# X-Pack Authentication issue

**URL:** <https://discuss.elastic.co/t/x-pack-authentication-issue/121632>\
**Category:** Elasticsearch\
**Created:** [February 27, 2018, 10:45am UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632 "2018-02-27T10:45:17Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Suryakumar](https://avatars.discourse-cdn.com/v4/letter/s/8c91f0/32.png) [@Suryakumar](https://discuss.elastic.co/u/Suryakumar)\
**Post date:** [February 27, 2018, 10:45am UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/1 "2018-02-27T10:45:17Z")

</div>

I have recently uninstalled and again reinstalled X-Pack. But when I followed the same tutorial used before, now I am getting error messages.

I have installed X-Pack with sudo permission. When I use the below command to generate password,

> bin/x-pack/setup-passwords auto

I am getting the following error message.

> Failed to authenticate user 'elastic' against [http://127.0.0.1:9200/\_xpack/security/\_authenticate?pretty](http://127.0.0.1:9200/_xpack/security/_authenticate?pretty)  
> Possible causes include:
> 
> - The password for the 'elastic' user has already been changed on this cluster
> - Your elasticsearch node is running against a different keystore  
> This tool used the keystore at /home/suryakumar/elasticsearch/config/elasticsearch.keystore

Please help me out!

I am using Ubuntu 16.04 LTS

Thanks,  
Suryakumar.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 27, 2018, 4:09pm UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/2 "2018-02-27T16:09:07Z")

</div>

I assume that you installed X-Pack, ran setup-passwords, and then uninstalled X-Pack, and then reinstalled X-Pack and are now trying to run setup-passwords again.

That doesn't work. When you uninstall X-Pack it does not remove the X-Pack data, so the passwords that you setup the first time through still exist.

---

<div class="post-metadata">

**Author:** ![dorj1234](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorj1234/32/21339_2.png) [@dorj1234](https://discuss.elastic.co/u/dorj1234)\
**Post date:** [February 28, 2018, 7:47am UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/3 "2018-02-28T07:47:37Z")

</div>

Tim - I have the same issue.  
You are correct in your assessment. But what is the solution? how can we reset the old passwords?

This is so frustrating to deal with, nothing works. Trying to setup passwords interactively doesn't work.  
Trying the API to change passwords fails because of keystore issues.

I saw your answer to this on [another thread](https://discuss.elastic.co/t/i-lost-the-password-that-has-been-changed/91867), great answer, thank you.  
In my case I get this error:  
`Security index is not on the current version. Security features relying on the index will not be available until the upgrade API is run on the security index`

Update: problem solved in my case after upgrading the indices (security indices) using [this link](https://www.elastic.co/guide/en/elastic-stack/6.2/upgrading-elastic-stack.html#upgrade-internal-indices).

All of this took 4 hours, lots of research and time wasted. I think the scenarios that happened here should be part of a QA session to get better error messages, and to handle things like upgrading the security indices automatically. I, as a user, should not even know this has taken place. Once I did the upgrade and installed x-pack, why do I need to learn (4 hours later) that the root of my issue is something that was not upgraded? how could I have known?

Thank you

---

<div class="post-metadata">

**Author:** ![Suryakumar](https://avatars.discourse-cdn.com/v4/letter/s/8c91f0/32.png) [@Suryakumar](https://discuss.elastic.co/u/Suryakumar)\
**Post date:** [March 2, 2018, 5:27am UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/4 "2018-03-02T05:27:17Z")

</div>

Tim,

Thank you for your reply! Yes I understood this is the problem and what is the solution for it? How can I proceed? Can you please elaborate the possible options?

Thanks in advance,  
Suryakumar.

---

<div class="post-metadata">

**Author:** ![HansCama](https://avatars.discourse-cdn.com/v4/letter/h/3ec8ea/32.png) [@HansCama](https://discuss.elastic.co/u/HansCama)\
**Post date:** [March 5, 2018, 3:45pm UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/5 "2018-03-05T15:45:10Z")

</div>

I have the same situation. Tried time ago to install x-pack. Issues on configuring / making it running. Then I removed it and now I'm giving another try, without success...

./setup-passwords interactive

Failed to authenticate user 'elastic' against [http://10.150.2.116:9302/\_xpack/security/\_authenticate?pretty](http://10.150.2.116:9302/_xpack/security/_authenticate?pretty)  
Possible causes include:

- The password for the 'elastic' user has already been changed on this cluster
- Your elasticsearch node is running against a different keystore  
This tool used the keystore at /opt/software/elasticsearch-6.1.2/config/elasticsearch.keystore

ERROR: Failed to verify bootstrap password

I've also done a reset of the user elastic:

/opt/software/elasticsearch-6.1.2/bin/x-pack/users useradd my\_admin -p my\_pwd -r superuser

curl -u my\_admin -XPUT '[http://kibana:9302/\_xpack/security/user/elastic/\_password?pretty](http://kibana:9302/_xpack/security/user/elastic/_password?pretty)' -H 'Content-Type: application/json' -d'  
{  
"password" : "newpassword"  
}  
'

How can be fixed it? Please, help.

Marco

---

<div class="post-metadata">

**Author:** ![dorj1234](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorj1234/32/21339_2.png) [@dorj1234](https://discuss.elastic.co/u/dorj1234)\
**Post date:** [March 5, 2018, 8:00pm UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/6 "2018-03-05T20:00:28Z")

</div>

@Suryakumar and @HansCama - did you happen to read the update on my reply? I solved my issue.  
The erros may actually be in the elastic-search logs. In my case, just like you @HansCama I uninstalled xpack and now tried it again. The link I used is on my updated post.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 8, 2018, 3:00am UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/7 "2018-03-08T03:00:21Z")

</div>

_This is a revised version of [this post](https://discuss.elastic.co/t/i-lost-the-password-that-has-been-changed/91867/2)_

## Help! I don't have the password for the `elastic` user!

### Pre-reading:

- The password setup in Elasticsearch 6.x depends on a "bootstrap password" that is set on each node in your cluster. This password is documented here:  
[https://www.elastic.co/guide/en/x-pack/6.2/setting-up-authentication.html#bootstrap-elastic-passwords](https://www.elastic.co/guide/en/x-pack/6.2/setting-up-authentication.html#bootstrap-elastic-passwords)  
If you do not have a fixed password for the `elastic` user, then it uses the bootstrap password.

- X-Pack security includes an API to change the password of a user. This is documented here:  
[https://www.elastic.co/guide/en/elasticsearch/reference/6.2/security-api-change-password.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/security-api-change-password.html)

### Before you start

_(This section was added July 2018 in response to seeing many mistakes from new users)_

Just because authentication fails, that does not mean that you have the wrong password. Before you do anything read the Elasticsearch logs. If you don't know how to read the Elasticsearch logs on your platform, then _find out how_.  
Launching into the steps below before you confirmed what is causing the problems is incredibly unwise and is unlikely to solve your problem.  
Obviously, authentication will fail if you don't know the correct password, but it can also fail for other reasons such as:

- you have a storage problem that prevents ES from reading the security data
- you have a network problem that prevents ES from forming a cluster

If authentication is suddenly failing for no clear reason then you want to try and work out _why_ before you start messing around with your cluster.

If you have an underlying infrastructure problem, then try and solve that first.  
If this is a genuine case of a forgotten password, then read on...

### Reseting the password for `elastic`

You have 4 options to resolve this, depending on the state of your cluster and what data you need to keep, and what data you're happy to throw away, and how much risk you're willing to take upon yourself.

**_Option 1 is the safest option, and the only that is recommended for production clusters._ The other options may be suitable for trial or proof-of-concept clusters with non-production usage.**

Only Option 1 is described here. Options 2, 3 and 4 are in a post below. If you care about your data, or you want to stick with officially supported options, then you should just read and follow option 1.

#### _Option 1:_ Create a new superuser

This options involves, creating an alternate _superuser_ and then authenticating as that user in order to change the password for _elastic_. This is safe to perform on production clusters.

Steps.

1. Shutdown every node in your Elasticsearch cluster.

2. Ensure that the _file_ realm is available on your nodes. If you are using a default X-Pack configuration for authentication, then the file realm is available and you don't need to do anything.  
However, if you have explicitly configured the [authentication realms](https://www.elastic.co/guide/en/x-pack/6.2/how-authc-works.html) in your `elasticsearch.yml` file, then you may need to [add a `file` realm](https://www.elastic.co/guide/en/x-pack/6.2/file-realm.html#_configuring_a_file_realm).  
If you do this, then you should add it to on every node.

3. Use the `bin/x-pack/users` command to [create a new file-based](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/users-command.html#_examples_76) superuser on every node:

4. Start all your nodes.

5. [Reset the password](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/security-api-change-password.html) for the elastic user:

6. Verify the new password

7. If you wish, stop elasticsearch and then remove the _file_ realm from your `elasticsearch.yml` and/or [remove](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/users-command.html#_examples_76) the `my_admin` user from the file realm.  
However, we do recommend that you keep this realm and user enabled, just in case you ever need to perform this sort of emergency maintenance in the future.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 8, 2018, 3:04am UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/8 "2018-03-08T03:04:56Z")

</div>

# WARNING WARNING WARNING

**These are not official supported methods.**  
**These steps may cause you to lose data that you care about.**  
**Please read the post above and follow _Option 1_ instead.**

Below are some other options for reseting the password for your `elastic` user.  
They all involve manual manipulation of your data, and if you do something wrong you may end up in a state that was worse than where you started. The **Create a new superuser** option listed in the previous post is safe, and is the only officially supported option for reseting the elastic user's password.

#### _Option 2:_ Delete all data

If you delete _all_ data from your elasticsearch cluster, this will also reset the `elastic` password as if you had a completely fresh cluster. The `elastic` user will reset to using the _bootstrap password_.

**_WARNING:_ Deleting all data means, _all data_. You will lose everything. Every index. Every template. Every Kibana visualisation/dashboard. Every user/role. Every ML job. Every watcher alert. _Everything goes away._ Only do this if you really want to start from scratch.**

Steps:

1. Shut down every node.
2. Go back and re-read the warning above. If you take the next step, then you will **lose all your data**.
3. Delete the `data` directory for every node. The [location of this directory](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/path-settings.html) depends on how you installed and configured Elasticsearch.
4. Start every node.
5. Your cluster is now empty, and the `elastic` user has been reset to use the _bootstrap password_.

#### _Option 3:_ Delete all security data

The data for security is stored in a special index called `.security-6` (this name applies to Elasticsearch 6.x. The details may vary between releases).  
If you delete this index, then you will reset all of the X-Pack security data, and this will mean that the `elastic` user can authenticate using the _bootstrap password_.

**_WARNING:_ Deleting the security index means that you lose _all of your security data_. Every user, role, role mapping, etc.** If you have created your own users roles in X-Pack security, then you probably don't want to follow this option.

**_WARNING:_ These steps include temporarily disabling security on your cluster. Don't do this on your production cluster. If you do this, then your cluster will be open and accessible to anyone that has network access to your cluster.**

Steps:

1. Shutdown every node in your cluster.
2. Go back and re-read _both_ of the warnings above. You are about **disable all security** on your cluster, and **remove all your users, roles, passwords, etc**. Do you really want to do this?
3. On each node, disable all security by setting

```auto
xpack.security.enabled: false

```

in the `elasticsearch.yml` configuration file.
4. Start your nodes.
5. Delete the `.security-6` index. You can do this with:

```auto
curl -XDELETE "http://localhost:9200/.security-6" 

```

Depending on your configuration, you may need to change the host/port.  
You only need to do this once regardless of how many nodes are in your cluster.
6. Stop all your nodes.
7. Enable security on your cluster by changing `xpack.security.enabled` to `true` in your `elasticsearch.yml` configuration file on every node.
8. Start your nodes.
9. Your cluster no longer has any security data and the `elastic` user has been reset to use the _bootstrap password_.

#### _Option 4:_ Delete the `elastic` user from your security data

The password for the `elastic` user is stored in a special document (`reserved-user-elastic`), in a special index called `.security-6`. (These names are applicable for Elasticsearch 6.x. The details may vary between releases).  
If you delete this document, then you will reset the elastic user back to its "uninitialised" state, which will means you can authenticate using the _bootstrap password_.

**_WARNING:_ This requires performing manual operations against the security index. We do not support this. If you get this wrong, then you could make life very difficult for yourself. Do not do this on a production cluster. Use at your own risk.**

**_WARNING:_ These steps include temporarily disabling security on your cluster. Don't do this on your production cluster. If you do this, then your cluster will be open and accessible to anyone that has network access to your cluster.**

Steps:

1. Shutdown every node in your cluster.
2. Go back and re-read _both_ of the warnings above. You are about **disable all security** on your cluster, and **make low level changes to your security data**. Do you really want to do this?
3. On each node, disable all security by setting

```auto
xpack.security.enabled: false

```

in the `elasticsearch.yml` configuration file.
4. Start your nodes.
5. Delete the `reserved-user-elastic` document from the `.security-6` index. You can do this with:

```auto
curl -XDELETE "http://localhost:9200/.security-6/doc/reserved-user-elastic" 

```

Depending on your configuration, you may need to change the host/port.  
You only need to do this once regardless of how many nodes are in your cluster.
6. Stop all your nodes.
7. Enable security on your cluster by changing `xpack.security.enabled` to `true` in your `elasticsearch.yml` configuration file on every node.
8. Start your nodes.
9. The `elastic` user has been reset to use the _bootstrap password_.

# WARNING WARNING WARNING

**These are not official supported methods.**  
**These steps may cause you to lose data that you care about.**  
**Please read the post above and follow _Option 1_ instead.**

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [March 8, 2018, 3:57am UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/9 "2018-03-08T03:57:00Z")

</div>

Did you try this Command if not then try its may be give something 🙂

bin/x-pack/setup-passwords auto -u "http://YOUR\_ELASTIC\_IP:9200"

Thanks & Regards,  
Krunal.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2018, 3:57am UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/10 "2018-04-05T03:57:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
