Configure TLS for ingestion from an external client through RT¶
This page explains the ems.yaml tls parameter modes for enabling TLS encryption on ingestion from external clients through RT.
In the ems.yaml configuration you can configure whether a TLS endpoint is surfaced to external publishers and/or if internal publishers use encryption, using the tls parameter, a short integer, indicating the following modes:
| Mode | Description |
|---|---|
| 0 | TLS is disabled, non-secure endpoint is exposed through discovery |
| 1 | Mixed mode, TLS encryption on receipt of external traffic (non-q publishing clients), no encryption on internal traffic |
| 2 | TLS must be used by all publishers to the messaging bus. When this mode is enabled, internal publishers will automatically open a connection to all RT streams using TLS. |
If TLS is enabled on any stream, RTO supplies the certificates configured using KX_SSL_CA_CERT_FILE, KX_SSL_CERT_FILE, and KX_SSL_KEY_FILE to the RT processes it starts. As of 3.3, these variables must point to files that exist on the host: RTO validates them at startup, logs a warning naming any that are missing, and exits without automatically restarting if the configuration is incomplete. In KX Sensors v3 releases before 3.3, where RT ran in containers, RTO volume mounted these certificates into the RT containers and only checked that the variables were set. TLS can be enabled on streams that are running in bridge mode.
If configured properly from a maintenance console you can confirm the configuration from ancillary information for the RT entries for the configured stream.
q)select proc,addrs,pubs,subs,anc from .disc.reg where svcClass in`RT
proc addrs pubs subs anc
----------------------------------------------------------------------------------------------
feed1/sub/feed1-wonka-0 :feed1-wonka-0:5001 `symbol$() ,`feed1 `bridge`tls!(1b;1h)
feed1/pub/feed1-wonka-0 :feed1-wonka-0:5005 ,`feed1 `symbol$() `bridge`tls!(1b;1h)
Note
Kx Sensors 3 currently does not support encryption of traffic on subscribers of our EMS streams as well as cross sync traffic between EMS Raft nodes. These issues are blockers towards having a system where all data in flight is encrypted.