Secure P4 Search communications with TLS

P4 Search communications should be secured over SSL using the HTTPS protocol. This involves creating a Java keystore with a valid SSL certificate.

You should consider using a valid SSL certificate issued by a trusted Certificate Authority (CA), including the full certificate chain.
  1. Create a certificate signing request (CSR) and private key with the following command:
  2. openssl req -new -newkey rsa:2048 -nodes -keyout server.key -out server.csr

  3. Provide answers to the questions about your organization and the domain you are installing the P4 Search service on.
  4. Send the CSR to your certificate provider to create a valid certificate and chained authority.

    View an existing CSR with the following command:

  5. openssl req -text -noout -verify -in server.csr

  6. Combine the valid certificate and private key to create a PK12 formatted file.

    For example, given a certificate example.com.crt, a chained authority CA.crt and a private key server.key:

    openssl pkcs12 -export -in example.com.crt -inkey server.key -name example.com -out example.com.p12

    Enter [password]

  7. Create or Add the PK12 file to the Java keystore:

    keytool -importkeystore -deststorepass [password] -destkeystore keystore.jks -srckeystore example.com.p12 -srcstoretype PKCS12

    Enter [password]

  8. Bundle the CA.crt:

    keytool -import -alias bundle -trustcacerts -file CA.crt -keystore keystore.jks

    Enter [password]

  9. Migrate to PKCS12:

    keytool -importkeystore -srckeystore keystore.jks -destkeystore keystore.jks -deststoretype pkcs12

    Enter [password]

  10. Copy the keystore to a suitable location and check the file permissions. For example:

    • Windows: c:\Program Files\Perforce
    • Linux: /opt/perforce
  11. Make a note of the keystore location and password for use during the installation or configuration of P4 Search.
  12. Configure the keystore location, password, and protocol:
  13. com.perforce.p4search.service.keystore=<location>
    com.perforce.p4search.service.keypass=[password]
    com.perforce.p4search.service.protocol=https
    

  14. Restart the P4 Search service by running the following command as root:

    sudo systemctl restart p4search.service

  15. P4 Search is now configured for https.