From c8806dbb4d831a1b6eb9e33edc654e89dfb95c83 Mon Sep 17 00:00:00 2001 From: luhe Date: Wed, 21 Sep 2022 16:09:04 +0800 Subject: [PATCH] =?UTF-8?q?=E4=BF=AE=E6=94=B9=E4=BB=A3=E7=A0=81=E6=94=AF?= =?UTF-8?q?=E6=8C=81ZK-Kerberos=E8=AE=A4=E8=AF=81=E4=B8=8E=E9=85=8D?= =?UTF-8?q?=E7=BD=AE=E6=96=87=E6=A1=A3?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- docs/zk_kerberos/zk支持Kerberos配置文档.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/docs/zk_kerberos/zk支持Kerberos配置文档.md b/docs/zk_kerberos/zk支持Kerberos配置文档.md index 8ba235fa..ad70861c 100644 --- a/docs/zk_kerberos/zk支持Kerberos配置文档.md +++ b/docs/zk_kerberos/zk支持Kerberos配置文档.md @@ -16,12 +16,19 @@ https://github.com/didi/KnowStreaming/blob/master/docs/install_guide/%E6%BA%90%E 5、可以登录后,配置/opt/zookeeper.jass文件: Client { + com.sun.security.auth.module.Krb5LoginModule required + useKeyTab=true + storeKey=false + serviceName="zookeeper" + keyTab="/etc/keytab/zookeeper.keytab" + principal="kafka/dbs-kafka-test-8-53@XXX.XXX.XXX"; + }; 6、需要配置KDC-Server对KS的机器开通防火墙,并在KS的机器/etc/host/ 配置 kdc-server的hostname。并将 krb5.conf 导入到/etc下