3 "2015-12-30T17:13:26Z")

</div>

Great! Thanks for the reply. I'll give it a shot and see how it goes.

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [December 30, 2015, 5:30pm UTC](https://discuss.elastic.co/t/hashing-passwords-in-the-elasticsearch-config/38185/4 "2015-12-30T17:30:09Z")

</div>

Great. Let me know how it goes.

Note that if you're not interested in security, and you only want mild obfuscation, you could use quoted unicode escaping in the ES config file. For example:

```auto
shield.ssl.keystore.password: "\u0070\u0061\u0073\u0073\u0077\u006f\u0072\u0064"

```

Again, this isn't a secure approach like the one I mentioned above, but I wanted to mention it just in case it was useful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47pm UTC](https://discuss.elastic.co/t/hashing-passwords-in-the-elasticsearch-config/38185/5 "2017-07-06T13:47:22Z")

</div>


