# Upgrade to x-pack failure, cannot set passwords

**URL:** <https://discuss.elastic.co/t/upgrade-to-x-pack-failure-cannot-set-passwords/130880>\
**Category:** Elasticsearch\
**Created:** [May 7, 2018, 5:21pm UTC](https://discuss.elastic.co/t/upgrade-to-x-pack-failure-cannot-set-passwords/130880 "2018-05-07T17:21:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rmac/32/30897_2.png) [@rmac](https://discuss.elastic.co/u/rmac)\
**Post date:** [May 7, 2018, 5:21pm UTC](https://discuss.elastic.co/t/upgrade-to-x-pack-failure-cannot-set-passwords/130880/1 "2018-05-07T17:21:47Z")

</div>

Per the opening of x-pack, I've tried to upgrade to it with my current cluster. I perhaps did not do enough research into what's involved but here I am.  
I have a trial license and ES version 6.1.

Here's what I did:

- Disabled shard routing allocation
- Performed a sync-flush
- Set indices to read-only (\<-- might be my problem)
- Stopped elasticsearch on all nodes, installed x-pack
- Set a bootstrap.password (`/usr/share/elasticsearch/bin/elasticsearch-keystore remove bootstrap-password --stdin`)
- Confirmed it was working with an `/_xpack/security/_authenticate/` request.
- `/usr/share/elasticsearch/bin/x-pack/setup-passwords interactive` timed out after prompting for passwords
- Basic authentication with bootstrap password now fails.
- All of the cluster is now down.

Logs I managed to pull without my brain exploding:

> <https://gist.github.com/Swashy/1e0609265196c71f77d5786cf7963f80>

Pretty stuck from where to go from here. Am I screwed with my data even if I upgrade to Elastic 6.2? Is the new open version of x-pack only available on 6.3?

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [May 7, 2018, 9:28pm UTC](https://discuss.elastic.co/t/upgrade-to-x-pack-failure-cannot-set-passwords/130880/2 "2018-05-07T21:28:46Z")

</div>

Hi @rmac,

> [@rmac](#):
>
> Stopped elasticsearch on all nodes, installed x-pack

Did you try to upgrade your cluster to 6.3?  
The open version of x-pack is available 6.3 onwards.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 8, 2018, 12:19am UTC](https://discuss.elastic.co/t/upgrade-to-x-pack-failure-cannot-set-passwords/130880/3 "2018-05-08T00:19:10Z")

</div>

Your cluster is not in good shape, but hopefully we can get you back up and running.

**Note** , as @Yogesh_Gaikwad has said, Open X-Pack will only be available in 6.3, and it will come pre-installed so your attempts to install X-Pack aren't going to achieve much.

Also, to be 100% clear, even with the Open X-Pack security is a commercial feature that requires a paid license. We strongly recommend enabling X-Pack security, but unless you purchase a gold or platinum [subscription](https://www.elastic.co/subscriptions) then you'll be limited to a 30 day trial and then need to disable security again.

What we need to do is get you access to your cluster again, so you can then set indices to read-write again and hopefully that will get your cluster back to green.

The simplest step you can take is to simply turn off security while you get things sorted. That will allow you to set the cluster settings back to normal (allow writes, allow allocation) and then you can try to setup passwords again. The bootstrap password process cannot run if your cluster is read-only (and will typically also fail if you disable allocation, but it depends on the exact details).

Add

```
xpack.security.enabled: false

```

into your `elasticsearch.yml` on every node, and restart.  
That _should_ resolve your issues. If not, please come back with updated logs.

---

<div class="post-metadata">

**Author:** ![rmac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rmac/32/30897_2.png) [@rmac](https://discuss.elastic.co/u/rmac)\
**Post date:** [May 8, 2018, 2:46pm UTC](https://discuss.elastic.co/t/upgrade-to-x-pack-failure-cannot-set-passwords/130880/4 "2018-05-08T14:46:56Z")

</div>

> [@TimV](#):
>
> xpack.security.enabled: false

Thank you very much! Didn't realize the x-pack could be manipulated through elasticsearch.yml, missed that setting in the docs

Is there a reference page in the docs that has all the directives I can declare in elasticsearch.yml for x-pack?

I've also removed x-pack and will wait patiently for 6.3. Sorry for my confusion...

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 9, 2018, 12:40am UTC](https://discuss.elastic.co/t/upgrade-to-x-pack-failure-cannot-set-passwords/130880/5 "2018-05-09T00:40:20Z")

</div>

> [@rmac](#):
>
> Is there a reference page in the docs that has all the directives I can declare in elasticsearch.yml for x-pack?

> **[X-Pack Settings | X-Pack for the Elastic Stack \[6.1\] | Elastic](https://www.elastic.co/guide/en/x-pack/6.1/xpack-settings.html)**

It splits by feature, so there's separate pages for security, monitoring, etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2018, 12:40am UTC](https://discuss.elastic.co/t/upgrade-to-x-pack-failure-cannot-set-passwords/130880/6 "2018-06-06T00:40:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
