# Not a valid Logstash keystore error

**URL:** <https://discuss.elastic.co/t/not-a-valid-logstash-keystore-error/159945>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [December 7, 2018, 2:37pm UTC](https://discuss.elastic.co/t/not-a-valid-logstash-keystore-error/159945 "2018-12-07T14:37:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sachintanpure85](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@sachintanpure85](https://discuss.elastic.co/u/sachintanpure85)\
**Post date:** [December 7, 2018, 2:37pm UTC](https://discuss.elastic.co/t/not-a-valid-logstash-keystore-error/159945/1 "2018-12-07T14:37:32Z")

</div>

Hi,

I am using ELK 6.3.2 version and I have used below configuration steps for logstash keystore

set +o history  
export LOGSTASH\_KEYSTORE\_PASS=mypassword  
set -o history  
logstash-keystore create  
logstash-keystore add user  
logstash-keystore add es\_pwd

and modifed logstash.yml as below :  
xpack.monitoring.elasticsearch.password: ${LOGSTASH\_KEYSTORE\_PASS}

and conf files as below:  
input {  
{elasticsearch{  
hosts =\> ["{LOGSTASH\_HOST}"] user =\> "{USER}"  
password =\> "${ES\_PWD}"  
ssl =\> true  
}  
}

Error :

[2018-12-05T05:40:29,568][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"Java::OrgLogstashSecretStore::SecretStoreException::LoadException", :message=\>"Found a file at /opt/guardian/conf/logstash/settings/logstash.keystore, but it is not a valid Logstash keystore.", :backtrace=\>["org.logstash.secret.store.backend.JavaKeyStore.load(org/logstash/secret/store/backend/JavaKeyStore.java:265)", "org.logstash.secret.store.backend.JavaKeyStore.load(org/logstash/secret/store/backend/JavaKeyStore.java:40)", "org.logstash.secret.store.SecretStoreFactory.doIt(org/logstash/secret/store/SecretStoreFactory.java:107)", "org.logstash.secret.store.SecretStoreFactory.load(org/logstash/secret/store/SecretStoreFactory.java:93)", "java.lang.reflect.Method.invoke(java/lang/reflect/Method.java:498)", "org.jruby.javasupport.JavaMethod…

can anybody help me on this?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 12, 2018, 7:30am UTC](https://discuss.elastic.co/t/not-a-valid-logstash-keystore-error/159945/2 "2018-12-12T07:30:15Z")

</div>

Hi there,

`LOGSTASH_KEYSTORE_PASS` environment variable holds the password with which the logstash keystore is encrypted and not the password for accessing your elasticsearch node so you most probably should not set it to

```auto
xpack.monitoring.elasticsearch.password: ${LOGSTASH_KEYSTORE_PASS}

```

The problem you are facing is because the running instance of logstash doesn't have access to the `LOGSTASH_KEYSTORE_PASS` environment variable and as such cannot load and decrypt the keystore. As mentioned in [our docs](https://www.elastic.co/guide/en/logstash/current/keystore.html) you need to make sure this environment variable is set and there are instructions [here](https://www.elastic.co/guide/en/logstash/current/keystore.html#keystore-password) on how to do this when using the `DEB` or `RPM` packages

---

<div class="post-metadata">

**Author:** ![sachintanpure85](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@sachintanpure85](https://discuss.elastic.co/u/sachintanpure85)\
**Post date:** [December 12, 2018, 11:32am UTC](https://discuss.elastic.co/t/not-a-valid-logstash-keystore-error/159945/3 "2018-12-12T11:32:34Z")

</div>

@ikakavas Thank you for your response.

I agree , after setting environment variable as LOGSTASH\_KEYSTORE\_PASS it will work .  
But without using logstash keystore also it will work , if we set the env variable .

Also the problem will be here as I do echo ${LOGSTASH\_KEYSTORE\_PASS} as I am using unix box, the password will be visible .

then its not secure way to configure password in environment files .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2019, 11:36am UTC](https://discuss.elastic.co/t/not-a-valid-logstash-keystore-error/159945/4 "2019-01-09T11:36:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
