1、生成證書
創(chuàng)新互聯(lián)是一家專注于成都網(wǎng)站設計、做網(wǎng)站與策劃設計,石景山網(wǎng)站建設哪家好?創(chuàng)新互聯(lián)做網(wǎng)站,專注于網(wǎng)站建設十余年,網(wǎng)設計領域的專業(yè)建站公司;建站業(yè)務涵蓋:石景山等地區(qū)。石景山做網(wǎng)站價格咨詢:18980820575
bin/elasticsearch-certutil ca
bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12
mv bin/elastic-certificates.p12 config/
mv bin/elastic-stack-ca.p12 config/
2、編輯elasticsearch.yml
開啟xpack
xpack.security.enabled: true
3、開啟集群中https傳輸
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12
4、開啟api接口https傳輸
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: elastic-certificates.p12
xpack.security.http.ssl.truststore.path: elastic-certificates.p12
xpack.security.http.ssl.client_authentication: none
xpack.ssl.verification_mode: none
5、自動生成密碼
bin/elasticsearch-setup-passwords auto
6、配置kibana.yml
因為開啟了elastic https傳輸所以要把http改為https
elasticsearch.hosts: ["https://localhost:9200"]
配置剛剛生成的kibana用戶名和密碼,否則啟動kibana會報錯
elasticsearch.username: "kibana"
elasticsearch.password: "puVIrhabjDNOMFCybZZj"
ssl證書認證為none
elasticsearch.ssl.verificationMode: none