将主域控制器配置为使用 SSL 或 TLS,如以下示例中所示。当您配置了所有证书和密钥存储后,您需要配置安全域以使用双向 SSL/TLS。您可以通过将安全域配置为使用 SSL/TLS 来达到此目的。配置的安全域将保护用于在主机控制器和主域控制器之间连接的管理接口。
batch
/host=master/core-service=management/security-realm=CertificateRealm:add()
/host=master/core-service=management/security-realm=CertificateRealm/server-identity=ssl:add(alias=domaincontroller,keystore-relative-to=jboss.domain.config.dir,keystore-path=domaincontroller.jks,keystore-password=secret)
/host=master/core-service=management/security-realm=CertificateRealm/authentication=truststore:add(keystore-relative-to=jboss.domain.config.dir,keystore-path=domaincontroller.jks,keystore-password=secret)
/host=master/core-service=management/security-realm=CertificateRealm/authentication=local:add(default-user=\$local)
/host=master/core-service=management/security-realm=CertificateRealm/authentication=properties:add(relative-to=jboss.domain.config.dir,path=mgmt-users.properties)
/host=master/core-service=management/management-interface=http-interface:write-attribute(name=security-realm,value=CertificateRealm)
run-batch
batch
/host=master/core-service=management/security-realm=CertificateRealm:add()
/host=master/core-service=management/security-realm=CertificateRealm/server-identity=ssl:add(alias=domaincontroller,keystore-relative-to=jboss.domain.config.dir,keystore-path=domaincontroller.jks,keystore-password=secret)
/host=master/core-service=management/security-realm=CertificateRealm/authentication=truststore:add(keystore-relative-to=jboss.domain.config.dir,keystore-path=domaincontroller.jks,keystore-password=secret)
/host=master/core-service=management/security-realm=CertificateRealm/authentication=local:add(default-user=\$local)
/host=master/core-service=management/security-realm=CertificateRealm/authentication=properties:add(relative-to=jboss.domain.config.dir,path=mgmt-users.properties)
/host=master/core-service=management/management-interface=http-interface:write-attribute(name=security-realm,value=CertificateRealm)
run-batch
Copy to Clipboard
Copied!
Toggle word wrap
Toggle overflow