# Email node forgets password

**URL:** <https://discourse.nodered.org/t/email-node-forgets-password/35832>\
**Category:** General\
**Created:** [12 November 2020 20:15 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832 "2020-11-12T20:15:54Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![dennishvo](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dennishvo/32/2896_2.png) [@dennishvo](https://discourse.nodered.org/u/dennishvo)\
**Post date:** [12 November 2020 20:15 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832/1 "2020-11-12T20:15:54Z")

</div>

Over time I've noticed that my email node seems to forget its account info. It always remembers the server and port but forgets the userid and password. I run multiple node-red servers on AWS. Has anyone else seen this behavior? Where is the account info stored?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [12 November 2020 21:01 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832/2 "2020-11-12T21:01:35Z")

</div>

Does this just happen suddenly during operation or when you are doing things in the editor? If you copy/paste a flow with email nodes in it then it loses the credentials, that is a security feature.  
The credentials are stored, encrypted, in `flows_xxx_cred.json`.

---

<div class="post-metadata">

**Author:** ![edje11](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/edje11/32/572_2.png) [@edje11](https://discourse.nodered.org/u/edje11)\
**Post date:** [13 November 2020 12:26 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832/3 "2020-11-13T12:26:29Z")

</div>

I had the same problem, not with the email node but with my Lg-tv node.  
Solution was to enable the **credentialSecret: "Secretkey"** line in the settings.js file.

Maybe it helps you.

---

<div class="post-metadata">

**Author:** ![dennishvo](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dennishvo/32/2896_2.png) [@dennishvo](https://discourse.nodered.org/u/dennishvo)\
**Post date:** [13 November 2020 13:57 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832/4 "2020-11-13T13:57:08Z")

</div>

It seems to happen during operation. I don't use the NR editor for weeks at a time. Now and then a user will report that they aren't receiving an email that I'm sending programmatically. When I check the node, the credentials are gone.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [13 November 2020 14:01 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832/5 "2020-11-13T14:01:50Z")

</div>

The passwords are stored in the flow credentials file. The only way it could forget the password is if:

1. someone deploys a change to clear the password
2. or the credentials file is deleted and NR is restarted

There is no other way for it to spontaneously forget the password.

How are you running it in AWS?

---

<div class="post-metadata">

**Author:** ![dennishvo](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dennishvo/32/2896_2.png) [@dennishvo](https://discourse.nodered.org/u/dennishvo)\
**Post date:** [13 November 2020 14:05 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832/6 "2020-11-13T14:05:52Z")

</div>

I have several ec2 nodes running Ubuntu and NR v1.1.3. Not using Docker.

---

<div class="post-metadata">

**Author:** ![dennishvo](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dennishvo/32/2896_2.png) [@dennishvo](https://discourse.nodered.org/u/dennishvo)\
**Post date:** [13 November 2020 14:10 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832/7 "2020-11-13T14:10:44Z")

</div>

Here's a scenario where I might be stepping on my own foot. If I copy the flow file from server A to server B but I don't copy the credentials file, will the credentials on server B still be valid?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [13 November 2020 14:16 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832/8 "2020-11-13T14:16:00Z")

</div>

> [@dennishvo](#):
>
> will the credentials on server B still be valid?

They will be valid as long as the node id's haven't changed. But you ought to copy both files together as you may otherwise miss an update. But for that to work, you need to have set `credentialSecret` in all of the settings file. This is what Node-RED uses to encrypt and decrypt your credentials file. If you don't set it explicitly, it will auto-generate a key and store it in the `.config.json` file (`.config.runtime.json` as of 1.2). If each instance has an auto-generated key, they won't be able to decrypt the credentials copied from another machine.

---

<div class="post-metadata">

**Author:** ![dennishvo](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dennishvo/32/2896_2.png) [@dennishvo](https://discourse.nodered.org/u/dennishvo)\
**Post date:** [13 November 2020 14:35 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832/9 "2020-11-13T14:35:27Z")

</div>

Very helpful information. Thanks!

I'll assume that this is the solution, until proven otherwise.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [27 November 2020 14:35 UTC](https://discourse.nodered.org/t/email-node-forgets-password/35832/10 "2020-11-27T14:35:40Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
