# Keystore.password deprecated

**URL:** <https://discuss.elastic.co/t/keystore-password-deprecated/319324>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 18, 2022, 4:45pm UTC](https://discuss.elastic.co/t/keystore-password-deprecated/319324 "2022-11-18T16:45:04Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 21, 2022, 5:26pm UTC](https://discuss.elastic.co/t/keystore-password-deprecated/319324/7 "2022-11-21T17:26:54Z")

</div>

Ok I see your other post

> [@Deprecated Log](https://discuss.elastic.co/t/deprecated-log/319091):
>
> Hello, i'm trying to patch the deprecated settings in my ES cluster v.7.13.x. I runned into these 2 deprecated settings: [2022-11-16T15:03:23,504][DEPRECATION][o.e.d.c.s.Settings] [es-md-01] [xpack.security.http.ssl.keystore.password] setting was deprecated in Elasticsearch and will be removed in a future release! See the breaking changes documentation for the next major version. [2022-11-16T15:03:23,508][DEPRECATION][o.e.d.c.s.Settings] [es-md-01] [xpack.security.transport.ssl.…

Yes it is about the ssl settings...  
`xpack.security.http.ssl.keystore.password: "xxxxx"`

I get the same in the deprecation log ...

So you take that out...

AND Then you need to add they new setting to the keystore

`./bin/elasticsearch-keystore add xpack.security.http.ssl.keystore.secure_password`

That got rid of the error...seems the docs are missing the deprecation warning on the settings

Yes to it looks like everywhere there is an ssl `password` they are being replaced with `secure_password` which should be store in the `elasticsearch-keystore`

What makes it confusing of some of the ssl setting are for the ssl / java keystore 🙂

There is a note at the top of the new docs

> All of these settings can be added to the `elasticsearch.yml` configuration file, with the exception of the secure settings, which you add to the Elasticsearch keystore. For more information about creating and updating the Elasticsearch keystore, see [Secure settings](https://www.elastic.co/guide/en/elasticsearch/reference/8.5/secure-settings.html).

that means anything starting with `secure_`

---

_[View the full topic](https://discuss.elastic.co/t/keystore-password-deprecated/319324)._
