0 前言
如果沒有安裝Kerberos或者想讓cdh開啓Kerberos 認證的可以查看CDH5安装Kerberos认证
1 介质
下載地址:http://mirror.centos.org/centos/7/os/x86_64/Packages/
压缩包中包含下面文件
2 关闭KDC服务
systemctl stop krb5kdc
systemctl stop kadmin
3 查看当前版本
在kdc安装所在机器上面执行下面脚本
rpm -qa | grep krb5
4 卸载(所有节点)
rpm -e krb5-devel-1.15.1-18.el7.x86_64 --nodeps
rpm -e krb5-libs-1.15.1-18.el7.x86_64 --nodeps
rpm -e krb5-workstation-1.15.1-18.el7.x86_64 --nodeps
rpm -e libkadm5-1.15.1-18.el7.x86_64 –nodeps
#只在服务端多执行下面命令
rpm -e krb5-server-1.15.1-18.el7.x86_64 –nodeps
5 安装(所有节点)
rpm -ivh krb5-libs-1.15.1-50.el7.x86_64.rpm
rpm -ivh libkadm5-1.15.1-50.el7.x86_64.rpm
rpm -ivh krb5-devel-1.15.1-50.el7.x86_64.rpm
rpm -ivh krb5-workstation-1.15.1-50.el7.x86_64.rpm
#只在服务端多执行下面命令
rpm -ivh krb5-server-1.15.1-50.el7.x86_64.rpm
6 修改配置文件
只在服务端执行
mv /etc/krb5.conf /etc/krb5.conf.bakup.50
mv /etc/krb5.conf.rpmsave /etc/krb5.conf
mv /var/kerberos/krb5kdc/kdc.conf.rpmsave /var/kerberos/krb5kdc/kdc.conf
mv /var/kerberos/krb5kdc/kadm5.acl.rpmsave /var/kerberos/krb5kdc/kadm5.acl
7 拷贝配置文件
将KDC Server上的krb5.conf文件拷贝到所有Kerberos客户端
以namenode01为例:
scp /etc/krb5.conf root@namenode01:/etc
8 启动kerberos服务
#启动
systemctl start krb5kdc
systemctl start kadmin
查看状态
systemctl status krb5kdc
systemctl status kadmin
9 验证
kinit admin/admin@HADOOP.COM
klist
10.kerberos系列
CDH5安装Kerberos认证
升级kerberos
windows下火狐浏览器中配置kerberos客户端
CDH禁用kerberos
卸载kerberos