# Change built-in admin pwd without destroing created users

**URL:** <https://forum.opensearch.org/t/change-built-in-admin-pwd-without-destroing-created-users/8912>\
**Category:** Security\
**Tags:** configure\
**Created:** [March 15, 2022, 4:19pm UTC](https://forum.opensearch.org/t/change-built-in-admin-pwd-without-destroing-created-users/8912 "2022-03-15T16:19:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fsitler](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@Fsitler](https://forum.opensearch.org/u/Fsitler)\
**Post date:** [March 15, 2022, 4:19pm UTC](https://forum.opensearch.org/t/change-built-in-admin-pwd-without-destroing-created-users/8912/1 "2022-03-15T16:19:36Z")

</div>

Hello,

please, is it possible to change internal admin pwd without destroing all internal users created via GUI or API? WHen I tried so via generating new hash and putting it into internal\_users.yml and applied using securityadmin.sh , all of my manually created users were gone…  
Is there some way to preserve them? I have more than 20 users with different roles and even tenants, so not much want ro recreate all manually again.

Thanks

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [March 15, 2022, 4:35pm UTC](https://forum.opensearch.org/t/change-built-in-admin-pwd-without-destroing-created-users/8912/2 "2022-03-15T16:35:43Z")

</div>

@Fsitler Yes, the easiest way is to export all the config, make the charges, then upload the config again. That way all the previously defined config remains intact.  
You can use the “-r” parameters with securityadmin.sh script, something like this:

`./securityadmin.sh -cd /usr/share/opensearch/plugins/opensearch-security/securityconfig/ -icl -nhnv -cacert /usr/share/opensearch/config/certs/root-ca.pem -cert /usr/share/opensearch/config/certs/admin-crt.pem -key /usr/share/opensearch/config/certs/admin-key.pem -r`

Hope this helps

---

<div class="post-metadata">

**Author:** ![Fsitler](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@Fsitler](https://forum.opensearch.org/u/Fsitler)\
**Post date:** [March 15, 2022, 5:32pm UTC](https://forum.opensearch.org/t/change-built-in-admin-pwd-without-destroing-created-users/8912/3 "2022-03-15T17:32:26Z")

</div>

@Anthony Thanks. I will try. What exactly does it do? I think I have no seen the -r switch in documentation?

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [March 15, 2022, 7:15pm UTC](https://forum.opensearch.org/t/change-built-in-admin-pwd-without-destroing-created-users/8912/4 "2022-03-15T19:15:06Z")

</div>

@Fsitler “-r” (–retrieve) retrieves all the configuration from the security index and stores it in the directory specified with -cd parameter. From there you can edit any of it and upload back the same way without the “-r” parameter
