| 1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465 | [[secure-settings]]== Secure SettingsSome settings are sensitive, and relying on filesystem permissions to protecttheir values is not sufficient. For this use case, elasticsearch provides akeystore, which may be password protected, and the `elasticsearch-keystore`tool to manage the settings in the keystore.NOTE: All commands here should be run as the user which will run elasticsearch.[float][[creating-keystore]]=== Creating the keystoreTo create the `elasticsearch.keystore`, use the `create` command:[source,sh]----------------------------------------------------------------bin/elasticsearch-keystore create----------------------------------------------------------------The file `elasticsearch.keystore` will be created alongside `elasticsearch.yml`.[float][[list-settings]]=== Listing settings in the keystoreA list of the settings in the keystore is available with the `list` command:[source,sh]----------------------------------------------------------------bin/elasticsearch-keystore list ----------------------------------------------------------------[float][[add-string-to-keystore]]=== Adding string settingsSensitive string settings, like authentication credentials for cloudplugins, can be added using the `add` command:[source,sh]----------------------------------------------------------------bin/elasticsearch-keystore add the.setting.name.to.set----------------------------------------------------------------The tool will prompt for the value of the setting. To pass the valuethrough stdin, use the `--stdin` flag:[source,sh]----------------------------------------------------------------cat /file/containing/setting/value | bin/elasticsearch-keystore add --stdin the.setting.name.to.set----------------------------------------------------------------[float][[remove-settings]]=== Removing settingsTo remove a setting from the keystore, use the `remove` command:[source,sh]----------------------------------------------------------------bin/elasticsearch-keystore remove the.setting.name.to.remove----------------------------------------------------------------
 |