# "Setting \[xpack.security.transport.ssl.keystore.secure\_password\] is a secure setting and must be stored inside the Elasticsearch keystore, but was found inside elasticsearch.yml

**URL:** <https://discuss.elastic.co/t/setting-xpack-security-transport-ssl-keystore-secure-password-is-a-secure-setting-and-must-be-stored-inside-the-elasticsearch-keystore-but-was-found-inside-elasticsearch-yml/356465>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [March 29, 2024, 2:42pm UTC](https://discuss.elastic.co/t/setting-xpack-security-transport-ssl-keystore-secure-password-is-a-secure-setting-and-must-be-stored-inside-the-elasticsearch-keystore-but-was-found-inside-elasticsearch-yml/356465 "2024-03-29T14:42:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sohaib\_El\_Mediouni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sohaib_el_mediouni/32/123391_2.png) [@Sohaib\_El\_Mediouni](https://discuss.elastic.co/u/Sohaib_El_Mediouni)\
**Post date:** [March 29, 2024, 2:42pm UTC](https://discuss.elastic.co/t/setting-xpack-security-transport-ssl-keystore-secure-password-is-a-secure-setting-and-must-be-stored-inside-the-elasticsearch-keystore-but-was-found-inside-elasticsearch-yml/356465/1 "2024-03-29T14:42:03Z")

</div>

Hello,

I have Elasticsearch based on a Red Hat image with 3 nodes in a StatefulSet, and Kibana in a deployment. Each Elasticsearch node has a PVC mounted in /usr/share/elasticsearch/data. I have generated the **elastic-stack-ca.p12 and the elastic-stack-ca.p12** , I have copied them into **/usr/share/elasticsearch/data** where my volume is mounted.  
but when i try to add the password in the keystore i lost it when the pod restarted and i got this error :  
"Setting [xpack.security.transport.ssl.keystore.secure\_password] is a secure setting and must be stored inside the Elasticsearch keystore, but was found inside elasticsearch.yml"

then pod is in a crash loop back-off  
this is my statefullSet :

```auto
kind: StatefulSet
apiVersion: apps/v1
metadata:
  name: elasticsearch
  namespace: 
  uid: 
  resourceVersion: 
  generation: 315
spec:
  replicas: 1
  selector:
    matchLabels:
      app: elasticsearch
  template:
    metadata:
      creationTimestamp: null
      labels:
        app: elasticsearch
    spec:
      volumes:
        - name: elastic-storage
          persistentVolumeClaim:
            claimName: elastic-storage
      containers:
        - resources:
            limits:
              cpu: '3'
              memory: 3Gi
            requests:
              cpu: 500m
              memory: 1Gi
          terminationMessagePath: /dev/termination-log
          lifecycle:
            postStart:
              exec:
                command:
                  - /bin/sh
                  - '-c'
                  - >

                    cp /usr/share/elasticsearch/data/elastic-certificates.p12
                    /usr/share/elasticsearch/config/

                    cp /usr/share/elasticsearch/data/elastic-stack-ca.p12
                    /usr/share/elasticsearch/config/

          name: elasticsearch
          env:
            - name: ingest.geoip.downloader.enabled
              value: 'false'
            - name: xpack.security.enabled
              value: 'true'
            - name: elasticsearch-xpack
              value: disabled
            - name: cluster.name
              value: Trafic-Cluster-Uat-Openshift
            - name: discovery.seed_hosts
              value: >-
                elasticsearch-0.elasticsearch-discovery,elasticsearch-1.elasticsearch-discovery
            - name: cluster.initial_master_nodes
              value: 'elasticsearch-0,elasticsearch-1'
            - name: xpack.monitoring.collection.enabled
              value: 'true'
            - name: xpack.security.transport.ssl.enabled
              value: 'false'
            - name: xpack.security.enrollment.enabled
              value: 'true'
            - name: xpack.security.transport.ssl.verification_mode
              value: certificate
            - name: xpack.security.transport.ssl.client_authentication
              value: required
            - name: xpack.security.transport.ssl.keystore.path
              value: /usr/share/elasticsearch/config/elastic-certificates.p12
            - name: xpack.security.transport.ssl.truststore.path
              value: /usr/share/elasticsearch/config/elastic-certificates.p12
          ports:
            - name: rest
              containerPort: 9200
              protocol: TCP
            - name: inter-node
              containerPort: 9300
              protocol: TCP
          imagePullPolicy: Always
          volumeMounts:
            - name: elasticsearch-storage
              mountPath: /usr/share/elasticsearch/data
          terminationMessagePolicy: File
          envFrom:
            - secretRef:
                name: truststore-password
            - secretRef:
                name: keystore-password
          image: >-
            openshift...com/elastic/elasticsearch:latest
      restartPolicy: Always
      terminationGracePeriodSeconds: 30
      dnsPolicy: ClusterFirst
      securityContext: {}
      schedulerName: default-scheduler
  volumeClaimTemplates:
    - kind: PersistentVolumeClaim
      apiVersion: v1
      metadata:
        name: elasticsearch-storage
        creationTimestamp: null
      spec:
        accessModes:
          - ReadWriteOnce
        resources:
          requests:
            storage: 10Gi
        volumeMode: Filesystem
      status:
        phase: Pending
  serviceName: elasticsearch-discovery
  podManagementPolicy: OrderedReady
  updateStrategy:
    type: RollingUpdate
    rollingUpdate:
      partition: 0
  revisionHistoryLimit: 10

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2024, 2:42pm UTC](https://discuss.elastic.co/t/setting-xpack-security-transport-ssl-keystore-secure-password-is-a-secure-setting-and-must-be-stored-inside-the-elasticsearch-keystore-but-was-found-inside-elasticsearch-yml/356465/2 "2024-04-26T14:42:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
