# Scripting password setup after install

**URL:** <https://discuss.elastic.co/t/scripting-password-setup-after-install/201535>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 29, 2019, 3:00pm UTC](https://discuss.elastic.co/t/scripting-password-setup-after-install/201535 "2019-09-29T15:00:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![fmstrat](https://avatars.discourse-cdn.com/v4/letter/f/f1d935/32.png) [@fmstrat](https://discuss.elastic.co/u/fmstrat)\
**Post date:** [September 29, 2019, 3:00pm UTC](https://discuss.elastic.co/t/scripting-password-setup-after-install/201535/1 "2019-09-29T15:00:14Z")

</div>

Hi all,

I'm trying to figure out how to script setup of passwords. I'm using the below:

```auto
printf "password" | elasticsearch-keystore add "boostrap.password"
curl -uelastic:"password" -XPUT -H 'Content-Type: application/json' 'http://localhost:9200/_xpack/security/user/kibana/_password' -d '{ "password":"password" }'

```

However, the result I get from the `curl` call is:

```auto
{"error":{"root_cause":[{"type":"security_exception","reason":"failed to authenticate user [elastic]","header":{"WWW-Authenticate":"Basic realm=\"security\" charset=\"UTF-8\""}}],"type":"security_exception","reason":"failed to authenticate user [elastic]","header":{"WWW-Authenticate":"Basic realm=\"security\" charset=\"UTF-8\""}},"status":401}

```

This is based on the @TimV supplied this answer back in 2018, but it seems to no longer work with ES7.3.0: [How to set passwords for built-in users in batch mode?](https://discuss.elastic.co/t/how-to-set-passwords-for-built-in-users-in-batch-mode/119655/6)

It seems that `elasticsearch-setup-passwords` is supposed to have a `-b` flag to batch run, but while it's in the documentation ([https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-passwords.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-passwords.html)) it does not actually exist in the command.

Thanks!

---

<div class="post-metadata">

**Author:** ![fmstrat](https://avatars.discourse-cdn.com/v4/letter/f/f1d935/32.png) [@fmstrat](https://discuss.elastic.co/u/fmstrat)\
**Post date:** [September 29, 2019, 3:16pm UTC](https://discuss.elastic.co/t/scripting-password-setup-after-install/201535/2 "2019-09-29T15:16:27Z")

</div>

I seem to able to do it by installing `expect` and using the below script, but this doesn't seem like the best way to handle things.

```auto
#!/usr/bin/expect -f
 
set timeout -1
spawn bin/elasticsearch-setup-passwords interactive
expect "N]"
send -- "y\n"
expect "elastic]: "
send -- "password\n"
expect "elastic]: "
send -- "password\n"
expect "apm_system]: " 
send -- "password\n"
expect "apm_system]: " 
send -- "password\n"
expect "kibana]: "
send -- "password\n"
expect "kibana]: "
send -- "password\n"
expect "logstash_system]: "
send -- "password\n"
expect "logstash_system]: "
send -- "password\n"
expect "beats_system]: "
send -- "password\n"
expect "beats_system]: "
send -- "password\n"
expect "remote_monitoring_user]: "
send -- "password\n"
expect "remote_monitoring_user]: "
send -- "password\n"
expect eof

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 30, 2019, 6:16am UTC](https://discuss.elastic.co/t/scripting-password-setup-after-install/201535/3 "2019-09-30T06:16:22Z")

</div>

> [@fmstrat](#):
>
> This is based on the @TimV supplied this answer back in 2018, but it seems to no longer work with ES7.3.0: [How to set passwords for built-in users in batch mode?](https://discuss.elastic.co/t/how-to-set-passwords-for-built-in-users-in-batch-mode/119655/6)

This process still works just fine, so I would assume that something went wrong when you attempted to run the commands you share. The [`bootstrap.password`](https://www.elastic.co/guide/en/elastic-stack-overview/current/built-in-users.html#bootstrap-elastic-passwords) is only taken into consideration when the `elastic` user _doesn't already_ have a password.

Do you get any error messages when running the `elasticsearch-keystore-add` command ? Can you verify that `bootstrap.password` is in the keystore with `elasticsearch-keystore-list` ?

> [@fmstrat](#):
>
> It seems that `elasticsearch-setup-passwords` is supposed to have a `-b` flag to batch run, but while it's in the documentation ([elasticsearch-setup-passwords | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-passwords.html)) it does not actually exist in the command.

It does exist but what it does is that it prevents the CLI from outputting verification messages to the user. You wouldn't be able to use a CLI tool in interactive mode if it doesn't prompt you for input 🙂

> [@fmstrat](#):
>
> I seem to able to do it by installing `expect` and using the below script, but this doesn't seem like the best way to handle things.

As Tim mentioned in the original post, the `elasticsearch-setup-password` is not designed to be scriptable, so the proper way to achieve what you are after is the original suggestion.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [October 3, 2019, 10:56am UTC](https://discuss.elastic.co/t/scripting-password-setup-after-install/201535/4 "2019-10-03T10:56:33Z")

</div>

> printf "password" | elasticsearch-keystore add "boostrap.password"

You have misspelt `bootstrap` here, and you need to pass `-x` to `elasticsearch-keystore add` if you want it to read from stdin.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2019, 10:56am UTC](https://discuss.elastic.co/t/scripting-password-setup-after-install/201535/5 "2019-10-31T10:56:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
