# Impossible to set password for elastic builtin superuser

**URL:** <https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 24, 2022, 9:39am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305 "2022-10-24T09:39:02Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [October 24, 2022, 9:39am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/1 "2022-10-24T09:39:02Z")

</div>

Hi,

I just install elasticsearch 8.4.1 from elasticsearch-8.4.1-1.x86\_64 RPM on a Red Hat Enterprise Linux release 8.6 (Ootpa) server.

Everything looks ok, elastic service is running.

But I cannot find the elastic user password.

In the logfile /var/log/elasticsearch/cluster.log, I found a line with this:

```auto
[2022-10-24T11:09:12,063][INFO][o.e.x.s.InitialNodeSecurityAutoConfiguration] [servername.localdomain] Auto-configuration will not generate a password for the elastic bui
lt-in superuser, as we cannot determine if there is a terminal attached to the elasticsearch process. You can use the `bin/elasticsearch-reset-password` tool to set
 the password for the elastic user.

```

But running bin/elasticsearch-reset-password returns an error:

```auto
bash-4.4$ cd /usr/share/elasticsearch/
bash-4.4$ bin/elasticsearch-reset-password -u elastic

ERROR: could not write file [/etc/elasticsearch/users_roles]

```

despite the fact the file is writable for the user elasticsearch:

```auto
bash-4.4$ id
uid=9999(elasticsearch) gid=9999(elasticsearch) groups=9999(elasticsearch) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
bash-4.4$ ls -l /etc/elasticsearch/users*
-rw-rw----. 1 root elasticsearch 0 Aug 26 14:16 /etc/elasticsearch/users
-rw-rw----. 1 root elasticsearch 0 Aug 26 14:16 /etc/elasticsearch/users_roles

bash-4.4$ ls -ln /etc/elasticsearch/users*
-rw-rw----. 1 0 9999 0 Aug 26 14:16 /etc/elasticsearch/users
-rw-rw----. 1 0 9999 0 Aug 26 14:16 /etc/elasticsearch/users_roles

```

And user elasticsearch can write in file:

```auto
bash-4.4$ ls -l users
-rw-rw----. 1 root elasticsearch 0 Aug 26 14:16 users
bash-4.4$ touch users
bash-4.4$ ls -l users
-rw-rw----. 1 root elasticsearch 0 Oct 24 13:21 users

```

Also, SElinux is enable on the server:

```auto
bash-4.4$ ls -Z /etc/elasticsearch/users*
system_u:object_r:etc_t:s0 /etc/elasticsearch/users system_u:object_r:etc_t:s0 /etc/elasticsearch/users_roles
bash-4.4$ id -Z
unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023

```

Any suggestion ?

Regards,

JM

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [October 25, 2022, 12:38pm UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/2 "2022-10-25T12:38:00Z")

</div>

Is it possible I am the only one facing this issue ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 26, 2022, 12:30am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/3 "2022-10-26T00:30:59Z")

</div>

> [@JimJ](#):
>
> But running bin/elasticsearch-reset-password returns an error:

What user are you running that as?

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 26, 2022, 1:35am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/4 "2022-10-26T01:35:29Z")

</div>

Can you please check whether the directories (`/etc/elasticsearch` and `/etc`) hosting the files are writable for the `elasticsearch` user?

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [October 26, 2022, 4:36am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/5 "2022-10-26T04:36:48Z")

</div>

> [@JimJ](#):
>
> ```auto
> Auto-configuration will not generate a password for the elastic bui
> lt-in superuser, as we cannot determine if there is a terminal attached to the elasticsearch process. You can use the `bin/elasticsearch-reset-password` tool to set
> 
> ```

I use the `elasticsearch` user.

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [October 26, 2022, 4:49am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/7 "2022-10-26T04:49:40Z")

</div>

the `elasticsearch` user can write into existing files but not create new ones.

```auto
$ sudo -u elasticsearch /usr/bin/bash
Creating home directory for elasticsearch.

bash-4.4$ id
uid=983(elasticsearch) gid=983(elasticsearch) groups=983(elasticsearch) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023

bash-4.4$ cd /etc/elasticsearch/

bash-4.4$ pwd
/etc/elasticsearch

bash-4.4$ cat > trying
bash: trying: Permission denied

bash-4.4$ echo trying > trying
bash: trying: Permission denied

bash-4.4$ vim elasticsearch.yml
bash-4.4$ grep line elasticsearch.yml
# Adding a line into this file
bash-4.4$ vim elasticsearch.yml
bash-4.4$ grep line elasticsearch.yml

bash-4.4$ ls -la
total 60
drwxr-s---. 4 root elasticsearch 253 Oct 21 10:16 .
drwxr-xr-x. 128 root root 8192 Oct 21 10:16 ..
drwxr-x---. 2 root elasticsearch 62 Oct 21 10:16 certs
-rw-rw----. 1 root elasticsearch 536 Oct 21 10:16 elasticsearch.keystore
-rw-rw----. 1 root elasticsearch 1042 Aug 26 14:16 elasticsearch-plugins.example.yml
-rw-rw----. 1 root elasticsearch 4292 Oct 25 14:14 elasticsearch.yml
-rw-rw----. 1 root elasticsearch 2617 Aug 26 14:16 jvm.options
drwxr-s---. 2 root elasticsearch 6 Aug 26 14:19 jvm.options.d
-rw-rw----. 1 root elasticsearch 17417 Aug 26 14:16 log4j2.properties
-rw-rw----. 1 root elasticsearch 473 Aug 26 14:16 role_mapping.yml
-rw-rw----. 1 root elasticsearch 197 Aug 26 14:16 roles.yml
-rw-rw----. 1 root elasticsearch 0 Oct 24 13:21 users
-rw-rw----. 1 root elasticsearch 0 Aug 26 14:16 users_roles

bash-4.4$

```

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 27, 2022, 12:25am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/8 "2022-10-27T00:25:01Z")

</div>

> [@JimJ](#):
>
> `drwxr-xr-x. 128 root root 8192 Oct 21 10:16 ..`

You need fix file permission of the parent folder (I believe it is `/etc/elasticsearch/`) to create any new files. It is currently owned by `root:root` as oppose to `root:elasticsearch`.

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [October 27, 2022, 5:11am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/9 "2022-10-27T05:11:03Z")

</div>

parent folder is `/etc`.

I will not change the ownership of `/etc` to `root:elasticsearch`.

But you are right, as `/etc/elasticsearch` directory gets `drwxr-s---` permissions, meaning the `elasticsearch` user cannot create any files in it.

But it is still not explaining the error message saying:

```auto
ERROR: could not write file [/etc/elasticsearch/users_roles]

```

This file is writable for the user `elasticsearch`.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 27, 2022, 5:56am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/10 "2022-10-27T05:56:05Z")

</div>

Something else is going on here is my fully functional  
Which appears to be aligned with your settings...

```auto
root@stephenb-es-8-test:/etc/elasticsearch# ls -la
total 72
drwxr-sr-x 4 root elasticsearch 4096 Oct 23 19:25 .
drwxr-xr-x 98 root root 4096 Oct 27 02:11 ..
drwxr-xr-x 2 root elasticsearch 4096 Oct 7 19:09 certs
-rw-rw---- 1 root elasticsearch 1042 Jun 8 22:28 elasticsearch-plugins.example.yml
-rw-rw---- 1 root elasticsearch 536 Jun 27 18:30 elasticsearch.keystore
-rw-rw---- 1 root elasticsearch 4296 Oct 7 19:10 elasticsearch.yml
-rw-rw---- 1 root elasticsearch 2617 Sep 14 16:33 jvm.options
drwxr-s--- 2 root elasticsearch 4096 Jun 8 22:28 jvm.options.d
-rw-rw---- 1 root elasticsearch 17417 Sep 14 16:33 log4j2.properties
-rw-rw---- 1 root elasticsearch 473 Jun 8 22:28 role_mapping.yml
-rw-rw---- 1 root elasticsearch 197 Jun 8 22:28 roles.yml
-rw-rw---- 1 root elasticsearch 84 Oct 23 19:25 users
-rw-rw---- 1 root elasticsearch 33 Oct 23 19:25 users_roles

```

have you simply tried

`sudo bin/elasticsearch-reset-password -u elastic`

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 27, 2022, 6:00am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/11 "2022-10-27T06:00:12Z")

</div>

and I just changed my password...

```auto
root@stephenb-es-8-test:/etc/elasticsearch# sudo /usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic -url https://elasticsearch.mydomain.net:9200
This tool will reset the password of the [elastic] user to an autogenerated value.
The password will be printed in the console.
Please confirm that you would like to continue [y/N]y

Password for the [elastic] user successfully reset.
New value: askljfdhasldkfjhasflkasjdfh

```

then Tested It

```auto
# curl -u elastic https://elasticsearch.mydomain.net:9200
Enter host password for user 'elastic':
{
  "name" : "stephenb-es-8-test",
  "cluster_name" : "elasticsearch",
  "cluster_uuid" : "asdfsadfasdfasdf",
  "version" : {
    "number" : "8.4.3",
    "build_flavor" : "default",
    "build_type" : "deb",
    "build_hash" : "42f05b9372a9a4a470db3b52817899b99a76ee73",
    "build_date" : "2022-10-04T07:17:24.662462378Z",
    "build_snapshot" : false,
    "lucene_version" : "9.3.0",
    "minimum_wire_compatibility_version" : "7.17.0",
    "minimum_index_compatibility_version" : "7.0.0"
  },
  "tagline" : "You Know, for Search"
}

```

and you can see it updated the files

```auto
root@stephenb-es-8-test:/etc/elasticsearch# ls -lart
total 72
-rw-rw---- 1 root elasticsearch 197 Jun 8 22:28 roles.yml
-rw-rw---- 1 root elasticsearch 473 Jun 8 22:28 role_mapping.yml
drwxr-s--- 2 root elasticsearch 4096 Jun 8 22:28 jvm.options.d
-rw-rw---- 1 root elasticsearch 1042 Jun 8 22:28 elasticsearch-plugins.example.yml
-rw-rw---- 1 root elasticsearch 536 Jun 27 18:30 elasticsearch.keystore
-rw-rw---- 1 root elasticsearch 17417 Sep 14 16:33 log4j2.properties
-rw-rw---- 1 root elasticsearch 2617 Sep 14 16:33 jvm.options
drwxr-xr-x 2 root elasticsearch 4096 Oct 7 19:09 certs
-rw-rw---- 1 root elasticsearch 4296 Oct 7 19:10 elasticsearch.yml
drwxr-xr-x 98 root root 4096 Oct 27 02:11 ..
-rw-rw---- 1 root elasticsearch 168 Oct 27 05:58 users
-rw-rw---- 1 root elasticsearch 56 Oct 27 05:58 users_roles
drwxr-sr-x 4 root elasticsearch 4096 Oct 27 05:58 .

```

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [October 27, 2022, 6:14am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/12 "2022-10-27T06:14:03Z")

</div>

> [@stephenb](#):
>
> have you simply tried
> 
> `sudo bin/elasticsearch-reset-password -u elastic`

Hi Stephen,

I am not admin of the server and have no sudo on it.

I requested privileged access and planned to try this once done.

It is too bad you have to be `root` to change elastic builtin user password.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 27, 2022, 7:00am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/13 "2022-10-27T07:00:29Z")

</div>

> [@JimJ](#):
>
> But it is still not explaining the error message saying:
> 
> ```auto
> ERROR: could not write file [/etc/elasticsearch/users_roles]
> 
> ```
> 
> This file is writable for the user `elasticsearch`.

The CLI tools always try to write the file atomicly. To do that, it internally creates a temporary file and write changes to the temp file. It then copies the file to overwrite the actual file to achieve atomicity. So what the error really means is that it cannot create the temp file which is a new file.

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [October 27, 2022, 7:08am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/14 "2022-10-27T07:08:58Z")

</div>

I asked to an admin to add a `'w'` permission on `/etc/elasticsearch/` at group level.

Now, running `$ sudo -u elasticsearch bin/elasticsearch-reset-password -u elastic`, I get this message:

```auto
WARNING: Owner of file [/etc/elasticsearch/users] used to be [root], but now is [elasticsearch]
WARNING: Owner of file [/etc/elasticsearch/users_roles] used to be [root], but now is [elasticsearch]
This tool will reset the password of the [elastic] user to an autogenerated value.
The password will be printed in the console.
Please confirm that you would like to continue [y/N]

```

and the `/etc/elasticsearch/users*` files ownership changed from `root:elasticsearch` to `elasticsearch:elasticsearch`.

And the reset works:

```auto
Password for the [elastic] user successfully reset.
New value: xxx

```

So, solution: allow `elasticsearch` user to write in `/etc/elasticsearch/` directory.

Note, writting into `/etc/elasticsearch/users*` files seems to be temporary because once the reset done, files are emptied. I guess the system uses the native solution storing users+passwords in a dedicated index.

Do you think this should be in the Elastic documentation ? The fact you have to be `root` to reset password ?

Or maybe just put the right `/etc/elasticsearch/` directory permission when instaling from a package ?

JM

---

<div class="post-metadata">

**Author:** ![JimJ](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Post date:** [October 27, 2022, 7:11am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/15 "2022-10-27T07:11:51Z")

</div>

> [@Yang\_Wang](#):
>
> The CLI tools always try to write the file atomicly. To do that, it internally creates a temporary file and write changes to the temp file. It then copies the file to overwrite the actual file to achieve atomicity. So what the error really means is that it cannot create the temp file which is a new file.

That's was my first assomption, the tool trying to create a temp file into `/etc/elasticsearch/` directory.

Error message is not clear and misleading. It will be very helpfull saying, i.e., `Cannot create Temp file into /etc/elasticsearch/`.

If it was like this, the problem was solved in 1 minute.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2022, 7:12am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305/16 "2022-11-24T07:12:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
