Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The  mzsh keytool enable-tls command from Enable One-way SSL On HTTP will configure these properties in Platform container automatically. You can also manually change the value of this property.

Do a  mzsh topo open container to view the platform container.conf.

Info

Quotes and double quotes surrounding the target path and property names are required for some properties to prevent overwriting. For further information, see Working with STR.

mz.httpd.security

This property is set to true (default value is false) to enable encryption.

Example value in container.conf:

Code Block
"mz.httpd.security"=true

To set this property manually, run this command:

Code Block
languagetext
$ mzsh topo set 'topo://container:<container>/val:common."mz.httpd.security"' true

mz.httpd.security.keystore

This property is to set the keystore file path. If this property is not set, TLS will not be used. 

Example value in container.conf:

Code Block
"mz.httpd.security.keystore"="/opt/mz/keys/keystore.p12"

To set this property manually, run this command:

Code Block
languagetext
$ mzsh topo set 'topo://container:<container>/val:common."mz.httpd.security.keystore"' <keystore path>
Info

Note: Full Path to the keystore file is required.

mz.httpd.security.keystore.password

Use this property to set the keystore password, which is the password we entered while creating keystore.

Example value in container.conf:

Code Block
"mz.httpd.security.keystore.password"="DR_8.1_KEY-1-9E5885A757778BFB153C6C877A7D9A86"

To set this property manually, run this command:

Code Block
languagetext
$ mzsh topo set 'topo://container:<container>/val:common."mz.httpd.security.keystore.password"' \
`mzsh encryptpassword <password>`

mz.httpd.security.key.password

Use this property to set the password for the key, as chosen in keytool. By default, this is the same as the keystore password. (This is the default for keytool).

Example value in container.conf:

Code Block
"mz.httpd.security.key.password"="DR_8.1_KEY-1-9E5885A757778BFB153C6C877A7D9A86"

To set this property manually, run this command:

Code Block
languagetext
$ mzsh topo set topo://container:<container>/val:common.mz.httpd.security.key.password \
`mzsh encryptpassword <password>`

Note

Restart Required

After the configuration is done all affected processes need to be restarted. Use the following command:

Code Block
mzsh restart platform