You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

咨询:通过TLS/SSL连接RESTHeart与MongoDB时mongod公证书获取方法

How to Locate MongoDB's Public Key Certificate & Configure RESTHeart for TLS/SSL Connection

Hey there! I see you're working through setting up RESTHeart to connect to MongoDB over TLS/SSL, and stuck on finding that mongod public key certificate. Let's walk through this step by step.

1. Find the MongoDB Public Key Certificate Path

The location of your MongoDB TLS certificate depends on how you've configured MongoDB's SSL setup—here are the most common scenarios:

  • Manually Configured MongoDB TLS
    If you edited your mongod.conf to enable SSL, look for the net.ssl.pemKeyFile (or net.ssl.certificateKeyFile in newer versions) entry. This points to a PEM file that contains both the public certificate and private key. The public certificate is either in this same file, or stored alongside it in a .crt file in the same directory.

    Example mongod.conf snippet:

    net:
      ssl:
        mode: requireSSL
        PEMKeyFile: /etc/ssl/mongodb/mongodb.pem
    

    If there's no separate .crt file, extract the public key from the PEM using OpenSSL:

    openssl x509 -in /etc/ssl/mongodb/mongodb.pem -out /etc/ssl/mongodb/mongodb.crt -outform PEM
    
  • Auto-Generated Test Certificates
    If you started MongoDB with --sslMode requireSSL without specifying a certificate, MongoDB creates a temporary self-signed certificate. The default paths are:

    • Linux/macOS: /tmp/mongodb-<port>.pem (e.g., /tmp/mongodb-27017.pem for default port 27017)
    • Windows: C:\Users\<YourUsername>\AppData\Local\Temp\mongodb-<port>.pem
      Note: These are only for testing—never use them in production!
  • CA-Issued Certificates
    If your MongoDB uses a certificate signed by a third-party CA, the public key certificate is the .crt file provided by your CA (or the root/intermediate certificate from the CA's trust chain). Reach out to your certificate admin or retrieve it from your CA's management portal if you don't have it locally.

2. Create a Truststore with keytool

Once you have the public certificate, use keytool to import it into a Java truststore (required for RESTHeart to trust MongoDB's TLS certificate):

keytool -importcert -file /path/to/your/mongodb.crt -alias mongodb-cert -keystore restheart-truststore.jks

You'll be prompted to set a truststore password—make sure to remember this, you'll need it when starting RESTHeart.

3. Full RESTHeart Startup Command

The startup command from the docs needs to include the truststore config and your SSL-enabled MongoDB connection URI. Here's a complete example:

$ java -server -Djavax.net.ssl.trustStore=./restheart-truststore.jks -Djavax.net.ssl.trustStorePassword=your-truststore-password -jar restheart.jar etc/restheart.yml

Don't forget to update your restheart.yml to use an SSL-enabled MongoDB URI:

mongodb:
  uri: mongodb://your-user:your-password@localhost:27017/?ssl=true&sslInvalidHostNameAllowed=false

(Only set sslInvalidHostNameAllowed=true for testing with self-signed certificates—disable it in production!)

内容的提问来源于stack exchange,提问作者konsul777

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:16:22