【Kafka SASL认证】

条件:
  • 注:先安装Zookeeper和Kafka
  • 链接:https://blog.csdn.net/ZhongYuxuanG

Kafka配置SASL认证:

1.创建文件中配置用户

①.kafka/config/下创建kafka_client_jaas.conf文件:
KafkaClient {  
org.apache.kafka.common.security.plain.PlainLoginModule required  
  username="admin"  
  password="admin";  
};
②.kafka/config/下创建kafka_server_jaas.conf文件:
KafkaServer {
        org.apache.kafka.common.security.plain.PlainLoginModule required
        username="admin"
        password="admin"
        user_admin="admin"
        user_test1="123456"
        user_test2="1234567";
};

KafkaClient {
	org.apache.kafka.common.security.plain.PlainLoginModule required
		username="admin"
		password="admin";
};

Client {
	org.apache.kafka.common.security.plain.PlainLoginModule required
		username="admin"
		password="admin";
};
③.kafka/config/下创建kafka_zoo_jaas.conf文件:
ZKServer{
	org.apache.kafka.common.security.plain.PlainLoginModule required
		username="admin"
		password="admin"
		user_admin="admin";
};
④.kafka/config/consumer.properties文件,添加下面内容:
security.protocol=SASL_PLAINTEXT
sasl.mechanism=PLAIN
⑤.kafka/config/producer.properties文件,添加下面内容:
security.protocol=SASL_PLAINTEXT
sasl.mechanism=PLAIN
⑥.kafka/config/zookeeper.properties文件,添加下面内容:
authProvider.1=org.apache.zookeeper.server.auth.SASLAuthenticationProvider
requireClientAuthScheme=sasl
jaasLoginRenew=3600000
⑦.kafka/config/server.properties文件,添加下面内容:
listeners=SASL_PLAINTEXT://ip:9092
security.inter.broker.protocol=SASL_PLAINTEXT
sasl.enabled.mechanisms=PLAIN
sasl.mechanism.inter.broker.protocol=PLAIN
authorizer.class.name=kafka.security.auth.SimpleAclAuthorizer
super.users=User:admin
delete.topic.enable=true
auto.create.topics.enable=false

2.修改Kafka的bin文件(注意:里面有自己的路径需要修改)

①.修改zookeeper-server-start.sh文件:
export KAFKA_OPTS="-Djava.security.auth.login.config=/自己的路径/kafka_2.11-0.11.0.0/config/kafka_zoo_jaas.conf -Dzookeeper.sasl.serverconfig=ZKServer"
②.修改kafka-server-start.sh文件:
export KAFKA_OPTS=" -Djava.security.auth.login.config=/自己的路径/kafka_2.11-0.11.0.0/config/kafka_server_jaas.conf"
③.修改kafka-console-producer.sh文件:
export KAFKA_OPTS=" -Djava.security.auth.login.config=/自己的路径/kafka_2.11-0.11.0.0/config/kafka_client_jaas.conf"
④.修改kafka-console-consumer.sh文件:
export KAFKA_OPTS=" -Djava.security.auth.login.config=/自己的路径/kafka_2.11-0.11.0.0/config/kafka_client_jaas.conf"

3.启动

①.启动zookeeper:
bin/zookeeper-server-start.sh config/zookeeper.properties
②.启动kafka:
bin/kafka-server-start.sh config/server.properties

4.生产、消费

①.生产:
bin/kafka-console-producer.sh --broker-list ip:9092 --topic test --producer.config config/producer.properties
①.消费:
bin/kafka-console-consumer.sh --bootstrap-server ip:9092 --topic test --from-beginning --consumer.config config/consumer.properties
  • 3
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值