如何禁用OpenSearch登录弹窗同时保留SSL安全连接?
解决方案:保留HTTPS安全连接同时禁用OpenSearch登录弹窗
你的需求完全可行——可以在保留SSL/TLS加密(安全连接)的前提下,关闭身份验证要求,无需完全禁用OpenSearch Security插件。以下是具体调整步骤:
问题分析
- 设置
plugins.security.disabled: true会彻底关闭安全插件,导致HTTPS配置失效,这是错误的方向。 - 单独配置
clientcert_auth_domain仍出现登录弹窗,是因为该认证方式需要客户端提供SSL证书,而你未配置客户端证书时,插件会尝试其他认证流程;同时你可能未彻底关闭其他带挑战(challenge)的认证域。
具体配置步骤
1. 修改安全插件认证配置
编辑OpenSearch/config/opensearch-security/config.yml,启用匿名访问域并设为最高优先级,同时关闭其他需要身份验证的域:
authc: anonymous_auth_domain: description: "Anonymous access without authentication" http_enabled: true transport_enabled: true order: 1 http_authenticator: type: anonymous config: username: anonymous roles: [anonymous] challenge: false authentication_backend: type: noop # 关闭基础账号密码认证域 basic_internal_auth_domain: description: "Authenticate via HTTP Basic against internal users database" http_enabled: false transport_enabled: false order: 2 http_authenticator: type: basic config: challenge: true authentication_backend: type: intern # 若不需要客户端证书认证,可关闭该域 clientcert_auth_domain: description: "Authenticate via SSL client certificates" http_enabled: false transport_enabled: false order: 3 http_authenticator: type: clientcert config: username_attribute: cn challenge: false authentication_backend: type: noop
2. 保留OpenSearch SSL配置
确保opensearch.yml中不要添加plugins.security.disabled: true,同时保留你的SSL相关配置(示例如下,替换为你的实际证书路径):
# SSL加密配置(保留你的原有设置) plugins.security.ssl.http.enabled: true plugins.security.ssl.http.pemcert_filepath: certs/your-node-cert.pem plugins.security.ssl.http.pemkey_filepath: certs/your-node-key.pem plugins.security.ssl.http.pemtrustedcas_filepath: certs/root-ca.pem # 集群基础配置 cluster.name: opensearch-cluster node.name: local-node network.host: localhost
3. 重新加载安全配置
使用securityadmin.sh(Windows用securityadmin.bat)将修改后的配置应用到集群:
# 替换为你的实际证书路径与集群地址 ./securityadmin.sh -cd ../opensearch-security/config/ \ -cacert ../certs/root-ca.pem \ -cert ../certs/admin.pem \ -key ../certs/admin-key.pem \ -h localhost -p 9200 -t config -f ../opensearch-security/config/config.yml
4. 重启OpenSearch服务
重启后访问https://localhost:9200,此时会直接返回集群信息,无登录弹窗,且连接为HTTPS加密状态。
原理说明
通过启用匿名认证域并设置为最高优先级,OpenSearch会允许匿名用户直接访问;同时关闭其他带challenge: true的认证域,避免触发登录弹窗。而SSL配置依然生效,确保数据传输的安全性。
内容的提问来源于stack exchange,提问作者Cristi 12
相关产品推荐
相关产品推荐

