# Manually configure security, divergence in the documentation

**URL:** <https://discuss.elastic.co/t/manually-configure-security-divergence-in-the-documentation/315601>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 30, 2022, 6:12pm UTC](https://discuss.elastic.co/t/manually-configure-security-divergence-in-the-documentation/315601 "2022-09-30T18:12:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 30, 2022, 6:12pm UTC](https://discuss.elastic.co/t/manually-configure-security-divergence-in-the-documentation/315601/1 "2022-09-30T18:12:06Z")

</div>

Hello,

I'm creating a new cluster using 8.4 and configuring the security features manually.

I've created the certificates for the transport and http protocol and everything works as expected, the cluster starts up and the nodes communicate with each other without any issue.

The next part would be to reset the password for the built-in users.

From the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/master/security-minimal-setup.html#security-create-builtin-users), to do that you just need to run the following command in any node.

> ./bin/elasticsearch-reset-password auto

But running this command produces the following output:

```auto
[root@redacted ~]# /usr/share/elasticsearch/bin/elasticsearch-reset-password auto
Resets the password of users in the native realm and built-in users.

Option (* = required) Description                                          
--------------------- -----------                                          
-E <KeyValuePair> Configure a setting                                  
-a, --auto                                                                  
-b, --batch                                                                 
-f, --force Use this option to force execution of the command    
                         against a cluster that is currently unhealthy.     
-h, --help Show help                                            
-i, --interactive                                                           
-s, --silent Show minimal output                                  
* -u, --username The username of the user whose password will be reset
--url the URL where the elasticsearch node listens for     
                         connections.                                       
-v, --verbose Show verbose output                                  
ERROR: Missing required option(s) [u/username]

```

The error message says that the parameter `-u`, for the username you want to reset the password, must be provided, but this is not mentioned in the documentation.

Running using the parameter `--auto` provides the same error.

If I pass the username, then it works as expected and I'm able to reset the password for the built-in users needed, `elastic` e `kibana_system`.

Shouldn't this be mentioned in the documentation? Running `elasticsearch-reset-password auto` does not work as the documentation says it should work.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 3, 2022, 2:38am UTC](https://discuss.elastic.co/t/manually-configure-security-divergence-in-the-documentation/315601/2 "2022-10-03T02:38:35Z")

</div>

This is the doc bug. The command utility in this page is meant to be [`elasticsearch-setup-passwords`](https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-passwords.html) instead of `elasticsearch-reset-password`.

The `elasticsearch-reset-password` CLI is new in 8.x and in fact more flexibile. So you can totally use it instead but it requires the `-u` parameter as you have already discovered. I raised a [PR](https://github.com/elastic/elasticsearch/pull/90579) to fix the doc. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2022, 2:39am UTC](https://discuss.elastic.co/t/manually-configure-security-divergence-in-the-documentation/315601/3 "2022-10-31T02:39:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
