# Populating user credentials to all nodes in cluster

**URL:** <https://discuss.elastic.co/t/populating-user-credentials-to-all-nodes-in-cluster/42536>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 24, 2016, 12:03am UTC](https://discuss.elastic.co/t/populating-user-credentials-to-all-nodes-in-cluster/42536 "2016-02-24T00:03:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![megaforce1020](https://avatars.discourse-cdn.com/v4/letter/m/ecae2f/32.png) [@megaforce1020](https://discuss.elastic.co/u/megaforce1020)\
**Post date:** [February 24, 2016, 12:03am UTC](https://discuss.elastic.co/t/populating-user-credentials-to-all-nodes-in-cluster/42536/1 "2016-02-24T00:03:24Z")

</div>

Hi, so I am fairly new to the Elastic Stack. I've setup a cluster of elasticsearch nodes (Masters, Datas, Clients). I also have Kibana setup as well. Both Elasticsearch and Kibana have Shield installed on their respective nodes. The issue that I am running into is that I need to create Kibana4 users so that people can login to Kibana Web Interface. If I create the user on the Elasticsearch client node that Kibana4 is pointed to, they can login. If I create the user on a Elasticsearch Master that Kibana is not pointed to, they cannot login. Is there a way for me to create the users on a Elasticsearch node and have that populate to all servers in the cluster? Thanks!

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [February 24, 2016, 6:58pm UTC](https://discuss.elastic.co/t/populating-user-credentials-to-all-nodes-in-cluster/42536/2 "2016-02-24T18:58:10Z")

</div>

Hi Kevin,

Today, as an administrator of a Shield protected Elasticsearch cluster, it is up to you to keep the users, roles, and user-role mapping files in sync across _all nodes_ in the cluster. This is not optional - you cannot just add a user to one node, but not another; it won't be secure.

As you might imagine, we are working on a proper API, which includes seamless distribution of configuration across all nodes. This is planned for a near-term release, and will make this much easier.

In the mean time, you will need to keep the configuration in sync on all nodes.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![megaforce1020](https://avatars.discourse-cdn.com/v4/letter/m/ecae2f/32.png) [@megaforce1020](https://discuss.elastic.co/u/megaforce1020)\
**Post date:** [February 24, 2016, 9:27pm UTC](https://discuss.elastic.co/t/populating-user-credentials-to-all-nodes-in-cluster/42536/3 "2016-02-24T21:27:46Z")

</div>

That is exactly the answer I was looking for. Okay, I will do that then. Thanks skearns! I look forward to the next release for the seamless distribution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/populating-user-credentials-to-all-nodes-in-cluster/42536/4 "2017-07-06T13:46:28Z")

</div>


