how to enable TLS in postgres-db in hypledger fabric -ca?

Viewed 87

I've successfully changed fabric-ca-server.db from sqlite to postgres. how to enable TLS in postgres-db in hypledger fabric -ca ?

1 Answers

Mmm... You can override ssl-related variables in /var/lib/postgresql/data/postgresql.conf (through a volume, or a config-map in Kubernetes). You should also import the key and certificate through a volume or config-map.

Then, you must set db.datasource.sslmode and db.tls section in your fabric-ca-server-config.yaml as clearly explained here: https://hyperledger-fabric-ca.readthedocs.io/en/release-1.4/users-guide.html#postgresql. Don't forget to move the PostgreSQL certificate to db.tls.certfiles location (through a volume or whatever).

Anyway what you usually do is deploying the PostgreSQL in a way that only the fabric-ca server can access it and avoid SSL. For instance, in Kubernetes in the same pod without exposing the PostgreSQL port or in docker-compose inside the same docker-compose.yaml and in the same (separated) network without redirecting the PostgreSQL port.

Related