MetaDefender Distributed Cluster Identity Service

Ignition file

Info

The ignition file is required only for a fresh installation.

To install MetaDefender Distributed Cluster Identity Service server, ignition file in YML format is required at the following location:

  • Windows: C:\opswat\mddc_identity_service.yml

  • Linux: /etc/opswat/mddc_identity_service.yml

The ignition file includes keys

Key path

Value type

Accepted values

Required

Description

secure.connection_key

string

A string from 4 to 64 character long containing digits from 0 to 9 and characters from a/A to z/Z

required

An arbitrary string that enables clients to connect to the server.

Use this value for the key identity.connection_key in configuration file of MetaDefender Distributed Cluster Control Center.

secure.private_key

string


required

Content of private key in X509 format.

secure.certificate

string


required

Content of certificate in X509 format.

database.host

string


required

IP address / domain name of the server where PostgreSQL server locates.

database.port

number


required

Port of PostgreSQL server is listening for connections from clients.

database.user

string


required

PostgreSQL server's user.

SUPERUSER privilege is required to setup the server's database and extensions for the first time.

database.password

string


required

PostgreSQL server's user credentials.

rest.host

string


optional

IP address (V4/V6) or host where the server resides on. Default value is '*'

Notes: value '*'allows the service to accept connections from all network interfaces.

To bind the service to a specific interface, specify its IP address or domain name. For example, to listen on all IPv4 interfaces, set the host to 0.0.0.0

rest.port

number


optional

The port where the server resides on. Default value is 8891

log.streams[@].log_type

string

  • file

  • syslog

optional

Type of log device.

log.streams[@].log_level

string

  • dump

  • debug

  • info

  • warning

  • error

optional

Level of log message.

log.streams[@].log_path

string

If log.streams[@].log_type is "file" then log.streams[@].log_path is the path to a file on file system where logs are written.

If log.streams[@].log_type is "syslog" then

  • log.streams[@].log_path can be [tcp/udp]://host:port where host:port is the host and port to a remote syslog server that supports TCP or UDP protocol.

  • log.streams[@].log_path can be "local" to write log to local syslog server (Linux only).

optional

Location where logs are written.

user.name

string


optional

User name for the initial administrator user account.

user.password

string


optional

Password for the initial administrator user account.

user.email

string

Basic email format, a string starts with non whitespace/non @ characters, contains one @symbol, and ends with non whitespace/non @ characters.

optional

E-mail address for the initial administrator user account.

user.apikey

string

string of exactly 36 characters composed of uppercase and lowercase letters (A-Z, a-z) and digits (0-9)

optional

API key for the initial administrator user account.

Configuration file

After successfully installing, MetaDefender Distributed Cluster Identity Service generates a configuration file with changeable settings at the following location

  • Windows: C:\Program Files\OPSWAT\MetaDefender Distributed Cluster Identity Service\mddc_identity_service.yml

  • Linux: /etc/mddc-identity-service/mddc_identity_service.yml

Info

The service must be restarted to take the new configurations into effect.

Sample

Warning

database.host, database.port, database.user, and database.password should be updated with the appropriate values of your Postgres host/IP, port, username, and password.

Info

OpenSSL or a similar tool (e.g., ssh-keygen) can create a pair of public and private keys in X.509 format.

database:
host: "your_postgres_host"
port: 5432
user: "your_postgres_username"
password: "your_postgres_admin_password"
secure:
connection_key: "1234abcd" # [0-9a-zA-Z]{4,64}
certificate: |
-----BEGIN CERTIFICATE-----
MIIF5jCCA86gAwIBAgIJANq50IuwPFKgMA0GCSqGSIb3DQEBCwUAMIGGMQswCQYD
VQQGEwJHQjEQMA4GA1UECAwHRXJld2hvbjETMBEGA1UEBwwKQWxsIGFyb3VuZDEb
MBkGA1UECgwSbGlid2Vic29ja2V0cy10ZXN0MRIwEAYDVQQDDAlsb2NhbGhvc3Qx
HzAdBgkqhkiG9w0BCQEWEG5vbmVAaW52YWxpZC5vcmcwIBcNMTgwMzIwMDQxNjA3
WhgPMjExODAyMjQwNDE2MDdaMIGGMQswCQYDVQQGEwJHQjEQMA4GA1UECAwHRXJl
d2hvbjETMBEGA1UEBwwKQWxsIGFyb3VuZDEbMBkGA1UECgwSbGlid2Vic29ja2V0
cy10ZXN0MRIwEAYDVQQDDAlsb2NhbGhvc3QxHzAdBgkqhkiG9w0BCQEWEG5vbmVA
aW52YWxpZC5vcmcwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCjYtuW
aICCY0tJPubxpIgIL+WWmz/fmK8IQr11Wtee6/IUyUlo5I602mq1qcLhT/kmpoR8
Di3DAmHKnSWdPWtn1BtXLErLlUiHgZDrZWInmEBjKM1DZf+CvNGZ+EzPgBv5nTek