File tree Expand file tree Collapse file tree 1 file changed +3
-3
lines changed
modules/ROOT/pages/security Expand file tree Collapse file tree 1 file changed +3
-3
lines changed Original file line number Diff line number Diff line change @@ -918,7 +918,7 @@ If hardcoding of clear text private key password is not feasible due to security
918918----
919919echo "password123" > passwordfile
920920
921- openssl aes-256-cbc -a -salt -in passwordfile -out password.enc -pass file:certificate.crt
921+ base64 -w 0 certificate.crt | openssl aes-256-cbc -a -salt -in passwordfile -out password.enc -pass stdin
922922----
923923+
924924[NOTE]
@@ -930,15 +930,15 @@ Delete the password file and set file permissions for `password.enc` to `400` (e
930930+
931931[source]
932932----
933- openssl aes-256-cbc -a -d -in password.enc -pass file:certificate.crt
933+ base64 -w 0 certificate.crt | openssl aes-256-cbc -a -d -in password.enc -pass stdin
934934----
935935
936936. Set the neo4j.conf `dbms.ssl.policy.<type>.private_key_password` to be able to read out encrypted password.
937937To adjust paths to cert and encrypted password file, use full paths:
938938+
939939[source]
940940----
941- dbms.ssl.policy.bolt.private_key_password=$(openssl aes-256-cbc -a -d -in password.enc -pass file:certificate.crt )
941+ dbms.ssl.policy.bolt.private_key_password=$(base64 -w 0 certificate.crt | openssl aes-256-cbc -a -d -in password.enc -pass stdin )
942942----
943943
944944[NOTE]
You can’t perform that action at this time.
0 commit comments