# Using environment variables and bcrypt

**URL:** <https://forum.search-guard.com/t/using-environment-variables-and-bcrypt/1790>\
**Category:** Search Guard\
**Created:** [April 6, 2020, 1:22pm UTC](https://forum.search-guard.com/t/using-environment-variables-and-bcrypt/1790 "2020-04-06T13:22:49Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [April 6, 2020, 1:22pm UTC](https://forum.search-guard.com/t/using-environment-variables-and-bcrypt/1790/1 "2020-04-06T13:22:50Z")

</div>

I’m trying to use feature that can generate bcrypt of env variable to store password as described here:

```
https://docs.search-guard.com/latest/configuration-password-handling

```

Here’s my `sg_internal_users.yml`:

```auto
---
_sg_meta:
  type: internalusers
  config_version: 2

kibanaserver:
  hash: ${envbc.PASSWORD:-kibana}

```

And here’s the command I’m running:

```auto
PASSWORD=test sgadmin.sh -key "/etc/elasticsearch/Admin.key" -cert "/etc/elasticsearch/Admin.crt" -c
acert /etc/elasticsearch/ca.crt -cd sgconfig -cn foo -ff

```

This doesn’t seem to work, as the stored password seems to be “kibana” instead of “test”
