Skip to content

Commit 536fcfa

Browse files
committed
apply suggestions from review
1 parent 7b76645 commit 536fcfa

File tree

2 files changed

+22
-20
lines changed

2 files changed

+22
-20
lines changed

modules/ROOT/pages/backup-restore/online-backup.adoc

Lines changed: 0 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -320,36 +320,17 @@ As an example, add the following content to your _neo4j.conf_ and _neo4j-admin.c
320320
.Server configuration in _neo4j.conf_
321321
[source, properties]
322322
----
323-
server.backup.listen_address=0.0.0.0:6362
324-
dbms.ssl.policy.backup.enabled=true
325-
dbms.ssl.policy.backup.base_directory=certificates/backup
326-
dbms.ssl.policy.backup.private_key=private.key
327-
dbms.ssl.policy.backup.public_certificate=public.crt
328323
dbms.ssl.policy.backup.client_auth=REQUIRE
329324
dbms.ssl.policy.backup.tls_versions=TLSv1.2,TLSv1.3
330-
# dbms.ssl.policy.backup.tls_versions=TLSv1.2
331325
dbms.ssl.policy.backup.ciphers=TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
332-
# dbms.ssl.policy.backup.ciphers=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
333-
# dbms.ssl.policy.backup.ciphers=TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
334-
# dbms.netty.ssl.provider=OPENSSL
335-
dbms.netty.ssl.provider=JDK
336326
----
337327

338328
.Client configuration in _neo4j-admin.conf_
339329
[source, properties]
340330
----
341-
# Enable SSL backup
342-
dbms.ssl.policy.backup.enabled=true
343-
# dbms.ssl.policy.backup.base_directory=certificates/backup
344-
dbms.ssl.policy.backup.private_key=/path/to/certificates/backup/private.key
345-
dbms.ssl.policy.backup.public_certificate=/path/to/certificates/backup/public.crt
346331
dbms.ssl.policy.backup.client_auth=REQUIRE
347332
dbms.ssl.policy.backup.tls_versions=TLSv1.2,TLSv1.3
348-
# dbms.ssl.policy.backup.tls_versions=TLSv1.2
349333
dbms.ssl.policy.backup.ciphers=TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
350-
# dbms.netty.ssl.provider=OPENSSL
351-
dbms.netty.ssl.provider=JDK
352-
server.jvm.additional=-Djavax.net.ssl.trustStore=/path/to/certificates/backup/trusted/
353334
----
354335

355336
[TIP]

modules/ROOT/pages/security/ssl-framework.adoc

Lines changed: 22 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -928,7 +928,7 @@ The owner/group should be configured to the user/group that will be running the
928928
Default user/group is neo4j/neo4j.
929929
====
930930
931-
. Set the backup SSL configuration in both _neo4j.conf_ and _neo4j-admin.conf_.
931+
. Set the backup SSL configuration in the _neo4j.conf_ file.
932932
.. Set the backup SSL policy to `true`:
933933
+
934934
[source, properties]
@@ -956,6 +956,27 @@ If the certificate is a different path outside of NEO4J_HOME, then set the absol
956956
dbms.ssl.policy.backup.client_auth=REQUIRE
957957
----
958958
959+
=== Configure the backup client for SSL
960+
961+
When using `neo4j-admin backup` command, you need to specify the SSL policy to be used by the backup client.
962+
You can do this by setting a matching SSL configuration in the _neo4j.conf_ and _neo4j-admin.conf_ files.
963+
This is crucial for the backup to work properly.
964+
For example, if you have set up the backup SSL policy described in section <<ssl-backup-config>>, then you need to set the following in the _neo4j-admin.conf_ file:
965+
966+
[source, properties]
967+
----
968+
dbms.ssl.policy.backup.enabled=true
969+
dbms.ssl.policy.backup.base_directory=/path/to/certificates/backup
970+
dbms.ssl.policy.backup.private_key=private.key
971+
dbms.ssl.policy.backup.public_certificate=public.crt
972+
dbms.ssl.policy.backup.client_auth=REQUIRE
973+
----
974+
975+
[NOTE]
976+
====
977+
Keep in mind that if you are a backup client on a different machine from the Neo4j server, you must also ensure that equivalent SSL certs are installed in both places.
978+
====
979+
959980
[[ssl-other-configs]]
960981
=== Other configurations for SSL
961982

0 commit comments

Comments
 (0)