# Unable to setup elastic stack in docker with tls enabled

**URL:** <https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734>\
**Category:** Elasticsearch\
**Created:** [December 21, 2019, 12:07pm UTC](https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734 "2019-12-21T12:07:56Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![pythonredhat](https://avatars.discourse-cdn.com/v4/letter/p/ec9cab/32.png) [@pythonredhat](https://discuss.elastic.co/u/pythonredhat)\
**Post date:** [December 21, 2019, 12:07pm UTC](https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734/1 "2019-12-21T12:07:56Z")

</div>

Followed these instructions verbatim:  
[https://www.elastic.co/guide/en/elastic-stack-get-started/7.5/get-started-docker.html#get-started-docker-tls](https://www.elastic.co/guide/en/elastic-stack-get-started/7.5/get-started-docker.html#get-started-docker-tls)

This issue is when you attempt to setup passwords this is the error received:

```auto
Failed to authenticate user 'elastic' against https://es01:9200/_security/_authenticate?pretty
Possible causes include:
 * The password for the 'elastic' user has already been changed on this cluster
 * Your elasticsearch node is running against a different keystore
   This tool used the keystore at /usr/share/elasticsearch/config/elasticsearch.keystore

ERROR: Failed to verify bootstrap password

```

I have tried for over two weeks tweaking the configuration, the certs, the container, the permissions. Please review these instructions. I am dying to know the answer to reset a password on this service.

---

<div class="post-metadata">

**Author:** ![pythonredhat](https://avatars.discourse-cdn.com/v4/letter/p/ec9cab/32.png) [@pythonredhat](https://discuss.elastic.co/u/pythonredhat)\
**Post date:** [December 21, 2019, 12:15pm UTC](https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734/2 "2019-12-21T12:15:10Z")

</div>

Also setting the environmental variable for ELASTIC\_PASSWORD in the docker-compose file doesn't work at all. How come this functionality doesn't work?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 21, 2019, 1:34pm UTC](https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734/3 "2019-12-21T13:34:05Z")

</div>

It works for me very well.

Here is the `docker-compose.yml` file I'm using:

```auto
---
version: '3'
services:

  elasticsearch:
    image: docker.elastic.co/elasticsearch/elasticsearch:7.5.1
    environment:
      - bootstrap.memory_lock=true
      - discovery.type=single-node
      - ELASTIC_PASSWORD=changeme
      - xpack.security.enabled=true
    ulimits:
      memlock:
        soft: -1
        hard: -1
    ports:
      - 9200:9200
    networks: ['stack']

  kibana:
    image: docker.elastic.co/kibana/kibana:7.5.1
    environment:
      - ELASTICSEARCH_USERNAME=elastic
      - ELASTICSEARCH_PASSWORD=changeme
    ports: ['5601:5601']
    networks: ['stack']
    links: ['elasticsearch']
    depends_on: ['elasticsearch']

networks:
  stack: {}

```

---

<div class="post-metadata">

**Author:** ![pythonredhat](https://avatars.discourse-cdn.com/v4/letter/p/ec9cab/32.png) [@pythonredhat](https://discuss.elastic.co/u/pythonredhat)\
**Post date:** [December 21, 2019, 2:34pm UTC](https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734/4 "2019-12-21T14:34:53Z")

</div>

David I am looking for a config that incorporates TLS certs with Xpack in Docker containers. Your configuration doesn't appear to be utilizing certificates. Any experience with this?

---

<div class="post-metadata">

**Author:** ![pythonredhat](https://avatars.discourse-cdn.com/v4/letter/p/ec9cab/32.png) [@pythonredhat](https://discuss.elastic.co/u/pythonredhat)\
**Post date:** [December 21, 2019, 2:36pm UTC](https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734/5 "2019-12-21T14:36:02Z")

</div>

Error message in Elastic container when attempting to set the passwords:

```auto
es01 | {"type": "server", "timestamp": "2019-12-14T21:38:28,670Z", "level": "INFO", "component": "o.e.x.s.a.AuthenticationService", "cluster.name": "docker-cluster", "node.name": "es01", "message": "Authentication of [elastic] was terminated by realm [reserved] - failed to authenticate user [elastic]", "cluster.uuid": "38P8BUwoRymc8niNyYIfuQ", "node.id": "HznRQrvZTmuk-EGr6EBqtA" }

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 21, 2019, 3:07pm UTC](https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734/6 "2019-12-21T15:07:44Z")

</div>

No. I don't.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 21, 2019, 3:08pm UTC](https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734/7 "2019-12-21T15:08:17Z")

</div>

Did you start with a clean data volume?

---

<div class="post-metadata">

**Author:** ![pythonredhat](https://avatars.discourse-cdn.com/v4/letter/p/ec9cab/32.png) [@pythonredhat](https://discuss.elastic.co/u/pythonredhat)\
**Post date:** [December 21, 2019, 3:20pm UTC](https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734/8 "2019-12-21T15:20:22Z")

</div>

Yes started from scratch per these instructions:

[https://www.elastic.co/guide/en/elastic-stack-get-started/7.5/get-started-docker.html#get-started-docker-tls](https://www.elastic.co/guide/en/elastic-stack-get-started/7.5/get-started-docker.html#get-started-docker-tls)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2020, 3:20pm UTC](https://discuss.elastic.co/t/unable-to-setup-elastic-stack-in-docker-with-tls-enabled/212734/9 "2020-01-18T15:20:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
