|
@@ -31,9 +31,9 @@ endif::server[]
|
|
ifndef::verifies[]
|
|
ifndef::verifies[]
|
|
The SSL settings in `pass:a[{ssl-prefix}.ssl]` control a _server context_ for TLS, which
|
|
The SSL settings in `pass:a[{ssl-prefix}.ssl]` control a _server context_ for TLS, which
|
|
defines the settings for the TLS connection. The use of `verification_mode` in
|
|
defines the settings for the TLS connection. The use of `verification_mode` in
|
|
-a TLS _server_ is discouraged.
|
|
|
|
|
|
+a TLS _server_ is discouraged.
|
|
endif::verifies[]
|
|
endif::verifies[]
|
|
-Defines how to verify the certificates presented by another party in the TLS
|
|
|
|
|
|
+Defines how to verify the certificates presented by another party in the TLS
|
|
connection:
|
|
connection:
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-verification-mode-values]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-verification-mode-values]
|
|
|
|
|
|
@@ -62,9 +62,11 @@ When using PEM encoded files, use the following settings:
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-key-pem]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-key-pem]
|
|
|
|
|
|
|
|
+ifndef::secure-pass[]
|
|
+{ssl-prefix}.ssl.key_passphrase+::
|
|
+{ssl-prefix}.ssl.key_passphrase+::
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-key-passphrase]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-key-passphrase]
|
|
|
|
+endif::secure-pass[]
|
|
|
|
|
|
+{ssl-prefix}.ssl.secure_key_passphrase+::
|
|
+{ssl-prefix}.ssl.secure_key_passphrase+::
|
|
(<<secure-settings,Secure>>)
|
|
(<<secure-settings,Secure>>)
|
|
@@ -87,17 +89,21 @@ and certificates that should be trusted, use the following settings:
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-path]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-path]
|
|
|
|
|
|
|
|
+ifndef::secure-pass[]
|
|
+{ssl-prefix}.ssl.keystore.password+::
|
|
+{ssl-prefix}.ssl.keystore.password+::
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-password]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-password]
|
|
|
|
+endif::secure-pass[]
|
|
|
|
|
|
+{ssl-prefix}.ssl.keystore.secure_password+::
|
|
+{ssl-prefix}.ssl.keystore.secure_password+::
|
|
(<<secure-settings,Secure>>)
|
|
(<<secure-settings,Secure>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-secure-password]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-secure-password]
|
|
|
|
|
|
|
|
+ifndef::secure-pass[]
|
|
+{ssl-prefix}.ssl.keystore.key_password+::
|
|
+{ssl-prefix}.ssl.keystore.key_password+::
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-key-password]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-key-password]
|
|
|
|
+endif::secure-pass[]
|
|
|
|
|
|
+{ssl-prefix}.ssl.keystore.secure_key_password+::
|
|
+{ssl-prefix}.ssl.keystore.secure_key_password+::
|
|
(<<secure-settings,Secure>>)
|
|
(<<secure-settings,Secure>>)
|
|
@@ -107,9 +113,11 @@ include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-secure-key
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-truststore-path]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-truststore-path]
|
|
|
|
|
|
|
|
+ifndef::secure-pass[]
|
|
+{ssl-prefix}.ssl.truststore.password+::
|
|
+{ssl-prefix}.ssl.truststore.password+::
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-truststore-password]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-truststore-password]
|
|
|
|
+endif::secure-pass[]
|
|
|
|
|
|
+{ssl-prefix}.ssl.truststore.secure_password+::
|
|
+{ssl-prefix}.ssl.truststore.secure_password+::
|
|
(<<secure-settings,Secure>>)
|
|
(<<secure-settings,Secure>>)
|
|
@@ -131,17 +139,21 @@ include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-path]
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-type-pkcs12]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-type-pkcs12]
|
|
|
|
|
|
|
|
+ifndef::secure-pass[]
|
|
+{ssl-prefix}.ssl.keystore.password+::
|
|
+{ssl-prefix}.ssl.keystore.password+::
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-password]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-password]
|
|
|
|
+endif::secure-pass[]
|
|
|
|
|
|
+{ssl-prefix}.ssl.keystore.secure_password+::
|
|
+{ssl-prefix}.ssl.keystore.secure_password+::
|
|
(<<secure-settings,Secure>>)
|
|
(<<secure-settings,Secure>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-secure-password]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-secure-password]
|
|
|
|
|
|
|
|
+ifndef::secure-pass[]
|
|
+{ssl-prefix}.ssl.keystore.key_password+::
|
|
+{ssl-prefix}.ssl.keystore.key_password+::
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-key-password]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-keystore-key-password]
|
|
|
|
+endif::secure-pass[]
|
|
|
|
|
|
+{ssl-prefix}.ssl.keystore.secure_key_password+::
|
|
+{ssl-prefix}.ssl.keystore.secure_key_password+::
|
|
(<<secure-settings,Secure>>)
|
|
(<<secure-settings,Secure>>)
|
|
@@ -156,9 +168,11 @@ include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-truststore-path]
|
|
Set this to `PKCS12` to indicate that the truststore is a PKCS#12 file.
|
|
Set this to `PKCS12` to indicate that the truststore is a PKCS#12 file.
|
|
//TBD:Should this use the ssl-truststore-type definition and default values?
|
|
//TBD:Should this use the ssl-truststore-type definition and default values?
|
|
|
|
|
|
|
|
+ifndef::secure-pass[]
|
|
+{ssl-prefix}.ssl.truststore.password+::
|
|
+{ssl-prefix}.ssl.truststore.password+::
|
|
(<<static-cluster-setting,Static>>)
|
|
(<<static-cluster-setting,Static>>)
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-truststore-password]
|
|
include::{es-repo-dir}/settings/common-defs.asciidoc[tag=ssl-truststore-password]
|
|
|
|
+endif::secure-pass[]
|
|
|
|
|
|
+{ssl-prefix}.ssl.truststore.secure_password+::
|
|
+{ssl-prefix}.ssl.truststore.secure_password+::
|
|
(<<secure-settings,Secure>>)
|
|
(<<secure-settings,Secure>>)
|