clickhouse-docs icon indicating copy to clipboard operation
clickhouse-docs copied to clipboard

Instruct reader to implement CA and Certs for ClickHouse Keeper in "Configuring SSL" tutorial.

Open xogoodnow opened this issue 1 year ago • 0 comments

On the following Document: https://clickhouse.com/docs/en/guides/sre/configuring-ssl

When using TLS, the ca and certs must be specified for clickhosue keeper as well and not just for ClickHouse. but it has not been mentioned in the doc the following must be set within the configuration of clickhouse-keeper as well

<openSSL>
    <server>
        <certificateFile>/etc/clickhouse-server/certs/chnode1.crt</certificateFile>
        <privateKeyFile>/etc/clickhouse-server/certs/chnode1.key</privateKeyFile>
        <verificationMode>relaxed</verificationMode>
        <caConfig>/etc/clickhouse-server/certs/marsnet_ca.crt</caConfig>
        <cacheSessions>true</cacheSessions>
        <disableProtocols>sslv2,sslv3</disableProtocols>
        <preferServerCiphers>true</preferServerCiphers>
    </server>
    <client>
        <loadDefaultCAFile>false</loadDefaultCAFile>
        <caConfig>/etc/clickhouse-server/certs/marsnet_ca.crt</caConfig>
        <cacheSessions>true</cacheSessions>
        <disableProtocols>sslv2,sslv3</disableProtocols>
        <preferServerCiphers>true</preferServerCiphers>
        <verificationMode>relaxed</verificationMode>
        <invalidCertificateHandler>
            <name>RejectCertificateHandler</name>
        </invalidCertificateHandler>
    </client>
</openSSL>

xogoodnow avatar Feb 17 '24 17:02 xogoodnow