diff --git a/production-cluster.yml b/production-cluster.yml index fa1bf78f..9ec9ce92 100644 --- a/production-cluster.yml +++ b/production-cluster.yml @@ -86,6 +86,8 @@ services: - ./production_cluster/ssl_certs/root-ca.pem:/usr/share/elasticsearch/config/root-ca.pem - ./production_cluster/ssl_certs/node1.key:/usr/share/elasticsearch/config/node1.key - ./production_cluster/ssl_certs/node1.pem:/usr/share/elasticsearch/config/node1.pem + - ./production_cluster/ssl_certs/admin.pem:/usr/share/elasticsearch/config/admin.pem + - ./production_cluster/ssl_certs/admin.key:/usr/share/elasticsearch/config/admin.key - ./production_cluster/elastic_opendistro/elasticsearch-node1.yml:/usr/share/elasticsearch/config/elasticsearch.yml - ./production_cluster/elastic_opendistro/internal_users.yml:/usr/share/elasticsearch/plugins/opendistro_security/securityconfig/internal_users.yml diff --git a/production_cluster/elastic_opendistro/elasticsearch-node1.yml b/production_cluster/elastic_opendistro/elasticsearch-node1.yml index c343818e..4f9a628d 100644 --- a/production_cluster/elastic_opendistro/elasticsearch-node1.yml +++ b/production_cluster/elastic_opendistro/elasticsearch-node1.yml @@ -20,7 +20,7 @@ opendistro_security.nodes_dn: - 'CN=node2,OU=Ops,O=Example\, Inc.,DC=example,DC=com' - 'CN=node3,OU=Ops,O=Example\, Inc.,DC=example,DC=com' - 'CN=filebeat,OU=Ops,O=Example\, Inc.,DC=example,DC=com' -opendistro_security.authcz.admin_dn: [] +opendistro_security.authcz.admin_dn: ['CN=admin,OU=Ops,O=Example\, Inc.,DC=example,DC=com'] opendistro_security.audit.type: internal_elasticsearch opendistro_security.enable_snapshot_restore_privilege: true opendistro_security.check_snapshot_restore_write_privileges: true diff --git a/production_cluster/elastic_opendistro/elasticsearch-node2.yml b/production_cluster/elastic_opendistro/elasticsearch-node2.yml index 3e9bae49..e368461e 100644 --- a/production_cluster/elastic_opendistro/elasticsearch-node2.yml +++ b/production_cluster/elastic_opendistro/elasticsearch-node2.yml @@ -20,7 +20,7 @@ opendistro_security.nodes_dn: - 'CN=node2,OU=Ops,O=Example\, Inc.,DC=example,DC=com' - 'CN=node3,OU=Ops,O=Example\, Inc.,DC=example,DC=com' - 'CN=filebeat,OU=Ops,O=Example\, Inc.,DC=example,DC=com' -opendistro_security.authcz.admin_dn: [] +opendistro_security.authcz.admin_dn: ['CN=admin,OU=Ops,O=Example\, Inc.,DC=example,DC=com'] opendistro_security.audit.type: internal_elasticsearch opendistro_security.enable_snapshot_restore_privilege: true opendistro_security.check_snapshot_restore_write_privileges: true diff --git a/production_cluster/elastic_opendistro/elasticsearch-node3.yml b/production_cluster/elastic_opendistro/elasticsearch-node3.yml index 574bce5c..14717a81 100644 --- a/production_cluster/elastic_opendistro/elasticsearch-node3.yml +++ b/production_cluster/elastic_opendistro/elasticsearch-node3.yml @@ -20,7 +20,7 @@ opendistro_security.nodes_dn: - 'CN=node2,OU=Ops,O=Example\, Inc.,DC=example,DC=com' - 'CN=node3,OU=Ops,O=Example\, Inc.,DC=example,DC=com' - 'CN=filebeat,OU=Ops,O=Example\, Inc.,DC=example,DC=com' -opendistro_security.authcz.admin_dn: [] +opendistro_security.authcz.admin_dn: ['CN=admin,OU=Ops,O=Example\, Inc.,DC=example,DC=com'] opendistro_security.audit.type: internal_elasticsearch opendistro_security.enable_snapshot_restore_privilege: true opendistro_security.check_snapshot_restore_write_privileges: true diff --git a/production_cluster/ssl_certs/certs.yml b/production_cluster/ssl_certs/certs.yml index f7dad185..a4afcd45 100644 --- a/production_cluster/ssl_certs/certs.yml +++ b/production_cluster/ssl_certs/certs.yml @@ -28,3 +28,8 @@ nodes: dn: CN=filebeat,OU=Ops,O=Example\, Inc.,DC=example,DC=com dns: - wazuh + +clients: + - name: admin + dn: CN=admin,OU=Ops,O=Example\, Inc.,DC=example,DC=com + admin: true