In-transit TLS encryption¶
This page explains how to configure TLS encryption for service classes in manifest.yaml and the environment variables required to support it.
Setting up TLS encryption requires modification to the manifests imported to KX Sensors along with defining certain environment variables (which can be sourced through kxsenv).
manifest.yaml¶
In this configuration object, TLS encryption can be set up for each service class that connects to an external client. You activate encryption for a service class through the tls flag for that service class. This ensures that these processes start with the specified TLS server mode.
.default_service: &default_service
enabled: true
portOffset: 0
num: 1
threads: 0
prefix: ""
taskset: "0-10"
tls: 0
- sc: GW
<<: *default_service
tls: 0
- sc: SDL
<<: *default_service
tls: 1
- sc: SDL
<<: *default_service
tls: 2
kxsenv¶
In this file, the path to TLS certificates can be defined along with additional TLS related environment variables. Refer to https://code.kx.com/q/kb/ssl/ for further information on what each of the environment variables should be set to.
#
# SSL Configuration
# For additional details, please refer to: https://code.kx.com/q/kb/ssl/#keyscertificates
#
KX_SSL_CERT_FILE=
KX_SSL_CA_CERT_FILE=
KX_SSL_KEY_FILE=
KX_SSL_CN=
KX_SSL_VERIFY_CLIENT=
KX_SSL_VERIFY_SERVER=
Check TLS setup¶
In Linux, the TLS server mode of a process can be verified by going to the command line and typing the following:
ps -xf | grep <processName>
This shows the command line arguments of the process in question. The command line argument -E confirms the TLS server mode currently in effect for the process.
In Windows, the command line arguments of a process can be confirmed by looking for the process in Task Manager.
Alternatively, the TLS server mode can be verified by connecting to the KXS process and executing the kdb+ system command \E.
Start processes with TLS from the CLI¶
Instead of making manifest modifications, a process may be started with TLS enabled using the --tls-mode (-E) option to kxsctl start. This may be useful when testing TLS for a single service before enabling it for the entire system. The override applies to every target you name on the command line. A full list of options to kxsctl start may be viewed using kxsctl help start.
To set the TLS mode persistently for a service class without exporting and re-importing the manifest, use kxsctl manifest edit <node> --sc <class> --tls-mode <mode>. See Configure service classes in manifest.yaml.
Configure a stream with TLS enabled¶
ems.yaml also has a tls parameter that governs whether an individual stream, rather than a whole service class, requires TLS for external publishers, internal publishers, or both. See Configure TLS for ingestion from an external client through RT for the full set of tls modes and how RT mounts the configured certificates.