Skip to content

Commit

Permalink
[DOCS] TLS file resources are reloadable (#33258)
Browse files Browse the repository at this point in the history
Make clearer that file resources that are used as key trust material
are polled and will be reloaded upon modification.
  • Loading branch information
jkakavas committed Aug 30, 2018
1 parent b6f762d commit 557eabf
Show file tree
Hide file tree
Showing 2 changed files with 22 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -77,7 +77,17 @@ bin/elasticsearch-keystore add xpack.security.http.ssl.secure_key_passphrase

. Restart {es}.

NOTE: All TLS-related node settings are considered to be highly sensitive and
[NOTE]
===============================
* All TLS-related node settings are considered to be highly sensitive and
therefore are not exposed via the
{ref}/cluster-nodes-info.html#cluster-nodes-info[nodes info API] For more
information about any of these settings, see <<security-settings>>.
* {es} monitors all files such as certificates, keys, keystores, or truststores
that are configured as values of TLS-related node settings. If you update any of
these files (for example, when your hostnames change or your certificates are
due to expire), {es} reloads them. The files are polled for changes at
a frequency determined by the global {es} `resource.reload.interval.high`
setting, which defaults to 5 seconds.
===============================
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,17 @@ vice-versa). After enabling TLS you must restart all nodes in order to maintain
communication across the cluster.
--

NOTE: All TLS-related node settings are considered to be highly sensitive and
[NOTE]
===============================
* All TLS-related node settings are considered to be highly sensitive and
therefore are not exposed via the
{ref}/cluster-nodes-info.html#cluster-nodes-info[nodes info API] For more
information about any of these settings, see <<security-settings>>.
* {es} monitors all files such as certificates, keys, keystores, or truststores
that are configured as values of TLS-related node settings. If you update any of
these files (for example, when your hostnames change or your certificates are
due to expire), {es} reloads them. The files are polled for changes at
a frequency determined by the global {es} `resource.reload.interval.high`
setting, which defaults to 5 seconds.
===============================

0 comments on commit 557eabf

Please sign in to comment.