Skip to content

Commit

Permalink
[doc](https) Add https certificate docs (apache#18558)
Browse files Browse the repository at this point in the history
* add https certificate docs

* add version

* add version

* add version
  • Loading branch information
yongjinhou authored and gnehil committed Apr 21, 2023
1 parent fdc02ec commit ffbf800
Show file tree
Hide file tree
Showing 3 changed files with 93 additions and 0 deletions.
46 changes: 46 additions & 0 deletions docs/en/docs/admin-manual/fe-certificate.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
---
{
"title": "FE SSL certificate",
"language": "en"
}
---

<!--
Licensed to the Apache Software Foundation (ASF) under one
or more contributor license agreements. See the NOTICE file
distributed with this work for additional information
regarding copyright ownership. The ASF licenses this file
to you under the Apache License, Version 2.0 (the
"License"); you may not use this file except in compliance
with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing,
software distributed under the License is distributed on an
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
KIND, either express or implied. See the License for the
specific language governing permissions and limitations
under the License.
-->

# Certificate Configuration

<version since="2.0">

Certificate Configuration

</version>

To enable SSL function on Doris FE interface, you need to configure key certificate as follows:

1.Purchase or generate a self-signed SSL certificate. It is advised to use CA certificate in Production environment

2.Copy the SSL certificate to specified path. The default path is `${DORIS_HOME}/conf/ssl/`, and user can also specify their own path

3.Modify FE configuration file `conf/fe.conf`, and note that the following parameters are consistent with purchased or generated SSL certificate
Set `enable_https = true` to enable https function, default is `false`
Set certificate path `key_store_path`, default is `${DORIS_HOME}/conf/ssl/doris_ssl_certificate.keystore`
Set certificate password `key_store_password`, default is null
Set certificate type `key_store_type`, default is `JKS`
Set certificate alias `key_store_alias`, default is `doris_ssl_certificate`
1 change: 1 addition & 0 deletions docs/sidebars.json
Original file line number Diff line number Diff line change
Expand Up @@ -1054,6 +1054,7 @@
"admin-manual/tracing",
"admin-manual/optimization",
"admin-manual/certificate",
"admin-manual/fe-certificate",
{
"type": "category",
"label": "Maintenance and Monitor",
Expand Down
46 changes: 46 additions & 0 deletions docs/zh-CN/docs/admin-manual/fe-certificate.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
---
{
"title": "FE SSL密钥证书配置",
"language": "zh-CN"
}
---

<!--
Licensed to the Apache Software Foundation (ASF) under one
or more contributor license agreements. See the NOTICE file
distributed with this work for additional information
regarding copyright ownership. The ASF licenses this file
to you under the Apache License, Version 2.0 (the
"License"); you may not use this file except in compliance
with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing,
software distributed under the License is distributed on an
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
KIND, either express or implied. See the License for the
specific language governing permissions and limitations
under the License.
-->

# SSL密钥证书配置

<version since="2.0">

SSL密钥证书配置

</version>

Doris FE 接口开启 SSL 功能需要配置密钥证书,步骤如下:

1.购买或生成自签名 SSL 证书,生产环境建议使用 CA 颁发的证书

2.将 SSL 证书复制到指定路径下,默认路径为 `${DORIS_HOME}/conf/ssl/`,用户也可以自己指定路径

3.修改 FE 配置文件 `conf/fe.conf`,注意以下参数与购买或生成的 SSL 证书保持一致
设置 `enable_https = true` 开启 https 功能,默认为 `false`
设置证书路径 `key_store_path`,默认为 `${DORIS_HOME}/conf/ssl/doris_ssl_certificate.keystore`
设置证书密码 `key_store_password`,默认为空
设置证书类型 `key_store_type` ,默认为 `JKS`
设置证书别名 `key_store_alias`,默认为 `doris_ssl_certificate`

0 comments on commit ffbf800

Please sign in to comment.