Password management
The Wazuh passwords tool changes the passwords for Wazuh indexer users, also known as internal users, and the Wazuh manager API users.
The following Wazuh indexer users are relevant to password management:
admin: The default administrator user of the Wazuh indexer. This user logs in to the Wazuh dashboard.kibanaserver: Handles communications between the Wazuh dashboard and the Wazuh indexer.wazuh-manager: Handles communications between the Wazuh manager and the Wazuh indexer.
The Wazuh manager API has two default users:
wazuh: The default administrator user for the Wazuh manager API.wazuh-wui: Administrator user that handles communications between the Wazuh dashboard and the Wazuh manager API.
The Wazuh passwords tool is located at /usr/share/wazuh-indexer/tools/wazuh-passwords-tool.sh. You can also download it by running the following command:
# curl -so wazuh-passwords-tool.sh https://packages-staging.xdrsiem.wazuh.info/pre-release/5.x/installation-assistant/wazuh-passwords-tool-5.0.0-rc1.sh
In an all-in-one deployment, the tool automatically updates the passwords in the required components. In a distributed deployment, you must update the password in other components depending on the user whose password you change. See Change the passwords in a distributed environment for more details.
The wazuh-passwords-tool.sh script provides the following options:
Option |
Description |
|---|---|
|
Changes the passwords of all the Wazuh indexer and Wazuh manager API users
installed on the host. The new passwords are generated and saved in
|
|
Specifies the user whose password is changed. If |
|
Reads the new password from standard input. Must be used with |
|
Displays the full script execution output. |
|
Displays the help message. |
Change the password for a Wazuh indexer user
Wazuh indexer users are defined in /etc/wazuh-indexer/opensearch-security/internal_users.yml. To change the password for a Wazuh indexer user, run the script with the -u option and pass the new password to the -p option through standard input. Passwords for Wazuh indexer users and Wazuh manager API users must contain 12 to 64 characters, using only A-Z, a-z, 0-9, and the symbols . , _ + : @ % ^ = ~ -. They must include at least one uppercase letter, one lowercase letter, one number, and one of the previously mentioned symbols.
# printf '%s\n' '<PASSWORD>' | bash wazuh-passwords-tool.sh -u <USER> -p
Where:
<USER>is the name of the user whose password you want to change:admin,kibanaserver, orwazuh-manager.<PASSWORD>is the new password. If you omit-p, the tool generates a random password and saves it in/etc/wazuh/credentials.env.
Note
Run this command on any Wazuh indexer node for distributed deployments.
For example, run the following command to change the password of the admin user to Secr3tP4ssw.rd:
# printf '%s\n' 'Secr3tP4ssw.rd' | bash wazuh-passwords-tool.sh -u admin -p
The command output looks similar to this:
INFO: Updating the internal users.
INFO: A backup of the internal users has been saved in the /etc/wazuh-indexer/internalusers-backup folder.
INFO: Generating password hash
INFO: The password of the Wazuh indexer user admin was changed.
INFO: WAZUH_INDEXER_ADMIN_PASSWORD was updated in /etc/wazuh/credentials.env.
Change the password for a Wazuh manager API user
To change the password for a Wazuh manager API user, run the script with the -u option and pass the new password to the -p option through standard input:
# printf '%s\n' '<PASSWORD>' | bash wazuh-passwords-tool.sh -u <USER> -p
Where:
<USER>is the name of the API user whose password you want to change:wazuhorwazuh-wui.<PASSWORD>is the new password. If you omit-p, the tool generates a random password and saves it in/etc/wazuh/credentials.env.
Note
Run this command on the Wazuh manager master node for distributed deployments.
For example, run the following command to change the password of the wazuh user to Secr3tP4ssw.rd:
# printf '%s\n' 'Secr3tP4ssw.rd' | bash wazuh-passwords-tool.sh -u wazuh -p
The command output looks similar to this:
INFO: The password of the Wazuh API user wazuh was changed.
INFO: WAZUH_MANAGER_API_PASSWORD was updated in /etc/wazuh/credentials.env.
You can also change the Wazuh manager API passwords by following the instructions in the Securing the Wazuh manager API documentation.
Change the passwords in a distributed environment
In a distributed deployment, run the Wazuh passwords tool on the correct node depending on the user whose password you change:
To change the password of a Wazuh indexer user, run the tool on any Wazuh indexer node.
To change the password of a Wazuh manager API user, run the tool on the Wazuh manager master node.
Update the Wazuh dashboard configuration
Perform these steps on the Wazuh dashboard node after you change the kibanaserver or wazuh-wui password in a distributed deployment. This ensures the Wazuh dashboard can authenticate with the Wazuh indexer and Wazuh manager API using the updated credentials.
Update the kibanaserver password
When you change the kibanaserver password, update the opensearch.password value in the Wazuh dashboard keystore. Replace <KIBANASERVER_PASSWORD> with the new password:
# echo '<KIBANASERVER_PASSWORD>' | runuser -u wazuh-dashboard -- /usr/share/wazuh-dashboard/bin/opensearch-dashboards-keystore add opensearch.password --stdin --force
Update the wazuh-wui password
When you change the wazuh-wui password, update the wazuh_core.hosts.default.password value in the Wazuh dashboard keystore. Replace <WAZUH_WUI_PASSWORD> with the new password:
# echo '<WAZUH_WUI_PASSWORD>' | runuser -u wazuh-dashboard -- /usr/share/wazuh-dashboard/bin/opensearch-dashboards-keystore add wazuh_core.hosts.default.password --stdin --force
Restart the Wazuh dashboard to apply the changes.
# systemctl restart wazuh-dashboard
# service wazuh-dashboard restart