Elasticsearch3節(jié)點(diǎn)集群配置賬號密碼安全驗(yàn)證
ES配置文件
root@node1:~# grep -Ev "^#|^$" /etc/elasticsearch/elasticsearch.yml
cluster.name: es-pre
node.name: node1
node.master: true
node.data: true
path.data: /data/elk/es/data
path.logs: /data/elk/es/logs
network.host: esIP
http.port: 9200
discovery.seed_hosts: ["node1", "node2", "node3"]
cluster.initial_master_nodes: ["node1", "node2", "node3"]
http.cors.enabled: true
http.cors.allow-origin: "*"
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.client_authentication: required
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12
xpack.monitoring.enabled: true
xpack.monitoring.collection.enabled: true
root@node1:~#
生成CA證書
/usr/share/elasticsearch/bin/elasticsearch-certutil ca
/usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12
拷貝證書文件到es節(jié)點(diǎn)目錄
mv ./elastic-certificates.p12 /etc/elasticsearch
拷貝證書到es節(jié)點(diǎn)并授權(quán)
scp /etc/elasticsearch/elastic-certificates.p12 node3:/etc/elasticsearch/
scp /etc/elasticsearch/elastic-certificates.p12 node2:/etc/elasticsearch/
chown elasticsearch.elasticsearch /etc/elasticsearch/elastic-certificates.p12
拷貝es配置文件到es節(jié)點(diǎn)
scp /etc/elasticsearch/elasticsearch.yml node2:/etc/elasticsearch/
scp /etc/elasticsearch/elasticsearch.yml node3:/etc/elasticsearch/
三個節(jié)點(diǎn)啟動ES
systemctl restart elasticsearch.service
登錄任一節(jié)點(diǎn)設(shè)置密碼
/usr/share/elasticsearch/bin/elasticsearch-setup-passwords interactive
#需要設(shè)置密碼的用戶
apm_system
kibana_system
kibana
logstash_system
beats_system
remote_monitoring_user
elastic
配置kibana
root@node1:~# grep -Ev "^#|^$" /etc/kibana/kibana.yml
server.port: 5601
server.host: "kibanaIP"
server.publicBaseUrl: "http://kibanaIP"
elasticsearch.hosts: ["http://esIP:9200","http://esIP:9200","http://esIP:9200"]
elasticsearch.username: "kibana_system"
elasticsearch.password: "Your@Passw0rd"
i18n.locale: "zh-CN"
文章來源地址http://www.zghlxwxcb.cn/news/detail-634218.html
文章來源:http://www.zghlxwxcb.cn/news/detail-634218.html
到了這里,關(guān)于Elasticsearch3節(jié)點(diǎn)集群配置賬號密碼安全驗(yàn)證的文章就介紹完了。如果您還想了解更多內(nèi)容,請在右上角搜索TOY模板網(wǎng)以前的文章或繼續(xù)瀏覽下面的相關(guān)文章,希望大家以后多多支持TOY模板網(wǎng)!