# Where do we define the password for cert generated using elastic certutil in yml file?

**URL:** <https://discuss.elastic.co/t/where-do-we-define-the-password-for-cert-generated-using-elastic-certutil-in-yml-file/278448>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 12, 2021, 5:34pm UTC](https://discuss.elastic.co/t/where-do-we-define-the-password-for-cert-generated-using-elastic-certutil-in-yml-file/278448 "2021-07-12T17:34:07Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [July 12, 2021, 11:55pm UTC](https://discuss.elastic.co/t/where-do-we-define-the-password-for-cert-generated-using-elastic-certutil-in-yml-file/278448/2 "2021-07-12T23:55:18Z")

</div>

If the error is along the line of `not permitted to read ... file`, it is a file permission issue, not password issue. In this case, you need fix the file permission so the elasticsearch process can read it. You can find details in this [post](https://discuss.elastic.co/t/error-when-trying-to-setup-basic-security-for-the-elastic-stack/278473/2).

After fixing the file permission issue, you may run into the actual password issue since you haven't specified it anywhere. You can add that to the elasticsearch keystore with the command:

```auto
./bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure_password
./bin/elasticsearch-keystore add xpack.security.transport.ssl.truststore.secure_password

```

You can also check the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/7.13/security-basic-setup.html#encrypt-internode-communication) for details.

---

_[View the full topic](https://discuss.elastic.co/t/where-do-we-define-the-password-for-cert-generated-using-elastic-certutil-in-yml-file/278448)._
