# Install ES license as config

**URL:** <https://discuss.elastic.co/t/install-es-license-as-config/190257>\
**Category:** Elasticsearch\
**Created:** [July 12, 2019, 2:13pm UTC](https://discuss.elastic.co/t/install-es-license-as-config/190257 "2019-07-12T14:13:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Plamen\_Iliev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plamen_iliev/32/50005_2.png) [@Plamen\_Iliev](https://discuss.elastic.co/u/Plamen_Iliev)\
**Post date:** [July 12, 2019, 2:13pm UTC](https://discuss.elastic.co/t/install-es-license-as-config/190257/1 "2019-07-12T14:13:18Z")

</div>

Looking at the documentation it appears license can only be installed through the license API.

In my use case it would be handy to reference the license as a setting inside elasticsearch.yaml.

Essentially I would like to boot ES with PKI realm only and I don't want to configure any passwords (bin/elasticsearch-setup-passwords). However it appears I need to first configure passwords, install the license and then reboot and use PKI.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 12, 2019, 2:37pm UTC](https://discuss.elastic.co/t/install-es-license-as-config/190257/2 "2019-07-12T14:37:35Z")

</div>

Welcome!

> [@Plamen\_Iliev](#):
>
> In my use case...

What is your use case?

---

<div class="post-metadata">

**Author:** ![Plamen\_Iliev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plamen_iliev/32/50005_2.png) [@Plamen\_Iliev](https://discuss.elastic.co/u/Plamen_Iliev)\
**Post date:** [July 13, 2019, 2:45am UTC](https://discuss.elastic.co/t/install-es-license-as-config/190257/3 "2019-07-13T02:45:37Z")

</div>

The plan is to run ES/Kibana on Docker/Kubernetes and we would like to automate as much as possible and the other main point is that we would like to not use passwords if possible and instead opt for PKI realm. Reason for the latter being strict rules when it comes to using any passwords that we would like to simply avoid and go for PKI.

So unless I am mistaken when installing and configuring ES, all security related settings (xpack.security.\* inside elasticsearch.yml) require valid license upfront. And again I believe in order to install the license we would need to [PUT] /\_license which requires a valid user like elastic to have a password. I don't think we can use the bootstrap password for anything like this.

The other way around would be if the bin/elasticsearch-setup-passwords script is able to setup password only for specific user. This would allow us to deal with a single user/password only, again from first paragraph, trying to reduce number of users outside of PKI to the minimum necessary.

Thank you.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 16, 2019, 7:24am UTC](https://discuss.elastic.co/t/install-es-license-as-config/190257/4 "2019-07-16T07:24:06Z")

</div>

There are a number of option that can work here.  
Some of your assumptions aren't correct, so this is probably easier than you think it will be.

> [@Plamen\_Iliev](#):
>
> I don't want to configure any passwords

You should absolutely configure a password for the `elastic` user, even if you then disable the user. If you do not set a password for `elastic` then it will use the bootstrap password which is not a good idea for long term security.  
You can set a password using the `_password` API if you don't want to use the `elasticsearch-setup-passwords` tool, but please do not run your cluster without setting the password for `elastic`.

> [@Plamen\_Iliev](#):
>
> However it appears I need to first configure passwords, install the license and then reboot and use PKI.

No, you don't actually need to do any of that.

What you want to do it:

- Start the cluster in trial mode by setting `xpack.license.self_generated.type: trial` in your `elaticsearch.yml`
- Enable all your TLS settings, and PKI realm
- Configure a file-based role mapping for your "administrator" certificate, to grant it an administrative role (e.g. `superuser`)
- Start your cluster
- Use the "administrator" certificate to authenticate, and install your license.
- Use the "administrator" certificate to authenticate, and set a password on the elastic user, and disable the user (you may wish to disable all builtin users).

And then you're done.

---

<div class="post-metadata">

**Author:** ![Plamen\_Iliev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plamen_iliev/32/50005_2.png) [@Plamen\_Iliev](https://discuss.elastic.co/u/Plamen_Iliev)\
**Post date:** [July 16, 2019, 12:13pm UTC](https://discuss.elastic.co/t/install-es-license-as-config/190257/5 "2019-07-16T12:13:59Z")

</div>

Thank you will give this a go.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2019, 12:14pm UTC](https://discuss.elastic.co/t/install-es-license-as-config/190257/6 "2019-08-13T12:14:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
