-
Notifications
You must be signed in to change notification settings - Fork 0
Elasticsearch 6.7.1: node별 search guard 설치 후 클러스터링을 위한 tls세팅
5gyungjae edited this page Sep 5, 2019
·
2 revisions
- OS: CentOS 6
- ELK 버전: 6.7.1 basic
- node 수: 3개
- master, data, ingest 모두 적용
-
인증서 생성
-
elasticsearch.yml 설정 변경
# 노드 인증서 위치 지정
searchguard.ssl.transport.pemcert_filepath: certs_pem/domain.com.crtfull.pem
searchguard.ssl.transport.pemkey_filepath: certs_pem/domain.com.key.pem
searchguard.ssl.transport.pemkey_password:
searchguard.ssl.transport.pemtrustedcas_filepath: certs_pem/chain-ca.pem
searchguard.ssl.transport.enforce_hostname_verification: false
searchguard.nodes_dn:
- 'CN=*.omnitel.co.kr,OU=omnitel.co.kr,O=omnitel.co.kr'
searchguard.authcz.admin_dn:
- CN=sgadmin
searchguard.enterprise_modules_enabled: false