zoukankan      html  css  js  c++  java
  • Kafka SSL 配置

    #!/bin/bash

    # 生成服务器keystore(密钥和证书)
    keytool -keystore server.keystore.jks -alias machine03.zheng.com -validity 365 -keyalg RSA -storepass leonzheng -keypass leonzheng -genkey -dname "C=CN,ST=FJ,L=FZ,O=LEON,OU=LEON,CN=ZHENG.COM"
    # 生成客户端keystore(密钥和证书)
    keytool -keystore client.keystore.jks -alias machine03.zheng.com -validity 365 -keyalg RSA -storepass leonzheng -keypass leonzheng -genkey -dname "C=CN,ST=FJ,L=FZ,O=LEON,OU=LEON,CN=ZHENG.COM"
    # 创建CA证书
    openssl req -new -x509 -keyout ca.key -out ca.crt -days 365 -passout pass:leonzheng -subj "/C=CN/ST=FJ/L=FZ/O=LEON/OU=LEON/CN=ZHENG.COM"
    # 将CA证书导入到服务器truststore
    keytool -keystore server.truststore.jks -alias CARoot -import -file ca.crt -storepass leonzheng
    # 将CA证书导入到客户端truststore
    keytool -keystore client.truststore.jks -alias CARoot -import -file ca.crt -storepass leonzheng
    # 导出服务器证书
    keytool -keystore server.keystore.jks -alias machine03.zheng.com -certreq -file cert-file -storepass leonzheng
    keytool -keystore client.keystore.jks -alias machine03.zheng.com -certreq -file client-cert-file -storepass leonzheng
    # 用CA证书给服务器证书签名
    openssl x509 -req -CA ca.crt -CAkey ca.key -in cert-file -out cert-signed -days 365 -CAcreateserial -passin pass:leonzheng
    openssl x509 -req -CA ca.crt -CAkey ca.key -in client-cert-file -out client-cert-signed -days 365 -CAcreateserial -passin pass:leonzheng
    # 将CA证书导入服务器keystore
    keytool -keystore server.keystore.jks -alias CARoot -import -file ca.crt -storepass leonzheng
    keytool -keystore client.keystore.jks -alias CARoot -import -file ca.crt -storepass leonzheng
    # 将已签名的服务器证书导入服务器keystore
    keytool -keystore server.keystore.jks -alias machine03.zheng.com -import -file cert-signed -storepass leonzheng
    keytool -keystore client.keystore.jks -alias machine03.zheng.com -import -file client-cert-signed -storepass leonzheng

    验证ssl
    openssl s_client -debug -connect 192.168.12.33:9093 -tls1
    openssl s_client -debug -connect 192.168.12.33:9092 -tls1


    config/server.properties

    ssl.client.auth=required
    ssl.keystore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/server.keystore.jks
    ssl.keystore.password=leonzheng
    ssl.key.password=leonzheng
    ssl.truststore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/server.truststore.jks
    ssl.truststore.password=leonzheng

    clientssl.properties

    security.protocol=SSL
    ssl.truststore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/client.truststore.jks
    ssl.truststore.password=leonzheng
    ssl.keystore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/client.keystore.jks
    ssl.keystore.password=leonzheng
    ssl.key.password=leonzheng

    bin/kafka-topics.sh --zookeeper 192.168.12.33:2181,192.168.12.33:2182,192.168.12.33:2183/kafka --create --topic testssl --partitions 3 --replication-factor 1

    bin/kafka-console-producer.sh --broker-list 192.168.12.33:9093 --topic testssl --producer.config /usr/local/kafka_2.11-0.10.1.0/ssl/clientssl.properties

    bin/kafka-console-consumer.sh --bootstrap-server 192.168.12.33:9093 --topic testssl --from-beginning --consumer.config /usr/local/kafka_2.11-0.10.1.0/ssl/clientssl.properties

    required的适用于对客户端安全验证比较严格的场景,比如某些操作只能由特定的设备发起才能被允许访问资源
    requested适用于对客户端安全验证比较宽松的场景,客户端可以决定是否提供验证信息,如果未提供或已提供未通过,仍然允许访问资源
  • 相关阅读:
    教你怎么做游戏运营数据分析
    经验|数据分析告诉我们的四个经验教训
    hdu 2074 叠筐 好有意思的绘图题
    asp 之 让实体中字段类型为DateTime的字段仅仅显示日期不显示时间
    将字符串中不同字符的个数打印出来
    Cocos2d-x 3.0final 终结者系列教程08-画图节点Node中的锚点和坐标系
    mysql数据库sql优化——子查询优化
    jQuery ajax 动态append创建表格出现不兼容ie8
    JavaScript关于闭包
    PatternSyntaxException:Syntax error in regexp pattern
  • 原文地址:https://www.cnblogs.com/LT-blogs/p/7154345.html
Copyright © 2011-2022 走看看