-
Notifications
You must be signed in to change notification settings - Fork 411
CloudBeaver SSL certificate configuration
dbeaver-devops edited this page Mar 7, 2025
·
5 revisions
The instance contains an Nginx proxy server, the configuration of which is located at path /etc/nginx/conf.d/cloudbeaver.conf
To set up a connection via HTTPS with domain:
- You need to create or buy a valid TLS certificate for your domain endpoint.
- After you get SSL certificate for your domain you must put it to
/etc/nginx/ssl/fullchain.pem
as certificate and/etc/nginx/ssl/privkey.pem
as a private key. - Change
server_name _;
in configuration/etc/nginx/conf.d/cloudbeaver.conf
toserver_name <your-domain>;
- Enter in terminal
sudo systemctl reload nginx.service
to reload Nginx proxy - Now you can open your
CloudBeaver Server
from the browser using your domain address.
Tip: If you need to change Java security properties, for example, to enable TLS 1.0, see how to change Java security properties for details.
Self-signed certificates are considered insecure for the Internet. Firefox will treat the site as having an invalid certificate, while Chrome will act as if the connection was plain HTTP
You can create self-signed certificate for <your-domain>
by running the following script in the terminal:
SECRET_CERT_CSR="/C=US/ST=NY/L=NYC/O=CloudBeaver /OU=IT Department/CN=<your-domain>"
cd /etc/nginx/
mkdir ssl
cd ssl
sudo openssl req -x509 -sha256 -nodes -days 36500 -subj "$SECRET_CERT_CSR" -newkey rsa:2048 -keyout privkey.pem -out fullchain.pem
-
Administration
- Server configuration
- Create Connection
- Connection Templates Management
- Access Management
-
Authentication methods
-
Local Access Authentication
- Anonymous Access Configuration
- Reverse proxy header authentication
- LDAP
-
Single Sign On
-
SAML
-
OpenID
-
AWS OpenID
-
AWS SAML
-
AWS IAM
-
AWS OpenId via Okta
-
Snowflake SSO
-
Okta OpenId
-
Cognito OpenId
-
JWT authentication
-
Kerberos authentication
-
NTLM
-
Microsoft Entra ID authentication
-
Google authentication
-
Local Access Authentication
- Database authentication methods
- Network configuration settings
- User credentials storage
- Cloud databases configuration
-
Query Manager
-
Drivers Management
-
Features
- Server configuration
-
Domain manager
- Product configuration parameters
- Command line parameters
- Local Preferences
- API
- Deployment options
- Additional setup and management