1.安装密钥分发中心KDC
[root@hadoop102 /]# yum install krb5-server krb5-libs krb5-workstation
2.配置KDC
<1>配置krb5.conf文件
[root@hadoop102 ~]# vim /etc/krb5.conf
<2>配置kdc.conf文件
[root@hadoop102 /]# cd /var/kerberos/krb5kdc/
[root@hadoop102 krb5kdc]# vim kdc.conf
3.创建KDC数据库
[root@hadoop101 /]# kdb5_util create -r HADOOP -s
4.配置Kerberos管理员
(1)配置管理员标识
[root@hadoop102 ~]# vim /var/kerberos/krb5kdc/kadm5.acl
(2)设置Kerberos管理员
[root@hadoop102 ~]# kadmin.local
kadmin.local: addprinc -randkey root/hadoop102@HADOOP.COM
5.添加用户和服务标识
kadmin.local: addprinc -randkey root/hadoop102@HADOOP.COM
kadmin.local: addprinc -randkey host/hadoop102@HADOOP.COM
kadmin.local: addprinc -randkey HTTP/hadoop102@HADOOP.COM
6.创建用于hadoop服务的keytab文件
kadmin.local: xst -norandkey -k root.keytab root/hadoop102@HADOOP.COM
kadmin.local: xst -norandkey -k root.keytab host/hadoop102@HADOOP.COM
kadmin.local: xst -norandkey -k root.keytab HTTP/hadoop102@HADOOP.COM