OpenCTI-Platform / opencti

Open Cyber Threat Intelligence Platform
https://opencti.io
Other
6.32k stars 933 forks source link

Not able to set HTTPS #8716

Open nhs1925 opened 5 days ago

nhs1925 commented 5 days ago

Prerequisites

Description

I get errors when I try to set certificates not to be accessed by HTTP but by HTTPS. I have tried with my own configuration and with this one (copied from another post), but I can't get it to support it.

I've been looking in the guide but I find nothing

Environment

  1. OS (where OpenCTI server runs): Ubuntu Server 22.04 Virtualized VMware
  2. OpenCTI version: opencti/platform:6.3.6
  3. OpenCTI client: { e.g. frontend or python }
  4. Other environment details:

Reproducible Steps

Steps to create the smallest reproducible scenario:

  1. { e.g. Run ... }
  2. { e.g. Click ... }
  3. { e.g. Error ... }

Error: Failed to deploy a stack: Network opencti_default Creating Network opencti_default Created Container opencti-elasticsearch-1 Creating Container opencti-redis-1 Creating Container opencti-rabbitmq-1 Creating Container opencti-minio-1 Creating Container opencti-elasticsearch-1 Created Container opencti-redis-1 Created Container opencti-rabbitmq-1 Created Container opencti-minio-1 Created Container opencti-opencti-1 Creating Container opencti-opencti-1 Created Container opencti-connector-import-document-1 Creating Container opencti-connector-import-file-stix-1 Creating Container opencti-connector-export-file-stix-1 Creating Container opencti-worker-3 Creating Container opencti-connector-export-file-csv-1 Creating Container opencti-worker-1 Creating Container opencti-worker-2 Creating Container opencti-connector-analysis-1 Creating Container opencti-connector-export-file-txt-1 Creating Container opencti-connector-import-document-1 Created Container opencti-connector-import-file-stix-1 Created Container opencti-worker-1 Created Container opencti-connector-export-file-csv-1 Created Container opencti-connector-export-file-stix-1 Created Container opencti-connector-analysis-1 Created Container opencti-worker-3 Created Container opencti-connector-export-file-txt-1 Created Container opencti-worker-2 Created Container opencti-rabbitmq-1 Starting Container opencti-redis-1 Starting Container opencti-minio-1 Starting Container opencti-elasticsearch-1 Starting Container opencti-rabbitmq-1 Started Container opencti-elasticsearch-1 Started Container opencti-redis-1 Started Container opencti-minio-1 Started Container opencti-minio-1 Waiting Container opencti-rabbitmq-1 Waiting Container opencti-redis-1 Waiting Container opencti-elasticsearch-1 Waiting Container opencti-redis-1 Healthy Container opencti-minio-1 Healthy Container opencti-elasticsearch-1 Healthy Container opencti-rabbitmq-1 Healthy Container opencti-opencti-1 Starting Container opencti-opencti-1 Started Container opencti-opencti-1 Waiting Container opencti-opencti-1 Waiting Container opencti-opencti-1 Waiting Container opencti-opencti-1 Waiting Container opencti-opencti-1 Waiting Container opencti-opencti-1 Waiting Container opencti-opencti-1 Waiting Container opencti-opencti-1 Error Container opencti-opencti-1 Error Container opencti-opencti-1 Error Container opencti-opencti-1 Error Container opencti-opencti-1 Error Container opencti-opencti-1 Error Container opencti-opencti-1 Error dependency failed to start: container opencti-opencti-1 is unhealthy

Additional information

Configuration .yml services: redis: image: redis:7.4.0 restart: always volumes:

volumes: esdata: s3data: redisdata: amqpdata:

Variables: OPENCTI_ADMIN_EMAIL=admin@opencti.io OPENCTI_ADMIN_PASSWORD=** OPENCTI_ADMIN_TOKEN=95cea3ee-fe44-403b-8571-726a488f366f OPENCTI_BASE_URL=http://localhost:8080 OPENCTI_HEALTHCHECK_ACCESS_KEY= MINIO_ROOT_USER=opencti MINIO_ROOT_PASSWORD=***** RABBITMQ_DEFAULT_USER=opencti RABBITMQ_DEFAULT_PASS=** CONNECTOR_EXPORT_FILE_STIX_ID=d8eba972-a82a-4e10-bf62-4955b7256981 CONNECTOR_EXPORT_FILE_CSV_ID=c46b5f2f-c1e0-4fde-a29a-48a086f89536 CONNECTOR_EXPORT_FILE_TXT_ID=259ee64a-74f1-4f4f-91f1-61b80072e499 CONNECTOR_IMPORT_FILE_STIX_ID=4184c39d-5c22-47a4-9a4a-8801903c3b9d CONNECTOR_IMPORT_DOCUMENT_ID=7e961042-7339-4e84-acc4-4d45c98e6259 CONNECTOR_ANALYSIS_ID=b3528b52-ab81-44fd-bdfc-07e4d63cefd1 SMTP_HOSTNAME=localhost ELASTIC_MEMORY_SIZE=4G OPENCTI_KEY_PATH=/etc/ssl/certs/opencti/ca.key OPENCTI_CRT_PATH=/etc/ssl/certs/opencti/ca.crt

harboot commented 1 day ago

dependency failed to start: container opencti-opencti-1 is unhealthy same issue with me..

fixed by change this OPENCTI_ADMIN_TOKEN=95cea3ee-fe44-403b-8571-726a488f366f follow UUIDv4 format.