# Setting passwords of builtin users to crypts

**URL:** <https://discuss.elastic.co/t/setting-passwords-of-builtin-users-to-crypts/201406>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 27, 2019, 1:40pm UTC](https://discuss.elastic.co/t/setting-passwords-of-builtin-users-to-crypts/201406 "2019-09-27T13:40:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nicolai](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolai/32/55008_2.png) [@nicolai](https://discuss.elastic.co/u/nicolai)\
**Post date:** [September 27, 2019, 1:40pm UTC](https://discuss.elastic.co/t/setting-passwords-of-builtin-users-to-crypts/201406/1 "2019-09-27T13:40:46Z")

</div>

I'm working on chef recipes to install elasticsearch 7 (7.2.1) with all kinds of security enabled. I've gotten it to make self signed certificates. I've run the `elasticsearch-setup-passwords` to set the passwords of the system (reserved) accounts. And found the `/_security/user/jacknich/_password` API to set passwords. But I can't seem to find a way to give elasticsearch a crypt instead of a plaintext password when setting the passwords of the system accounts so that I don't need to store the passwords in plain text anywhere in chef.

I've found that I can define other users in a `file` store but elasticsearch protests loudly when I try to put any reserved user names in there.

So, any way I can put crypts into elasticsearch to set system account passwords?

Nicolai

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 29, 2019, 9:54am UTC](https://discuss.elastic.co/t/setting-passwords-of-builtin-users-to-crypts/201406/2 "2019-09-29T09:54:21Z")

</div>

Unfortunately there is nothing that satisfies your use case. The only API that allows you to pass a salted cryptographic hash of the the password instead of the plaintext password is the [Create or Update Users API](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/security-api-put-user.html) and this can't be used to update password of the [`built-in` users](https://www.elastic.co/guide/en/elastic-stack-overview/7.3/built-in-users.html).

We could support a password hash as input for our Change Password API, but frankly this has never been asked before AFAIK and there are currently no plans to introduce this functionality.

---

<div class="post-metadata">

**Author:** ![nicolai](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolai/32/55008_2.png) [@nicolai](https://discuss.elastic.co/u/nicolai)\
**Post date:** [October 25, 2019, 8:03am UTC](https://discuss.elastic.co/t/setting-passwords-of-builtin-users-to-crypts/201406/3 "2019-10-25T08:03:19Z")

</div>

Thanks for your answer.

To explain my use case: Storing system plaintext passwords in a secure location and restricting the distribution of them is good security policy. Therefore I would like to avoid putting the plaintext password into Chef. This works perfectly for unix user accounts, mysql accounts, and many other things, because you can create accounts or change passwords using the crypted passwords instead of the plaintext.

Thanks,  
Nicolai

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2019, 8:03am UTC](https://discuss.elastic.co/t/setting-passwords-of-builtin-users-to-crypts/201406/4 "2019-11-22T08:03:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
