# Unable to setup first time password for the new cluster

**URL:** <https://discuss.elastic.co/t/unable-to-setup-first-time-password-for-the-new-cluster/188941>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 4, 2019, 3:23pm UTC](https://discuss.elastic.co/t/unable-to-setup-first-time-password-for-the-new-cluster/188941 "2019-07-04T15:23:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dumkaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dumkaz/32/49228_2.png) [@dumkaz](https://discuss.elastic.co/u/dumkaz)\
**Post date:** [July 4, 2019, 3:23pm UTC](https://discuss.elastic.co/t/unable-to-setup-first-time-password-for-the-new-cluster/188941/1 "2019-07-04T15:23:15Z")

</div>

I install brand new elasticsearch 7.1.1 cluster using saltstack.  
I start from 3 master nodes and they properly provisioned and from cluster.  
After that i want to set-up passwords for built-in users, before provisioning data nodes by running

> Blockquote  
> /usr/share/elasticsearch/bin/elasticsearch-setup-passwords auto -u '[http://127.0.0.1:9200](http://127.0.0.1:9200)'  
> /Blockquote

and this is what i receive:

> Blockquote  
> root@es-master1:~# /usr/share/elasticsearch/bin/elasticsearch-setup-passwords auto -u '[http://127.0.0.1:9200](http://127.0.0.1:9200)'  
> Initiating the setup of passwords for reserved users elastic,apm\_system,kibana,logstash\_system,beats\_system,remote\_monitoring\_user.  
> The passwords will be randomly generated and printed to the console.  
> Please confirm that you would like to continue [y/N]y  
> Connection failure to: [http://127.0.0.1:9200/\_security/user/apm\_system/\_password?pretty](http://127.0.0.1:9200/_security/user/apm_system/_password?pretty) failed: Read timed out  
> ERROR: Failed to set password for user [apm\_system].  
> Blockquote

Master node configuration:  
#======================== Elasticsearch Configuration =========================  
cluster.name: ad-test  
node.name: es-master1  
node.master: True  
node.data: False  
node.ingest: True  
path.logs: /var/log/elasticsearch  
path.data: /var/lib/elasticsearch  
xpack.security.enabled: True  
xpack.monitoring.collection.enabled: True  
xpack.security.transport.ssl.enabled: True  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.keystore.path: certs/ad-test-certificate.p12  
xpack.security.transport.ssl.truststore.path: certs/ad-test-certificate.p12  
bootstrap.memory\_lock: True  
network.host: 0.0.0.0  
cluster.initial\_master\_nodes: [172.31.192.78, 172.31.192.91, 172.31.192.103]  
discovery.seed\_hosts: [172.31.192.78, 172.31.192.91, 172.31.192.103]

Before i run command to setup default users password i see the following errors in cluster.log

> Blockquote  
> [2019-07-04T15:21:26,745][WARN][o.e.x.m.e.l.LocalExporter] [es-master1] unexpected error while indexing monitoring document  
> org.elasticsearch.xpack.monitoring.exporter.ExportException: UnavailableShardsException[[.monitoring-es-7-2019.07.04][0] primary shard is not active Timeout: [1m], request: [BulkShardRequest [[.monitoring-es-7-2019.07.04][0]] containing [4] requests]]  
> at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.action.support.replication.TransportReplicationAction$ReroutePhase$2.onTimeout(TransportReplicationAction.java:928) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.cluster.ClusterStateObserver$ContextPreservingListener.onTimeout(ClusterStateObserver.java:322) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.cluster.ClusterStateObserver$ObserverClusterStateListener.onTimeout(ClusterStateObserver.java:249) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.cluster.service.ClusterApplierService$NotifyTimeout.run(ClusterApplierService.java:555) [elasticsearch-7.1.1.jar:7.1.1]  
> at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:681) [elasticsearch-7.1.1.jar:7.1.1]  
> at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) [?:?]  
> at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) [?:?]  
> at java.lang.Thread.run(Thread.java:835) [?:?]  
> Caused by: org.elasticsearch.action.UnavailableShardsException: [.monitoring-es-7-2019.07.04][0] primary shard is not active Timeout: [1m], request: [BulkShardRequest [[.monitoring-es-7-2019.07.04][0]] containing [4] requests]  
> Blockquote

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [July 4, 2019, 3:35pm UTC](https://discuss.elastic.co/t/unable-to-setup-first-time-password-for-the-new-cluster/188941/2 "2019-07-04T15:35:07Z")

</div>

Hi @dumkaz,

Could you please post the output for the [`GET _cluster/health` API](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-health.html)

Thanks and Regards,  
Yogesh Gaikwad

---

<div class="post-metadata">

**Author:** ![dumkaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dumkaz/32/49228_2.png) [@dumkaz](https://discuss.elastic.co/u/dumkaz)\
**Post date:** [July 4, 2019, 3:36pm UTC](https://discuss.elastic.co/t/unable-to-setup-first-time-password-for-the-new-cluster/188941/3 "2019-07-04T15:36:56Z")

</div>

@Yogesh_Gaikwad  
t won`t work, as something went wrong with setting password for default users.  
but anyway:  
curl -XGET [http://127.0.0.1:9200/\_cluster/health](http://127.0.0.1:9200/_cluster/health)  
{"error":{"root\_cause":[{"type":"security\_exception","reason":"missing authentication credentials for REST request [/\_cluster/health]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}}],"type":"security\_exception","reason":"missing authentication credentials for REST request [/\_cluster/health]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}},"status":401}

---

<div class="post-metadata">

**Author:** ![dumkaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dumkaz/32/49228_2.png) [@dumkaz](https://discuss.elastic.co/u/dumkaz)\
**Post date:** [July 4, 2019, 4:05pm UTC](https://discuss.elastic.co/t/unable-to-setup-first-time-password-for-the-new-cluster/188941/4 "2019-07-04T16:05:13Z")

</div>

using interactive mode on brand new cluster gives the same error  
Please confirm that you would like to continue [y/N]y

Enter password for [elastic]:  
Reenter password for [elastic]:  
Enter password for [apm\_system]:  
Reenter password for [apm\_system]:  
Enter password for [kibana]:  
Reenter password for [kibana]:  
Enter password for [logstash\_system]:  
Reenter password for [logstash\_system]:  
Enter password for [beats\_system]:  
Reenter password for [beats\_system]:  
Enter password for [remote\_monitoring\_user]:  
Reenter password for [remote\_monitoring\_user]:

Connection failure to: [http://127.0.0.1:9200/\_security/user/apm\_system/\_password?pretty](http://127.0.0.1:9200/_security/user/apm_system/_password?pretty) failed: Read timed out

ERROR: Failed to set password for user [apm\_system].

---

<div class="post-metadata">

**Author:** ![dumkaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dumkaz/32/49228_2.png) [@dumkaz](https://discuss.elastic.co/u/dumkaz)\
**Post date:** [July 4, 2019, 4:31pm UTC](https://discuss.elastic.co/t/unable-to-setup-first-time-password-for-the-new-cluster/188941/5 "2019-07-04T16:31:26Z")

</div>

I think I have found the problem: redeploying right now with data nodes

> <https://github.com/elastic/elasticsearch/issues/38261>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2019, 4:31pm UTC](https://discuss.elastic.co/t/unable-to-setup-first-time-password-for-the-new-cluster/188941/6 "2019-08-01T16:31:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
