# X-Pack Authentication issue

**URL:** <https://discuss.elastic.co/t/x-pack-authentication-issue/121632>\
**Category:** Elasticsearch\
**Created:** [February 27, 2018, 10:45am UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632 "2018-02-27T10:45:17Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 8, 2018, 3:00am UTC](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/7 "2018-03-08T03:00:21Z")

</div>

_This is a revised version of [this post](https://discuss.elastic.co/t/i-lost-the-password-that-has-been-changed/91867/2)_

## Help! I don't have the password for the `elastic` user!

### Pre-reading:

- The password setup in Elasticsearch 6.x depends on a "bootstrap password" that is set on each node in your cluster. This password is documented here:  
[https://www.elastic.co/guide/en/x-pack/6.2/setting-up-authentication.html#bootstrap-elastic-passwords](https://www.elastic.co/guide/en/x-pack/6.2/setting-up-authentication.html#bootstrap-elastic-passwords)  
If you do not have a fixed password for the `elastic` user, then it uses the bootstrap password.

- X-Pack security includes an API to change the password of a user. This is documented here:  
[https://www.elastic.co/guide/en/elasticsearch/reference/6.2/security-api-change-password.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/security-api-change-password.html)

### Before you start

_(This section was added July 2018 in response to seeing many mistakes from new users)_

Just because authentication fails, that does not mean that you have the wrong password. Before you do anything read the Elasticsearch logs. If you don't know how to read the Elasticsearch logs on your platform, then _find out how_.  
Launching into the steps below before you confirmed what is causing the problems is incredibly unwise and is unlikely to solve your problem.  
Obviously, authentication will fail if you don't know the correct password, but it can also fail for other reasons such as:

- you have a storage problem that prevents ES from reading the security data
- you have a network problem that prevents ES from forming a cluster

If authentication is suddenly failing for no clear reason then you want to try and work out _why_ before you start messing around with your cluster.

If you have an underlying infrastructure problem, then try and solve that first.  
If this is a genuine case of a forgotten password, then read on...

### Reseting the password for `elastic`

You have 4 options to resolve this, depending on the state of your cluster and what data you need to keep, and what data you're happy to throw away, and how much risk you're willing to take upon yourself.

**_Option 1 is the safest option, and the only that is recommended for production clusters._ The other options may be suitable for trial or proof-of-concept clusters with non-production usage.**

Only Option 1 is described here. Options 2, 3 and 4 are in a post below. If you care about your data, or you want to stick with officially supported options, then you should just read and follow option 1.

#### _Option 1:_ Create a new superuser

This options involves, creating an alternate _superuser_ and then authenticating as that user in order to change the password for _elastic_. This is safe to perform on production clusters.

Steps.

1. Shutdown every node in your Elasticsearch cluster.

2. Ensure that the _file_ realm is available on your nodes. If you are using a default X-Pack configuration for authentication, then the file realm is available and you don't need to do anything.  
However, if you have explicitly configured the [authentication realms](https://www.elastic.co/guide/en/x-pack/6.2/how-authc-works.html) in your `elasticsearch.yml` file, then you may need to [add a `file` realm](https://www.elastic.co/guide/en/x-pack/6.2/file-realm.html#_configuring_a_file_realm).  
If you do this, then you should add it to on every node.

3. Use the `bin/x-pack/users` command to [create a new file-based](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/users-command.html#_examples_76) superuser on every node:

4. Start all your nodes.

5. [Reset the password](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/security-api-change-password.html) for the elastic user:

6. Verify the new password

7. If you wish, stop elasticsearch and then remove the _file_ realm from your `elasticsearch.yml` and/or [remove](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/users-command.html#_examples_76) the `my_admin` user from the file realm.  
However, we do recommend that you keep this realm and user enabled, just in case you ever need to perform this sort of emergency maintenance in the future.

---

_[View the full topic](https://discuss.elastic.co/t/x-pack-authentication-issue/121632)._
