diff --git a/docs/en/docs/admin-manual/fe-certificate.md b/docs/en/docs/admin-manual/fe-certificate.md new file mode 100644 index 0000000000..2a471ab39d --- /dev/null +++ b/docs/en/docs/admin-manual/fe-certificate.md @@ -0,0 +1,46 @@ +--- +{ + "title": "FE SSL certificate", + "language": "en" +} +--- + + + +# Certificate Configuration + + + +Certificate Configuration + + + +To enable SSL function on Doris FE interface, you need to configure key certificate as follows: + +1.Purchase or generate a self-signed SSL certificate. It is advised to use CA certificate in Production environment + +2.Copy the SSL certificate to specified path. The default path is `${DORIS_HOME}/conf/ssl/`, and user can also specify their own path + +3.Modify FE configuration file `conf/fe.conf`, and note that the following parameters are consistent with purchased or generated SSL certificate + Set `enable_https = true` to enable https function, default is `false` + Set certificate path `key_store_path`, default is `${DORIS_HOME}/conf/ssl/doris_ssl_certificate.keystore` + Set certificate password `key_store_password`, default is null + Set certificate type `key_store_type`, default is `JKS` + Set certificate alias `key_store_alias`, default is `doris_ssl_certificate` diff --git a/docs/sidebars.json b/docs/sidebars.json index 883d246ec8..4d8a40be7a 100644 --- a/docs/sidebars.json +++ b/docs/sidebars.json @@ -1054,6 +1054,7 @@ "admin-manual/tracing", "admin-manual/optimization", "admin-manual/certificate", + "admin-manual/fe-certificate", { "type": "category", "label": "Maintenance and Monitor", diff --git a/docs/zh-CN/docs/admin-manual/fe-certificate.md b/docs/zh-CN/docs/admin-manual/fe-certificate.md new file mode 100644 index 0000000000..9821aea004 --- /dev/null +++ b/docs/zh-CN/docs/admin-manual/fe-certificate.md @@ -0,0 +1,46 @@ +--- +{ + "title": "FE SSL密钥证书配置", + "language": "zh-CN" +} +--- + + + +# SSL密钥证书配置 + + + +SSL密钥证书配置 + + + +Doris FE 接口开启 SSL 功能需要配置密钥证书,步骤如下: + +1.购买或生成自签名 SSL 证书,生产环境建议使用 CA 颁发的证书 + +2.将 SSL 证书复制到指定路径下,默认路径为 `${DORIS_HOME}/conf/ssl/`,用户也可以自己指定路径 + +3.修改 FE 配置文件 `conf/fe.conf`,注意以下参数与购买或生成的 SSL 证书保持一致 + 设置 `enable_https = true` 开启 https 功能,默认为 `false` + 设置证书路径 `key_store_path`,默认为 `${DORIS_HOME}/conf/ssl/doris_ssl_certificate.keystore` + 设置证书密码 `key_store_password`,默认为空 + 设置证书类型 `key_store_type` ,默认为 `JKS` + 设置证书别名 `key_store_alias`,默认为 `doris_ssl_certificate`