千家信息网

Elastic 安全配置 开启xpack

发表于:2025-01-23 作者:千家信息网编辑
千家信息网最后更新 2025年01月23日,1、生成证书bin/elasticsearch-certutil cabin/elasticsearch-certutil cert --ca elastic-stack-ca.p12mv bin/e
千家信息网最后更新 2025年01月23日Elastic 安全配置 开启xpack

1、生成证书

bin/elasticsearch-certutil cabin/elasticsearch-certutil cert --ca elastic-stack-ca.p12mv bin/elastic-certificates.p12 config/mv bin/elastic-stack-ca.p12 config/

2、编辑elasticsearch.yml
开启xpack

xpack.security.enabled: true

3、开启集群中https传输

xpack.security.transport.ssl.enabled: truexpack.security.transport.ssl.verification_mode: certificatexpack.security.transport.ssl.keystore.path: elastic-certificates.p12xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

4、开启api接口https传输

xpack.security.http.ssl.enabled: truexpack.security.http.ssl.keystore.path: elastic-certificates.p12xpack.security.http.ssl.truststore.path: elastic-certificates.p12xpack.security.http.ssl.client_authentication: nonexpack.ssl.verification_mode: none

5、自动生成密码

bin/elasticsearch-setup-passwords auto

6、配置kibana.yml
因为开启了elastic https传输所以要把http改为https

elasticsearch.hosts: ["https://localhost:9200"]

配置刚刚生成的kibana用户名和密码,否则启动kibana会报错

elasticsearch.username: "kibana"elasticsearch.password: "puVIrhabjDNOMFCybZZj"

ssl证书认证为none

elasticsearch.ssl.verificationMode: none
0