# ●\[TLS\] How to resolve the security concern of writing plaintext usernames and passwords in the yml file

**URL:** <https://discuss.elastic.co/t/tls-how-to-resolve-the-security-concern-of-writing-plaintext-usernames-and-passwords-in-the-yml-file/350626>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [January 9, 2024, 6:55am UTC](https://discuss.elastic.co/t/tls-how-to-resolve-the-security-concern-of-writing-plaintext-usernames-and-passwords-in-the-yml-file/350626 "2024-01-09T06:55:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![YUUTA.INOUE-JPN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuuta.inoue-jpn/32/117963_2.png) [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Post date:** [January 9, 2024, 6:55am UTC](https://discuss.elastic.co/t/tls-how-to-resolve-the-security-concern-of-writing-plaintext-usernames-and-passwords-in-the-yml-file/350626/1 "2024-01-09T06:55:07Z")

</div>

I have a question about https communication (encryption) between "client PC ←→ Elasticsearch server" & "Kibana server ←→ Elasticsearch server".  
We are concerned that username/password information may be leaked by specifying and writing plain text passwords in his yml files for `winlogbeat'' and `kibana.''  
Please tell me how to perform https communication (encryption) without specifying the plaintext password in the yml file.

▼Settings file  
winlogbeat.yml  
kibana.yml

▼Setting items  
elasticsearch.username  
elasticsearch.password

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 9, 2024, 5:32pm UTC](https://discuss.elastic.co/t/tls-how-to-resolve-the-security-concern-of-writing-plaintext-usernames-and-passwords-in-the-yml-file/350626/2 "2024-01-09T17:32:33Z")

</div>

> [@YUUTA.INOUE-JPN](#):
>
> I have a question about https communication (encryption) between "client PC ←→ Elasticsearch server" & "Kibana server ←→ Elasticsearch server".  
> We are concerned that username/password information may be leaked by specifying and writing plain text passwords in his yml files for `winlogbeat'' and `kibana.''  
> Please tell me how to perform https communication (encryption) without specifying the plaintext password in the yml file.
> 
> ▼Settings file  
> winlogbeat.yml  
> kibana.yml
> 
> ▼Setting items  
> elasticsearch.username  
> elasticsearch.password

Hi,

You can create a secure setting in the Elasticsearch keystore. For example, to add a secure setting for the Elasticsearch password, you can use the following command:

```auto
./bin/elasticsearch-keystore add xpack.security.http.ssl.secure_password

```

You'll be prompted to enter the password.

In your `winlogbeat.yml` and `kibana.yml` files, replace the plaintext password with the reference to the secure setting:

```auto
elasticsearch.password: "${xpack.security.http.ssl.secure_password}"

```

Restart Elasticsearch and Winlogbeat/Kibana for the changes to take effect.

Regards

---

<div class="post-metadata">

**Author:** ![YUUTA.INOUE-JPN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuuta.inoue-jpn/32/117963_2.png) [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Post date:** [January 10, 2024, 1:33am UTC](https://discuss.elastic.co/t/tls-how-to-resolve-the-security-concern-of-writing-plaintext-usernames-and-passwords-in-the-yml-file/350626/3 "2024-01-10T01:33:36Z")

</div>

Hi Yago82 !  
Thank you for your reply !  
Your advice would be greatly appreciated by me.  
I will check this command.

If you don't mind, I would like to see the official documentation and URL of the site that describes this method. Could you please help me?  
Best regards  
Thank you

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 10, 2024, 4:20am UTC](https://discuss.elastic.co/t/tls-how-to-resolve-the-security-concern-of-writing-plaintext-usernames-and-passwords-in-the-yml-file/350626/4 "2024-01-10T04:20:49Z")

</div>

@YUUTA.INOUE-JPN Here you go

> **[Secrets keystore for secure settings | Winlogbeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/winlogbeat/current/keystore.html)**

---

<div class="post-metadata">

**Author:** ![YUUTA.INOUE-JPN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuuta.inoue-jpn/32/117963_2.png) [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Post date:** [January 10, 2024, 6:15am UTC](https://discuss.elastic.co/t/tls-how-to-resolve-the-security-concern-of-writing-plaintext-usernames-and-passwords-in-the-yml-file/350626/5 "2024-01-10T06:15:30Z")

</div>

Stephenb san （In Japan, we add "san" to the names of people who are respect us. ）  
Thank you for your reply.  
I remember you.  
Thank you for helping me with the ILM matter previously.  
Thanks again for providing me with the documentation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2024, 6:15am UTC](https://discuss.elastic.co/t/tls-how-to-resolve-the-security-concern-of-writing-plaintext-usernames-and-passwords-in-the-yml-file/350626/6 "2024-02-07T06:15:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
