Sicherheit in verteilten Systemen und Cookies
Sichern Sie die Kommunikation zwischen verteilten Erlang-Knoten mit Magic Cookies, Knotennamen und TLS für die Distribution.
Sicherheit in verteilten Systemen und Cookies ist eine kostenlose Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Kurs umfasst insgesamt 4 Lektionen.
Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.
Trust in a Cluster
Connected Erlang nodes fully trust each other: any node can run code on any other. That power makes securing distribution essential.
The Magic Cookie
Each node has a secret cookie. Two nodes can only connect if their cookies match. It is the basic authentication mechanism for clustering.
erlang:get_cookie().
% => 'SECRETCOOKIE'Setting the Cookie
You can set the cookie at startup or at runtime. All nodes that should cluster must share the same value.
% at startup:
% erl -setcookie SECRET -name node1@host
erlang:set_cookie(node(), 'SECRET').The .erlang.cookie File
If not set explicitly, the VM reads ~/.erlang.cookie. It must have restrictive permissions or the VM refuses to start.
% chmod 400 ~/.erlang.cookieShort vs Long Names
Nodes use -sname (short hostname) or -name (fully qualified). Both nodes must use the same scheme to connect.
% erl -sname worker
% erl -name worker@10.0.0.5Cookies Are Not Encryption
A matching cookie only authenticates the connection. By default, traffic between nodes is unencrypted. On untrusted networks you need TLS.
TLS Distribution
Erlang can tunnel all inter-node traffic over TLS using the inet_tls_dist module, configured via a proto_dist flag and a certificate file.
% erl -proto_dist inet_tls \
% -ssl_dist_optfile ssl_dist.conf \
% -name node1@hostThe ssl_dist Config
The config file points to your certificate, key, and CA so nodes mutually authenticate and encrypt.
[{server, [{certfile, "node.pem"},
{keyfile, "node.key"},
{cacertfile, "ca.pem"}]},
{client, [{cacertfile, "ca.pem"}]}].Restricting epmd Exposure
The Erlang Port Mapper Daemon (epmd) registers node ports. Never expose epmd or distribution ports to the public internet; firewall them or use a VPN.
Hidden Nodes
A node started with -hidden connects without joining the global mesh, useful for tools that should not be part of the cluster's full-trust topology.
% erl -hidden -name monitor@hostSecurity Checklist
For safe distribution:
- Use a strong, unique cookie
- Protect the cookie file (chmod 400)
- Enable TLS on untrusted networks
- Firewall epmd and distribution ports
Quick Check
Test your distribution security knowledge.
Recap
You learned to secure distributed Erlang.
- Matching cookies authenticate nodes
- Protect the
.erlang.cookiefile - Use TLS distribution for encryption
- Firewall epmd and distribution ports
Lerne Erlang mit einem KI-Tutor — kostenlos
Schreibe und führe echten Code in deinem Browser aus, bekomme sofortige Hilfe von einem 24/7 KI-Tutor und setze dein Lernen im Web oder in der App fort.
- Kurse
- 12
- Lektionen
- 48
Häufig gestellte Fragen
Ist die Lektion „Sicherheit in verteilten Systemen und Cookies“ kostenlos?
Ja — der vollständige Text von „Sicherheit in verteilten Systemen und Cookies“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Kurs umfasst insgesamt 4 Lektionen.
Was lerne ich in „Sicherheit in verteilten Systemen und Cookies“?
Sichern Sie die Kommunikation zwischen verteilten Erlang-Knoten mit Magic Cookies, Knotennamen und TLS für die Distribution. Du übst Erlang OTP: Distributed & Fault-Tolerant Systems Programming mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.
Brauche ich Erfahrung, um Erlang OTP: Distributed & Fault-Tolerant Systems Programming zu starten?
Keine Vorkenntnisse erforderlich. Erlang OTP: Distributed & Fault-Tolerant Systems Programming auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.
Wie lange dauert die Lektion „Sicherheit in verteilten Systemen und Cookies“?
Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.
Kann ich in dieser Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Lektion Code schreiben und ausführen?
Ja. Jede Erlang OTP: Distributed & Fault-Tolerant Systems Programming-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.
Alle Lektionen in diesem Kurs
- Knotenkommunikation und Einrichtung
- Remote Procedure Calls (RPC)
- Globale Prozessregistrierung
- Sicherheit in verteilten Systemen und Cookies