forked from apache/doris
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[doc](https) Add https certificate docs (apache#18558)
* add https certificate docs * add version * add version * add version
- Loading branch information
1 parent
fdc02ec
commit ffbf800
Showing
3 changed files
with
93 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,46 @@ | ||
--- | ||
{ | ||
"title": "FE SSL certificate", | ||
"language": "en" | ||
} | ||
--- | ||
|
||
<!-- | ||
Licensed to the Apache Software Foundation (ASF) under one | ||
or more contributor license agreements. See the NOTICE file | ||
distributed with this work for additional information | ||
regarding copyright ownership. The ASF licenses this file | ||
to you under the Apache License, Version 2.0 (the | ||
"License"); you may not use this file except in compliance | ||
with the License. You may obtain a copy of the License at | ||
http://www.apache.org/licenses/LICENSE-2.0 | ||
Unless required by applicable law or agreed to in writing, | ||
software distributed under the License is distributed on an | ||
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY | ||
KIND, either express or implied. See the License for the | ||
specific language governing permissions and limitations | ||
under the License. | ||
--> | ||
|
||
# Certificate Configuration | ||
|
||
<version since="2.0"> | ||
|
||
Certificate Configuration | ||
|
||
</version> | ||
|
||
To enable SSL function on Doris FE interface, you need to configure key certificate as follows: | ||
|
||
1.Purchase or generate a self-signed SSL certificate. It is advised to use CA certificate in Production environment | ||
|
||
2.Copy the SSL certificate to specified path. The default path is `${DORIS_HOME}/conf/ssl/`, and user can also specify their own path | ||
|
||
3.Modify FE configuration file `conf/fe.conf`, and note that the following parameters are consistent with purchased or generated SSL certificate | ||
Set `enable_https = true` to enable https function, default is `false` | ||
Set certificate path `key_store_path`, default is `${DORIS_HOME}/conf/ssl/doris_ssl_certificate.keystore` | ||
Set certificate password `key_store_password`, default is null | ||
Set certificate type `key_store_type`, default is `JKS` | ||
Set certificate alias `key_store_alias`, default is `doris_ssl_certificate` |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,46 @@ | ||
--- | ||
{ | ||
"title": "FE SSL密钥证书配置", | ||
"language": "zh-CN" | ||
} | ||
--- | ||
|
||
<!-- | ||
Licensed to the Apache Software Foundation (ASF) under one | ||
or more contributor license agreements. See the NOTICE file | ||
distributed with this work for additional information | ||
regarding copyright ownership. The ASF licenses this file | ||
to you under the Apache License, Version 2.0 (the | ||
"License"); you may not use this file except in compliance | ||
with the License. You may obtain a copy of the License at | ||
http://www.apache.org/licenses/LICENSE-2.0 | ||
Unless required by applicable law or agreed to in writing, | ||
software distributed under the License is distributed on an | ||
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY | ||
KIND, either express or implied. See the License for the | ||
specific language governing permissions and limitations | ||
under the License. | ||
--> | ||
|
||
# SSL密钥证书配置 | ||
|
||
<version since="2.0"> | ||
|
||
SSL密钥证书配置 | ||
|
||
</version> | ||
|
||
Doris FE 接口开启 SSL 功能需要配置密钥证书,步骤如下: | ||
|
||
1.购买或生成自签名 SSL 证书,生产环境建议使用 CA 颁发的证书 | ||
|
||
2.将 SSL 证书复制到指定路径下,默认路径为 `${DORIS_HOME}/conf/ssl/`,用户也可以自己指定路径 | ||
|
||
3.修改 FE 配置文件 `conf/fe.conf`,注意以下参数与购买或生成的 SSL 证书保持一致 | ||
设置 `enable_https = true` 开启 https 功能,默认为 `false` | ||
设置证书路径 `key_store_path`,默认为 `${DORIS_HOME}/conf/ssl/doris_ssl_certificate.keystore` | ||
设置证书密码 `key_store_password`,默认为空 | ||
设置证书类型 `key_store_type` ,默认为 `JKS` | ||
设置证书别名 `key_store_alias`,默认为 `doris_ssl_certificate` |