1.生成证书
bin/elasticsearch-certutil cert -out config/elastic-certificates.p12 -pass ""
生成的证书地址:/usr/local/opt/es7301/config/elastic-certificates.p12
2.拷贝到另外两台服务器
cp es7301/config/elastic-certificates.p12 es7302/config/
cp es7301/config/elastic-certificates.p12 es7303/config/
3.分别修改每台的配置并启动
修改第一台并启动
cd es7301
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /usr/local/opt/es7301/config/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /usr/local/opt/es7301/config/elastic-certificates.p12
nohup bin/elasticsearch &
修改第二台并启动
cd es7302
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /usr/local/opt/es7302/config/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /usr/local/opt/es7302/config/elastic-certificates.p12
nohup bin/elasticsearch &
修改第三台并启动
cd es7303
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /usr/local/opt/es7303/config/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /usr/local/opt/es7303/config/elastic-certificates.p12
nohup bin/elasticsearch &
4.设置密码(这里要注意,设置密码是最后一步,要在配置修改完并启动集群之后设置密码)
使用cd命令切换到elasticsearch目录,然后使用 bin/elasticsearch-setup-passwords auto 命令自动生成好几个默认用户和密码。
如果想手动生成密码,则使用 bin/elasticsearch-setup-passwords interactive 命令。一般默认会生成好几个管理员账户,其中一个叫elastic的用户是超级管理员
bin/elasticsearch-setup-passwords interactive
elastic
elastic
版权声明:本文内容由互联网用户自发贡献,该文观点仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 举报,一经查实,本站将立刻删除。
文章由极客之音整理,本文链接:https://www.bmabk.com/index.php/post/102135.html