# Unable to change internal\_user "admin" password

**URL:** <https://forum.opensearch.org/t/unable-to-change-internal-user-admin-password/17197>\
**Category:** Security\
**Tags:** troubleshoot, security-issue\
**Created:** [December 20, 2023, 4:41pm UTC](https://forum.opensearch.org/t/unable-to-change-internal-user-admin-password/17197 "2023-12-20T16:41:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vmm-afonso](https://avatars.discourse-cdn.com/v4/letter/v/9de053/32.png) [@vmm-afonso](https://forum.opensearch.org/u/vmm-afonso)\
**Post date:** [December 20, 2023, 4:41pm UTC](https://forum.opensearch.org/t/unable-to-change-internal-user-admin-password/17197/1 "2023-12-20T16:41:48Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
Opensearch 2.11.1

**Describe the issue** :  
So I tried to change my internal\_user “admin” 's password and it failed with the following error:  
{“status”:“FORBIDDEN”,“message”:“Resource ‘admin’ is reserved.”}

So I edited the internal\_user.yaml file to change the “reserved” parameter from “true” to “false”, I ran the secrurityadmin.sh script and changed the password.

All good so far, but now I don’t want to leave my admin as not reserved since it might pose a security concern.

My problem is that when I try to change “reserved” back to false after changing the password and I run securityadmin.sh once more the password automatically reverts to its original value “admin”. So it’s either keep admin user marked as not reserved but I get to change its password, or admin is a reserved user but every person that can access opensearch-dashboards can get creative if they so choose.

Is there any other way to get around this problem?

Thank you very much,

side note: I’ve been really enjoying working with opensearch, the project seems to be in good hands, a big thank you to the devs and to the community supporting it

**Configuration** :

**Relevant Logs or Screenshots** :

---

<div class="post-metadata">

**Author:** ![vmm-afonso](https://avatars.discourse-cdn.com/v4/letter/v/9de053/32.png) [@vmm-afonso](https://forum.opensearch.org/u/vmm-afonso)\
**Post date:** [December 20, 2023, 6:03pm UTC](https://forum.opensearch.org/t/unable-to-change-internal-user-admin-password/17197/2 "2023-12-20T18:03:27Z")

</div>

Ok I think I figured it out, sorry

I basically did the same first steps,

I edited my internal\_users.yml and changed reserved from “true” to “false” and ran the securityadmin.sh script.

Changed the admin password then I ran the securityadmin.sh script with -backup to save every current opensearch-security file to a volume I mounted inside my containers.

I edited the internal\_users.yml I just backed up and made admin reserved again. Then I ran securityadmin.sh once more with -cd and specifying the path to my backed up files and now I have my reserved admin with my a different password.

I forgot to mention I was running this on k8s cluster on my initial post. This thread can be closed

---

<div class="post-metadata">

**Author:** ![Mantas](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@Mantas](https://forum.opensearch.org/u/Mantas)\
**Post date:** [December 21, 2023, 12:01pm UTC](https://forum.opensearch.org/t/unable-to-change-internal-user-admin-password/17197/3 "2023-12-21T12:01:38Z")

</div>

Hi @vmm-afonso,

Whenever you run `securityadmin.sh` to update configuration it will overite everything from `opensearch-security/<config>.yml` files, so any change made in your UI will be changed back to what is in .yml.

I would strongly recommend to use `./securityadmin.sh -backup my-backup-directory \` whenever you update configuration in UI this will allow you to keep `opensearch-security/<config>.yml` files in sync with UI changes.

When it comes to the `admin` password you can change it directly in the `opensearch-security/internal_users.yml`. To generate a hash, run `plugins/opensearch-security/tools/hash.sh -p <new-password>` and don’t forget to update the configuration using `securityadmin.sh`.

Let me know if you have any further questions.

Best,  
Mantas

---

<div class="post-metadata">

**Author:** ![KateWinslet](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/katewinslet/32/6694_2.png) [@KateWinslet](https://forum.opensearch.org/u/KateWinslet)\
**Post date:** [December 22, 2023, 5:03pm UTC](https://forum.opensearch.org/t/unable-to-change-internal-user-admin-password/17197/4 "2023-12-22T17:03:28Z")

</div>

> [@vmm-afonso](#):
>
> **Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
> Opensearch 2.11.1
> 
> **Describe the issue** :  
> So I tried to change my internal\_user “admin” 's password and it failed with the following error:  
> {“status”:“FORBIDDEN”,“message”:“Resource ‘admin’ is reserved.”}
> 
> So I edited the internal\_user.yaml file to change the “reserved” parameter from “true” to “false”, I ran the secrurityadmin.sh script and changed the password.
> 
> All good so far, but now I don’t want to leave my admin as not reserved since it might pose a security concern.
> 
> My problem is that when I try to change “reserved” back to false after changing the password and I [paybyplate](https://paybyplatema.site/) run securityadmin.sh once more the password automatically reverts to its original value “admin”. So it’s either keep admin user marked as not reserved but I get to change its password, or admin is a reserved user but every person that can access opensearch-dashboards can get creative if they so choose
> 
> Is there any other way to get around this problem?
> 
> Thank you very much,
> 
> side note: I’ve been really enjoying working with opensearch, the project seems to be in good hands, a big thank you to the devs and to the community supporting it
> 
> **Configuration** :
> 
> **Relevant Logs or Screenshots** :

Consider setting a unique user as admin or implementing stricter access controls to balance security and password flexibility in OpenSearch.
