elasticsearch 使用现有证书的Elasticsearch SSL配置,elasticsearch,ssl,elasticsearch,Ssl" /> elasticsearch 使用现有证书的Elasticsearch SSL配置,elasticsearch,ssl,elasticsearch,Ssl" />

elasticsearch 使用现有证书的Elasticsearch SSL配置

elasticsearch 使用现有证书的Elasticsearch SSL配置,elasticsearch,ssl,elasticsearch,Ssl,我正在尝试使用自己的company.cer文件进行elasticsearch的ssl配置 xpack.security.enabled: true xpack.security.http.ssl.enabled: true xpack.security.transport.ssl.enabled: true xpack.security.http.ssl.key: company.key xpack.security.http.ssl.certificate: company.crt xpack

我正在尝试使用自己的company.cer文件进行elasticsearch的ssl配置

xpack.security.enabled: true
xpack.security.http.ssl.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.http.ssl.key: company.key
xpack.security.http.ssl.certificate: company.crt
xpack.security.http.ssl.certificate_authorities: company.crt
xpack.security.transport.ssl.key: company.key
xpack.security.transport.ssl.certificate: company.crt
xpack.security.transport.ssl.certificate_authorities: company.crt
然而,我在一些案例中失败了

在第一种情况下,我在下面的配置中使用证书文件的cer扩展名

xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true

xpack.security.http.ssl.certificate: company.cer 
xpack.security.http.ssl.certificate_authorities: company.cer 

xpack.security.transport.ssl.certificate: company.cer 
xpack.security.transport.ssl.certificate_authorities: company.cer 
第二个案例我用pfx试过

xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: company.pfx
xpack.security.transport.ssl.truststore.path: company.pfx
xpack.security.transport.ssl.keystore.password: password
xpack.security.transport.ssl.truststore.password: password
xpack.security.http.ssl.keystore.password:  password
xpack.security.http.ssl.truststore.password: password
密码是pfx文件的密码。但这种配置不起作用

然后,我尝试使用以下配置通过OpenSSL生成crt关键文件

xpack.security.enabled: true
xpack.security.http.ssl.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.http.ssl.key: company.key
xpack.security.http.ssl.certificate: company.crt
xpack.security.http.ssl.certificate_authorities: company.crt
xpack.security.transport.ssl.key: company.key
xpack.security.transport.ssl.certificate: company.crt
xpack.security.transport.ssl.certificate_authorities: company.crt
如何从cerpfx文件配置Elasticsearch SSL

谢谢你的回答