# Setup-Passwords script fails when ssl.keystore.password is not set

**URL:** <https://discuss.elastic.co/t/setup-passwords-script-fails-when-ssl-keystore-password-is-not-set/118350>\
**Category:** Elasticsearch\
**Created:** [February 4, 2018, 3:34pm UTC](https://discuss.elastic.co/t/setup-passwords-script-fails-when-ssl-keystore-password-is-not-set/118350 "2018-02-04T15:34:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jupp](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jupp](https://discuss.elastic.co/u/jupp)\
**Post date:** [February 4, 2018, 3:34pm UTC](https://discuss.elastic.co/t/setup-passwords-script-fails-when-ssl-keystore-password-is-not-set/118350/1 "2018-02-04T15:34:25Z")

</div>

Hi All,

i installed ES 6.1.3 with X-Pack. The Steps:

1. generate CA (with the Certutil)

2. generate certs for each node signed y the CA in a pkc12 keystore with a password set.

3. copied Elasticsearch on each node (tar.gz)

4. used elasticsearch-keystore to set the pkcs12 keystore-password

5. start all nodes - \> all fine, the cluster is formed and the master is elected

6. calling setup-passwords gives me following exception:

It seems that the password for the Keystore ist incorrect but the nodes have formed the cluster so this could not be.

OK than i did following:

1. Stop the Node

2. Add the setting (xpack.ssl.keystore.password) to the elasticsearch.yml

3. Start the node

4. Calling setup-password now works, the passwords are set, but i get following deprecation-message:

So, i am a bit confused. Why it isn't enough to set the "secure\_password" - maybe it is a bug?  
I did'n find the deprecation in the "breaking changes" section of ES 7.0 or x-pack.

For all Calls is source our environment (to set ES\_PATH\_CONF and so on...) and set JAVA\_HOME. We use jdk 1.8.

Has someone an idea?

Greetings,

Jupp

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 6, 2018, 4:10am UTC](https://discuss.elastic.co/t/setup-passwords-script-fails-when-ssl-keystore-password-is-not-set/118350/2 "2018-02-06T04:10:00Z")

</div>

> [@jupp](#):
>
> Why it isn't enough to set the "secure\_password" - maybe it is a bug?

It is a bug. `setup-passwords` only reads from the `elasticsearch.yml` and not from `elasticsearch.keystore`. We will fix that in an upcoming release.

---

<div class="post-metadata">

**Author:** ![jupp](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jupp](https://discuss.elastic.co/u/jupp)\
**Post date:** [February 6, 2018, 8:53pm UTC](https://discuss.elastic.co/t/setup-passwords-script-fails-when-ssl-keystore-password-is-not-set/118350/3 "2018-02-06T20:53:03Z")

</div>

OK, thanks for the info. I think since this is X-Pack, there won't be a bug number that I can track - will there?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 7, 2018, 12:33am UTC](https://discuss.elastic.co/t/setup-passwords-script-fails-when-ssl-keystore-password-is-not-set/118350/4 "2018-02-07T00:33:56Z")

</div>

No, there is no publically available issue to track.  
For now you'll just need to keep an eye on release notes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2018, 12:34am UTC](https://discuss.elastic.co/t/setup-passwords-script-fails-when-ssl-keystore-password-is-not-set/118350/5 "2018-03-07T00:34:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
