咨询:通过TLS/SSL连接RESTHeart与MongoDB时mongod公证书获取方法
Hey there! I see you're working through setting up RESTHeart to connect to MongoDB over TLS/SSL, and stuck on finding that mongod public key certificate. Let's walk through this step by step.
1. Find the MongoDB Public Key Certificate Path
The location of your MongoDB TLS certificate depends on how you've configured MongoDB's SSL setup—here are the most common scenarios:
Manually Configured MongoDB TLS
If you edited yourmongod.confto enable SSL, look for thenet.ssl.pemKeyFile(ornet.ssl.certificateKeyFilein newer versions) entry. This points to a PEM file that contains both the public certificate and private key. The public certificate is either in this same file, or stored alongside it in a.crtfile in the same directory.Example
mongod.confsnippet:net: ssl: mode: requireSSL PEMKeyFile: /etc/ssl/mongodb/mongodb.pemIf there's no separate
.crtfile, extract the public key from the PEM using OpenSSL:openssl x509 -in /etc/ssl/mongodb/mongodb.pem -out /etc/ssl/mongodb/mongodb.crt -outform PEMAuto-Generated Test Certificates
If you started MongoDB with--sslMode requireSSLwithout specifying a certificate, MongoDB creates a temporary self-signed certificate. The default paths are:- Linux/macOS:
/tmp/mongodb-<port>.pem(e.g.,/tmp/mongodb-27017.pemfor default port 27017) - Windows:
C:\Users\<YourUsername>\AppData\Local\Temp\mongodb-<port>.pem
Note: These are only for testing—never use them in production!
- Linux/macOS:
CA-Issued Certificates
If your MongoDB uses a certificate signed by a third-party CA, the public key certificate is the.crtfile provided by your CA (or the root/intermediate certificate from the CA's trust chain). Reach out to your certificate admin or retrieve it from your CA's management portal if you don't have it locally.
2. Create a Truststore with keytool
Once you have the public certificate, use keytool to import it into a Java truststore (required for RESTHeart to trust MongoDB's TLS certificate):
keytool -importcert -file /path/to/your/mongodb.crt -alias mongodb-cert -keystore restheart-truststore.jks
You'll be prompted to set a truststore password—make sure to remember this, you'll need it when starting RESTHeart.
3. Full RESTHeart Startup Command
The startup command from the docs needs to include the truststore config and your SSL-enabled MongoDB connection URI. Here's a complete example:
$ java -server -Djavax.net.ssl.trustStore=./restheart-truststore.jks -Djavax.net.ssl.trustStorePassword=your-truststore-password -jar restheart.jar etc/restheart.yml
Don't forget to update your restheart.yml to use an SSL-enabled MongoDB URI:
mongodb: uri: mongodb://your-user:your-password@localhost:27017/?ssl=true&sslInvalidHostNameAllowed=false
(Only set sslInvalidHostNameAllowed=true for testing with self-signed certificates—disable it in production!)
内容的提问来源于stack exchange,提问作者konsul777

