elasticsearch7.3.0集群并设置密码

1.生成证书

bin/elasticsearch-certutil cert -out config/elastic-certificates.p12 -pass ""
 生成的证书地址:/usr/local/opt/es7301/config/elastic-certificates.p12

2.拷贝到另外两台服务器

cp es7301/config/elastic-certificates.p12 es7302/config/
cp es7301/config/elastic-certificates.p12 es7303/config/

3.分别修改每台的配置并启动

修改第一台并启动
cd es7301
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /usr/local/opt/es7301/config/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /usr/local/opt/es7301/config/elastic-certificates.p12

nohup bin/elasticsearch &


修改第二台并启动
cd es7302

xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /usr/local/opt/es7302/config/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /usr/local/opt/es7302/config/elastic-certificates.p12

nohup bin/elasticsearch &


修改第三台并启动
cd es7303

xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: /usr/local/opt/es7303/config/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /usr/local/opt/es7303/config/elastic-certificates.p12

nohup bin/elasticsearch &

4.设置密码(这里要注意,设置密码是最后一步,要在配置修改完并启动集群之后设置密码)

使用cd命令切换到elasticsearch目录,然后使用 bin/elasticsearch-setup-passwords auto 命令自动生成好几个默认用户和密码。
如果想手动生成密码,则使用 bin/elasticsearch-setup-passwords interactive 命令。一般默认会生成好几个管理员账户,其中一个叫elastic的用户是超级管理员

bin/elasticsearch-setup-passwords interactive
elastic
elastic

在这里插入图片描述

猜你喜欢

转载自blog.csdn.net/m0_67393342/article/details/126660242