# Help Creating a File Based User

**URL:** <https://discuss.elastic.co/t/help-creating-a-file-based-user/186311>\
**Category:** Elasticsearch\
**Created:** [June 18, 2019, 4:22pm UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311 "2019-06-18T16:22:59Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ryh](https://avatars.discourse-cdn.com/v4/letter/r/ba9def/32.png) [@ryh](https://discuss.elastic.co/u/ryh)\
**Post date:** [June 18, 2019, 4:22pm UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311/1 "2019-06-18T16:22:59Z")

</div>

Hi All,

I can't seem to get this working via Docker.

Here's my Dockerfile.

```auto
FROM docker.elastic.co/elasticsearch/elasticsearch:7.1.1

COPY --chown=elasticsearch:elasticsearch users /usr/share/elasticsearch/config/
COPY --chown=elasticsearch:elasticsearch users_roles /usr/share/elasticsearch/config/
COPY --chown=elasticsearch:elasticsearch roles.yml /usr/share/elasticsearch/config/
COPY --chown=elasticsearch:elasticsearch elasticsearch.yml /usr/share/elasticsearch/config/

CMD ["elasticsearch", "-Elogger.level=INFO"]

```

roles.yml

```auto
writer:
  indices:
    - names: ['*']
      privileges: ['write', 'read']

```

user\_roles

```auto
writer:ry

```

users

```auto
ry:$2b$10$JEXLIzQeRVRYcA.r/J3HB.OT2w9z1INft9Ltv809ouczvnezIhuMS

```

I keep getting a 401 error.

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "unable to authenticate user [ry] for REST request [/?pretty]",
        "header" : {
          "WWW-Authenticate" : "Basic realm=\"security\" charset=\"UTF-8\""
        }
      }
    ],
    "type" : "security_exception",
    "reason" : "unable to authenticate user [ry] for REST request [/?pretty]",
    "header" : {
      "WWW-Authenticate" : "Basic realm=\"security\" charset=\"UTF-8\""
    }
  },
  "status" : 401
}

```

Thanks in advance,  
Ry

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 21, 2019, 2:46am UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311/2 "2019-06-21T02:46:28Z")

</div>

> [@ryh](#):
>
> ry:$2b$10$JEXLIzQeRVRYcA.r/J3HB.OT2w9z1INft9Ltv809ouczvnezIhuMS

How did you create this file?  
It definitely wasn't created using the `elasticsearch-users` tool.  
We don't use version `2b` bcrypt passwords.

---

<div class="post-metadata">

**Author:** ![ryh](https://avatars.discourse-cdn.com/v4/letter/r/ba9def/32.png) [@ryh](https://discuss.elastic.co/u/ryh)\
**Post date:** [June 21, 2019, 4:45pm UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311/3 "2019-06-21T16:45:38Z")

</div>

Created it using python's bcrypt library

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 24, 2019, 4:49am UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311/4 "2019-06-24T04:49:10Z")

</div>

Well that won't work. The bcrypt format that python generates is not the same at we use internally.

Officially, we only support using the `elasticsearch-users` tool to manage these files. You're free to manage them some othr way, but you will need to make sure that they're in a compatible format with the files we generate.

---

<div class="post-metadata">

**Author:** ![ryh](https://avatars.discourse-cdn.com/v4/letter/r/ba9def/32.png) [@ryh](https://discuss.elastic.co/u/ryh)\
**Post date:** [June 24, 2019, 4:20pm UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311/5 "2019-06-24T16:20:32Z")

</div>

Python's bcyrpt is equivalent to the hash/salt algorithm that elasticsearch uses. I found out that replacing 2b with 2a is actually allowed and will not screw things up.

Am I still missing anything? Here's the new users file

```auto
some_app: $2a$10$Sgyqh8VXqZbQ07jlhsLbPOtAS576ehgbOEeiecpEEeLiLncUP2W4i

```

roles.yml

```auto
es_write_only:
    cluster: ['all']
    indices:
      - names: ["*"]
        privileges: ["write", "create_index", "create", "index"]

```

users\_roles

```auto
es_write_only: some_app

```

Result

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "unable to authenticate user [some_app] for REST request [/?pretty]",
        "header" : {
          "WWW-Authenticate" : "Basic realm=\"security\" charset=\"UTF-8\""
        }
      }
    ],
    "type" : "security_exception",
    "reason" : "unable to authenticate user [some_app] for REST request [/?pretty]",
    "header" : {
      "WWW-Authenticate" : "Basic realm=\"security\" charset=\"UTF-8\""
    }
  },
  "status" : 401
}

```

Thanks,  
Ry

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 25, 2019, 1:09am UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311/6 "2019-06-25T01:09:42Z")

</div>

> [@ryh](#):
>
> I found out that replacing 2b with 2a is actually allowed and will not screw things up.

That's a very confident assertion to make, given that you haven't actually gotten it working yet.

> [@](#):
>
> ```auto
> es_write_only: some_app
> 
> ```
> 
> ```auto
> some_app: $2a$10$Sgyqh8VXqZbQ07jlhsLbPOtAS576ehgbOEeiecpEEeLiLncUP2W4i
> 
> ```

You have spaces in there. Our tool does not generate spaces.  
To quote my earlier comment:

> [@TimV](#):
>
> you will need to make sure that they're in a compatible format with the files we generate.

---

<div class="post-metadata">

**Author:** ![ryh](https://avatars.discourse-cdn.com/v4/letter/r/ba9def/32.png) [@ryh](https://discuss.elastic.co/u/ryh)\
**Post date:** [June 25, 2019, 4:00pm UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311/7 "2019-06-25T16:00:52Z")

</div>

When I meant not screw things up, I meant Python's bcrypt library is still able to decode my password even after changing 2b to 2a.

I'm referencing this table which states that encryption type needed for elasticsearch to read my hashed/salted password - [https://www.elastic.co/guide/en/elasticsearch/reference/master/security-settings.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/security-settings.html)

```auto
Likewise, realms that store passwords hash them using cryptographically strong and password-specific salt values. You can configure the algorithm for password hashing by setting the xpack.security.authc.password_hashing.algorithm setting to one of the following:

Table 2. Password hashing algorithms

Algorithm Description
bcrypt

 	 	
Uses bcrypt algorithm with salt generated in 1024 rounds. (default)

bcrypt4

 	 	
Uses bcrypt algorithm with salt generated in 16 rounds.

bcrypt5

 	 	
Uses bcrypt algorithm with salt generated in 32 rounds.

bcrypt6

 	 	
Uses bcrypt algorithm with salt generated in 64 rounds.

bcrypt7

 	 	
Uses bcrypt algorithm with salt generated in 128 rounds.

bcrypt8

 	 	
Uses bcrypt algorithm with salt generated in 256 rounds.

bcrypt9

 	 	
Uses bcrypt algorithm with salt generated in 512 rounds.

bcrypt10

 	 	
Uses bcrypt algorithm with salt generated in 1024 rounds.

```

Is there any bcrypt library on any programming language able to replicate elaticsearch-users results?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 26, 2019, 3:13am UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311/8 "2019-06-26T03:13:30Z")

</div>

I'm sorry, I can't really help you. The only option we support for generating those files it to use the `elasticsearch-users` tool directly.

I you really want to reproduce that code yourself, then I can't stop you, but you're on your own. My only advice is to call the `elasticsearch-users` tool directly.

---

<div class="post-metadata">

**Author:** ![ryh](https://avatars.discourse-cdn.com/v4/letter/r/ba9def/32.png) [@ryh](https://discuss.elastic.co/u/ryh)\
**Post date:** [June 26, 2019, 4:14pm UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311/9 "2019-06-26T16:14:24Z")

</div>

No worries. I understand.

Thanks for the replies,  
Ry

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2019, 4:14pm UTC](https://discuss.elastic.co/t/help-creating-a-file-based-user/186311/10 "2019-07-24T16:14:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
