> ## Documentation Index
> Fetch the complete documentation index at: https://clickhouse.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ClickHouse とZooKeeper間のセキュアなSSL/TLS通信を設定するためのガイド

# ClickHouseとZooKeeper間のオプションのセキュアな通信

export const CloudNotSupportedBadge = () => {
  return <div className="cloudNotSupportedBadge">
            <div className="cloudNotSupportedIcon">
            <svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">
                <path strokeWidth="1.5" d="M6.33366 12.6666L12.3739 12.6667C13.6593 12.6667 14.7073 11.6187 14.7073 10.3334C14.7073 9.04804 13.6593 8.00003 12.3739 8.00003C12.3739 8.00003 12.3337 7.66659 12.0003 7.33325M10.667 5.33322C8.00033 2.33325 4.45395 4.78537 4.14195 6.68203C2.55728 6.7627 1.29395 8.06203 1.29395 9.6667C1.29395 11.3234 2.66699 12.6666 4.00033 12.6666" stroke="currentColor" strokeLinecap="round" strokeLinejoin="round" />
                <path strokeWidth="1.5" d="M2.66699 14L12.0003 4.66663" stroke="currentColor" strokeLinecap="round" strokeLinejoin="round" />
            </svg>

        </div>
            ClickHouse Cloud では利用できません
        </div>;
};

<CloudNotSupportedBadge />

<Note>
  このページは[ClickHouse Cloud](https://clickhouse.com/cloud)には該当しません。ここで説明している手順は、ClickHouse Cloud サービスでは自動化されています。
</Note>

SSL 経由で ClickHouse client と通信するには、`ssl.keyStore.location`、`ssl.keyStore.password`、`ssl.trustStore.location`、`ssl.trustStore.password` を指定する必要があります。これらのオプションは ZooKeeper バージョン 3.5.2 以降で利用できます。

`zookeeper.crt` を信頼済み証明書に追加できます。

```bash theme={null}
sudo cp zookeeper.crt /usr/local/share/ca-certificates/zookeeper.crt
sudo update-ca-certificates
```

`config.xml` のクライアントセクションは次のようになります。

```xml theme={null}
<client>
    <certificateFile>/etc/clickhouse-server/client.crt</certificateFile>
    <privateKeyFile>/etc/clickhouse-server/client.key</privateKeyFile>
    <loadDefaultCAFile>true</loadDefaultCAFile>
    <cacheSessions>true</cacheSessions>
    <disableProtocols>sslv2,sslv3</disableProtocols>
    <preferServerCiphers>true</preferServerCiphers>
    <invalidCertificateHandler>
        <name>RejectCertificateHandler</name>
    </invalidCertificateHandler>
</client>
```

いくつかのクラスター設定とマクロを含めて、ZooKeeper を ClickHouse の設定に追加します:

```xml theme={null}
<clickhouse>
    <zookeeper>
        <node>
            <host>localhost</host>
            <port>2281</port>
            <secure>1</secure>
        </node>
    </zookeeper>
</clickhouse>
```

`clickhouse-server` を起動します。ログに次のように表示されます。

```text theme={null}
<Trace> ZooKeeper: initialized, hosts: secure://localhost:2281
```

プレフィックス `secure://` は、接続が SSL で保護されていることを示します。

トラフィックが暗号化されているか確認するには、保護されたポートで `tcpdump` を実行します:

```bash theme={null}
tcpdump -i any dst port 2281 -nnXS
```

`clickhouse-client` でクエリを実行します:

```sql theme={null}
SELECT * FROM system.zookeeper WHERE path = '/';
```

暗号化されていない接続では、`tcpdump` の出力に次のような内容が表示されます。

```text theme={null}
..../zookeeper/quota.
```

暗号化接続では、これは表示されないはずです。
