Uploaded image for project: 'ZooKeeper'
  1. ZooKeeper
  2. ZOOKEEPER-4740

I want to use kerberos for Zookeeper, but my authentication has been unsuccessful

    XMLWordPrintableJSON

Details

    • Wish
    • Status: Open
    • Major
    • Resolution: Unresolved
    • 3.5.9
    • None
    • kerberos
    • None

    Description

      zookeeper_jaas.conf

      Server {
       com.sun.security.auth.module.Krb5LoginModule required
       useKeyTab=true
       storeKey=true
       useTicketCache=false
       keyTab="/opt/test2.keytab"
       principal="test2/bigdata.hadoop.master01";
      };Client {
       com.sun.security.auth.module.Krb5LoginModule required
       useKeyTab=true
       keyTab="/opt/test2.keytab"
       principal="test2/bigdata.hadoop.master01"
       useTicketCache=false
       debug=true;
      }; 

      [root@bigdata conf]# cat java.env

      export JVMFLAGS="-Djava.security.auth.login.config=/usr/lib/zookeeper/conf/zookeeper_jaas.conf" 

      /etc/krb5.conf

      # Configuration snippets may be placed in this directory as well
      includedir /etc/krb5.conf.d/[logging]
       default = FILE:/var/log/krb5libs.log
       kdc = FILE:/var/log/krb5kdc.log
       admin_server = FILE:/var/log/kadmind.log[libdefaults]
       dns_lookup_realm = false
       ticket_lifetime = 24h
       renew_lifetime = 7d
       forwardable = true
       rdns = false
       default_realm = EXAMPLE.COM
       default_ccache_name = KEYRING:persistent:%{uid}[realms]
       EXAMPLE.COM = {
        kdc = bigdata.hadoop.master01
        admin_server = bigdata.hadoop.master01
       }[domain_realm]
      .bigdata.hadoop.master01 = EXAMPLE.COM
      bigdata.hadoop.master01 = EXAMPLE.COM 

       

       

      When I use a client connection:

      zookeeper-client -server localhost:12181 

      the connection log of the client is attached

      Attachments

        1. client_connection.log
          9 kB
          LiJie2023
        2. image-2023-09-01-16-37-20-848.png
          38 kB
          LiJie2023

        Activity

          People

            Unassigned Unassigned
            lijie1912 LiJie2023
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: