# Xpack setting password for build-in user

**URL:** <https://discuss.elastic.co/t/xpack-setting-password-for-build-in-user/138574>\
**Category:** Elasticsearch\
**Created:** [July 4, 2018, 2:00pm UTC](https://discuss.elastic.co/t/xpack-setting-password-for-build-in-user/138574 "2018-07-04T14:00:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rkparkar](https://avatars.discourse-cdn.com/v4/letter/r/82dd89/32.png) [@rkparkar](https://discuss.elastic.co/u/rkparkar)\
**Post date:** [July 4, 2018, 2:00pm UTC](https://discuss.elastic.co/t/xpack-setting-password-for-build-in-user/138574/1 "2018-07-04T14:00:24Z")

</div>

Is setting the password for all built-in users compulsory during the installation of xpack ?

i am not able to understand the advantages and disadvantages of setting up this password since we already have a default bootstrap password ,i believe.  
(referring : [https://www.elastic.co/guide/en/x-pack/6.2/setting-up-authentication.html#bootstrap-elastic-passwords](https://www.elastic.co/guide/en/x-pack/6.2/setting-up-authentication.html#bootstrap-elastic-passwords))

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [July 4, 2018, 2:31pm UTC](https://discuss.elastic.co/t/xpack-setting-password-for-build-in-user/138574/2 "2018-07-04T14:31:08Z")

</div>

The `bootstrap.password` is a transient password derived from the `keystore.seed` which is auto-generated, and is meant to be used only to set the passwords of the built in users. You should **not** use this instead and you **can not** use this instead as:

1. There is no API to read `keystore.seed` from the Elasticsearch keystore so that you can use it in authenticated API requests
2. Even if you set the `bootstrap.password` yourself in the Elasticsearch keystore, this password can subsequently only be used for the `elastic` user and not the rest of the built in users.

There are no advantages and disadvantages to think about in this specific case as there are no alternatives. The strongly suggested and only supported way is to follow the documentation and set the built-in users passwords.

---

<div class="post-metadata">

**Author:** ![rkparkar](https://avatars.discourse-cdn.com/v4/letter/r/82dd89/32.png) [@rkparkar](https://discuss.elastic.co/u/rkparkar)\
**Post date:** [July 12, 2018, 8:29am UTC](https://discuss.elastic.co/t/xpack-setting-password-for-build-in-user/138574/3 "2018-07-12T08:29:03Z")

</div>

> [@ikakavas](#):
>
> to read

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2018, 8:29am UTC](https://discuss.elastic.co/t/xpack-setting-password-for-build-in-user/138574/4 "2018-08-09T08:29:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
