* fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 os.yml config file settings Signed-off-by: cwillum <[email protected]> * fix#214 os.yml config file settings Signed-off-by: cwillum <[email protected]> * fix#214 os.yml config file settings Signed-off-by: cwillum <[email protected]> * fix#214 os.yml config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 os.yml config file settings Signed-off-by: cwillum <[email protected]> * fix#214 os.yml config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * fix#214 config file settings Signed-off-by: cwillum <[email protected]> * Refactor settings documentation Signed-off-by: Fanit Kolchina <[email protected]> * Add more settings Signed-off-by: Fanit Kolchina <[email protected]> * remove bad commits (#5505) Signed-off-by: Stephen Crawford <[email protected]> * Format security settings Signed-off-by: Fanit Kolchina <[email protected]> * Add plugin settings and dashboards settings Signed-off-by: Fanit Kolchina <[email protected]> * Specify json code highlighter Signed-off-by: Fanit Kolchina <[email protected]> * Add gateway and network settings Signed-off-by: Fanit Kolchina <[email protected]> * Change heading level Signed-off-by: Fanit Kolchina <[email protected]> * Heading text change Signed-off-by: Fanit Kolchina <[email protected]> * Fix link Signed-off-by: Fanit Kolchina <[email protected]> * Add Notifications plugin settings Signed-off-by: Fanit Kolchina <[email protected]> * Implemented tech review comments for search settings Signed-off-by: Fanit Kolchina <[email protected]> * Rename directory and implement latest search setting review comment Signed-off-by: Fanit Kolchina <[email protected]> * Remove non-existent ml circuit breaker settings Signed-off-by: Fanit Kolchina <[email protected]> * Add file system and s3 settings Signed-off-by: Fanit Kolchina <[email protected]> * Update nav order Signed-off-by: Fanit Kolchina <[email protected]> * Add security analytics settings and specify static/dynamic for security settings Signed-off-by: Fanit Kolchina <[email protected]> * Reword correlation time window Signed-off-by: Fanit Kolchina <[email protected]> * Implemented tech review comments for network and discovery settings Signed-off-by: Fanit Kolchina <[email protected]> * Apply suggestions from code review Co-authored-by: Melissa Vagi <[email protected]> Signed-off-by: kolchfa-aws <[email protected]> * Implemented editorial comments Signed-off-by: Fanit Kolchina <[email protected]> * Clarify security settings Signed-off-by: Fanit Kolchina <[email protected]> * Apply suggestions from code review Co-authored-by: Melissa Vagi <[email protected]> Signed-off-by: kolchfa-aws <[email protected]> * Update _install-and-configure/configuring-opensearch/security-settings.md Signed-off-by: kolchfa-aws <[email protected]> * Add cross links to static and dynamic settings Signed-off-by: Fanit Kolchina <[email protected]> * Fix link Signed-off-by: Fanit Kolchina <[email protected]> --------- Signed-off-by: cwillum <[email protected]> Signed-off-by: Fanit Kolchina <[email protected]> Signed-off-by: Stephen Crawford <[email protected]> Signed-off-by: kolchfa-aws <[email protected]> Co-authored-by: Fanit Kolchina <[email protected]> Co-authored-by: Stephen Crawford <[email protected]> Co-authored-by: kolchfa-aws <[email protected]> Co-authored-by: Melissa Vagi <[email protected]>
1.9 KiB
1.9 KiB
layout, title, nav_order, has_children, has_toc, redirect_from
| layout | title | nav_order | has_children | has_toc | redirect_from | ||
|---|---|---|---|---|---|---|---|
| default | Configuration | 2 | true | false |
|
Security configuration
The plugin includes demo certificates so that you can get up and running quickly. To use OpenSearch in a production environment, you must configure it manually:
- Replace the demo certificates.
- Reconfigure
opensearch.ymlto use your certificates. - Reconfigure
config.ymlto use your authentication backend (if you don't plan to use the internal user database). - Modify the configuration YAML files.
- If you plan to use the internal user database, set a password policy in
opensearch.yml. - Apply changes using the
securityadminscript. - Start OpenSearch.
- Add users, roles, role mappings, and tenants.
If you don't want to use the plugin, see Disable security.
The Security plugin has several default users, roles, action groups, permissions, and settings for OpenSearch Dashboards that use kibana in their names. We will change these names in a future release. {: .note }
For a full list of opensearch.yml Security plugin settings, Security plugin settings, see Security settings.
{: .note}