主机列表
主机名称 IP 硬件配置
pass-eda-hdp-001 10.218.12.14 80 Core、256 G
pass-eda-hdp-003 10.218.12.18 80 Core、256 G
软件清单
软件名称 版本号 备注
krb5-server 1.15.1
krb5-workstation 1.15.1 主备之间同步数据文件用
主机规划
主机 角色 软件
10.218.12.14 主 krb5-server
10.218.12.18 备 krb5-workstation
安装部署
服务安装
在两台机器上面分别安装kerberos服务。此处只安装服务,暂不做相应配置及启动服务。
yum install krb5-server krb5-workstation -y
1
修改配置
这里配置文件均在主备两台同时修改。
配置/etc/krb5.conf
# Configuration snippets may be placed in this directory as well
includedir /etc/krb5.conf.d/
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
dns_lookup_realm = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
rdns = false
pkinit_anchors = /etc/pki/tls/certs/ca-bundle.crt
default_realm = HLJ.CTC
default_ccache_name = KEYRING:persistent:%{uid}
[realms]
HLJ.CTC = {
kdc = pass-eda-hdp-001
kdc = pass-eda-hdp-003
admin_server = pass-eda-hdp-001
}
[domain_realm]
.hlj.ctc = HLJ.CTC
hlj.ctc = HLJ.CTC
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20