# Can opensearch.keystore (not jks/pkcs12) be copied across nodes?

**URL:** <https://forum.opensearch.org/t/can-opensearch-keystore-not-jks-pkcs12-be-copied-across-nodes/14611>\
**Category:** OpenSearch\
**Created:** [June 8, 2023, 2:26pm UTC](https://forum.opensearch.org/t/can-opensearch-keystore-not-jks-pkcs12-be-copied-across-nodes/14611 "2023-06-08T14:26:44Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![dgkn](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@dgkn](https://forum.opensearch.org/u/dgkn)\
**Post date:** [June 8, 2023, 2:26pm UTC](https://forum.opensearch.org/t/can-opensearch-keystore-not-jks-pkcs12-be-copied-across-nodes/14611/1 "2023-06-08T14:26:44Z")

</div>

Hello,

In the documentation it says that to add an email sender we also have to add its username and password to opensearch.keystore like this:

`./bin/opensearch-keystore add plugins.alerting.destination.email.<sender>.username`  
`./bin/opensearch-keystore add plugins.alerting.destination.email.<sender>.password`

Is it safe to create this file locally and mount it to containers as readonly via configMaps on k8s and configs/bind mounts on docker?
