kafka添加ssl认证

本文介绍了如何为Kafka设置SSL认证,包括安装java和openssl,执行生成证书的ca.sh脚本,修改Kafka配置文件,启动Zookeeper和Kafka,并创建SSL启用的主题、生产者和消费者配置文件。
摘要由CSDN通过智能技术生成

主要是生成证书:

请先安装java和openssl.

生成证书脚本ca.sh:

#!/bin/bash
#Step 1
keytool -keystore /var/soft/ca/server.keystore.jks -alias localhost -validity 365 -genkey
#Step 2
openssl req -new -x509 -keyout ca-key -out ca-cert -days 365
keytool -keystore /var/soft/ca/server.truststore.jks -alias CARoot -import -file ca-cert
keytool -keystore /var/soft/ca/client.truststore.jks -alias CARoot -import -file ca-cert
#Step 3
keytool -keystore /var/soft/ca/server.keystore.jks -alias localhost -certreq -file cert-file
openssl x509 -req -CA ca-cert -CAkey ca-key -in cert-file -out cert-signed -days 365 -CAcreateserial -passin pass:123456
keytool -keystore /var/soft/ca/server.keystore.jks -alias CARoot -import -file ca-cert
keytool -keystore /var/soft/ca/server.keystore.jks -alias localhost -import -file cert-signed



这里强调下,在执行脚本过程中会让你输入你的first,lastname,这里应该填你的域名:比如localhost或者xx.com

脚本执行完成了之后,先启动zookeeper.然后修改kafka配置文件,我的配置文件如下 :

# Licensed to the Apache Software Foundation (ASF) under one or more
# contributor license agreements.  See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to You under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License.  You may obtain a copy of the License at
#
#    http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

# see kafka.server.KafkaConfig for additional details and defaults

############################# Server Basics #############################
#主要是修改的下面部分:记住,SSL后面不应该是ip.而是你刚设置的域名。比如这里是localhost
# The id of the broker. This must be set to a 
  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值