elasticsearch集群未授权访问漏洞,设置用户登录认证

elasticsearch集群未授权访问漏洞,设置用户登录认证

ES安装步骤省略

1.节点上生成认证文件 ca证书

[elasticsearch@pgdb-es1 bin]$

[elasticsearch@pgdb-es1 bin]$ ./elasticsearch-certutil ca

WARNING: An illegal reflective access operation has occurred

WARNING: Illegal reflective access by org.bouncycastle.jcajce.provider.drbg.DRBG (file:/opt/elasticsearch-7.2.0/lib/tools/security-cli/bcprov-jdk15on-1.61.jar) to constructor sun.security.provider.Sun()

WARNING: Please consider reporting this to the maintainers of org.bouncycastle.jcajce.provider.drbg.DRBG

WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations

WARNING: All illegal access operations will be denied in a future release

This tool assists you in the generation of X.509 certificates and certificate

signing requests for use with SSL/TLS in the Elastic stack.

The 'ca' mode generates a new 'certificate authority'

This will create a new X.509 certificate and private key that can be used

to sign certificate when running in 'cert' mode.

Use the 'ca-dn' option if you wish to configure the 'distinguished name'

of the certificate authority

By default the 'ca' mode produces a single PKCS#12 output file which holds:

    * The CA certificate

    * The CA's private key

If you elect to generate PEM format certificates (the -pem option), then the output will

be a zip file containing individual files for the CA certificate and private key

Please enter the desired output file [elastic-stack-ca.p12]:                         ---直接回车

Enter password for elastic-stack-ca.p12 :                                 ---直接回车

[elasticsearch@pgdb-es1 bin]$

2.生产新文件elastic-stack-ca.p12

[elasticsearch@pgdb-es1 bin]$ cd ..

[elasticsearch@pgdb-es1 elasticsearch-7.2.0]$ ll -lrt

total 552

-rw-r--r--.  1 elasticsearch elasticsearch   8478 Jun 20  2019 README.textile

-rw-r--r--.  1 elasticsearch elasticsear

评论
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
红包 添加红包
表情包 插入表情
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值