You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何禁用OpenSearch登录弹窗同时保留SSL安全连接?

解决方案:保留HTTPS安全连接同时禁用OpenSearch登录弹窗

你的需求完全可行——可以在保留SSL/TLS加密(安全连接)的前提下,关闭身份验证要求,无需完全禁用OpenSearch Security插件。以下是具体调整步骤:

问题分析

  • 设置plugins.security.disabled: true会彻底关闭安全插件,导致HTTPS配置失效,这是错误的方向。
  • 单独配置clientcert_auth_domain仍出现登录弹窗,是因为该认证方式需要客户端提供SSL证书,而你未配置客户端证书时,插件会尝试其他认证流程;同时你可能未彻底关闭其他带挑战(challenge)的认证域。

具体配置步骤

1. 修改安全插件认证配置

编辑OpenSearch/config/opensearch-security/config.yml,启用匿名访问域并设为最高优先级,同时关闭其他需要身份验证的域:

authc:
  anonymous_auth_domain:
    description: "Anonymous access without authentication"
    http_enabled: true
    transport_enabled: true
    order: 1
    http_authenticator:
      type: anonymous
      config:
        username: anonymous
        roles: [anonymous]
      challenge: false
    authentication_backend:
      type: noop
  # 关闭基础账号密码认证域
  basic_internal_auth_domain:
    description: "Authenticate via HTTP Basic against internal users database"
    http_enabled: false
    transport_enabled: false
    order: 2
    http_authenticator:
      type: basic
      config:
        challenge: true
      authentication_backend:
        type: intern
  # 若不需要客户端证书认证,可关闭该域
  clientcert_auth_domain:
    description: "Authenticate via SSL client certificates"
    http_enabled: false
    transport_enabled: false
    order: 3
    http_authenticator:
      type: clientcert
      config:
        username_attribute: cn
      challenge: false
    authentication_backend:
      type: noop

2. 保留OpenSearch SSL配置

确保opensearch.yml中不要添加plugins.security.disabled: true,同时保留你的SSL相关配置(示例如下,替换为你的实际证书路径):

# SSL加密配置(保留你的原有设置)
plugins.security.ssl.http.enabled: true
plugins.security.ssl.http.pemcert_filepath: certs/your-node-cert.pem
plugins.security.ssl.http.pemkey_filepath: certs/your-node-key.pem
plugins.security.ssl.http.pemtrustedcas_filepath: certs/root-ca.pem

# 集群基础配置
cluster.name: opensearch-cluster
node.name: local-node
network.host: localhost

3. 重新加载安全配置

使用securityadmin.sh(Windows用securityadmin.bat)将修改后的配置应用到集群:

# 替换为你的实际证书路径与集群地址
./securityadmin.sh -cd ../opensearch-security/config/ \
  -cacert ../certs/root-ca.pem \
  -cert ../certs/admin.pem \
  -key ../certs/admin-key.pem \
  -h localhost -p 9200 -t config -f ../opensearch-security/config/config.yml

4. 重启OpenSearch服务

重启后访问https://localhost:9200,此时会直接返回集群信息,无登录弹窗,且连接为HTTPS加密状态。

原理说明

通过启用匿名认证域并设置为最高优先级,OpenSearch会允许匿名用户直接访问;同时关闭其他带challenge: true的认证域,避免触发登录弹窗。而SSL配置依然生效,确保数据传输的安全性。

内容的提问来源于stack exchange,提问作者Cristi 12

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 16:27:30