security.ssl.algorithms |
"TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384" |
The comma separated list of standard SSL algorithms to be supported. Read more <a href="http://docs.oracle.com/javase/8/docs/technotes/guides/security/StandardNames.html#ciphersuites">here</a>. |
security.ssl.enabled |
false |
Turns on SSL for internal network communication. This can be optionally overridden by flags defined in different transport modules. |
security.ssl.key-password |
(none) |
The secret to decrypt the server key in the keystore. |
security.ssl.keystore |
(none) |
The Java keystore file to be used by the flink endpoint for its SSL Key and Certificate. |
security.ssl.keystore-password |
(none) |
The secret to decrypt the keystore file. |
security.ssl.protocol |
"TLSv1.2" |
The SSL protocol version to be supported for the ssl transport. Note that it doesn’t support comma separated list. |
security.ssl.truststore |
(none) |
The truststore file containing the public CA certificates to be used by flink endpoints to verify the peer’s certificate. |
security.ssl.truststore-password |
(none) |
The secret to decrypt the truststore. |
security.ssl.verify-hostname |
true |
Flag to enable peer’s hostname verification during ssl handshake. |