ELK - Set up basic security for the Elastic Stack

13 篇文章 0 订阅

1. Genrate CA: elastic-stack-ca.p12

cd /usr/share/elasticsearch
./bin/elasticsearch-certutil ca

Input password

2. Generate Cert: elastic-certificates.p12

./bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12

Input password

Complete the following steps for each node in your cluster.

3. cp elastic-certificates.p12 /etc/elasticsearch/

chmod 644 elastic-certificates.p12

4. vi /etc/elasticsearch/elasticsearch.yml

//#cluster.name: my-cluster
//#node.name: node-1

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.client_authentication: required
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

5. Store the password in the Elasticsearch keystore

./bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure_password
./bin/elasticsearch-keystore add xpack.security.transport.ssl.truststore.secure_password

6. Restart elasticsearch

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值