zoukankan      html  css  js  c++  java
  • Kafka SSL 配置

    #!/bin/bash

    # 生成服务器keystore(密钥和证书)
    keytool -keystore server.keystore.jks -alias machine03.zheng.com -validity 365 -keyalg RSA -storepass leonzheng -keypass leonzheng -genkey -dname "C=CN,ST=FJ,L=FZ,O=LEON,OU=LEON,CN=ZHENG.COM"
    # 生成客户端keystore(密钥和证书)
    keytool -keystore client.keystore.jks -alias machine03.zheng.com -validity 365 -keyalg RSA -storepass leonzheng -keypass leonzheng -genkey -dname "C=CN,ST=FJ,L=FZ,O=LEON,OU=LEON,CN=ZHENG.COM"
    # 创建CA证书
    openssl req -new -x509 -keyout ca.key -out ca.crt -days 365 -passout pass:leonzheng -subj "/C=CN/ST=FJ/L=FZ/O=LEON/OU=LEON/CN=ZHENG.COM"
    # 将CA证书导入到服务器truststore
    keytool -keystore server.truststore.jks -alias CARoot -import -file ca.crt -storepass leonzheng
    # 将CA证书导入到客户端truststore
    keytool -keystore client.truststore.jks -alias CARoot -import -file ca.crt -storepass leonzheng
    # 导出服务器证书
    keytool -keystore server.keystore.jks -alias machine03.zheng.com -certreq -file cert-file -storepass leonzheng
    keytool -keystore client.keystore.jks -alias machine03.zheng.com -certreq -file client-cert-file -storepass leonzheng
    # 用CA证书给服务器证书签名
    openssl x509 -req -CA ca.crt -CAkey ca.key -in cert-file -out cert-signed -days 365 -CAcreateserial -passin pass:leonzheng
    openssl x509 -req -CA ca.crt -CAkey ca.key -in client-cert-file -out client-cert-signed -days 365 -CAcreateserial -passin pass:leonzheng
    # 将CA证书导入服务器keystore
    keytool -keystore server.keystore.jks -alias CARoot -import -file ca.crt -storepass leonzheng
    keytool -keystore client.keystore.jks -alias CARoot -import -file ca.crt -storepass leonzheng
    # 将已签名的服务器证书导入服务器keystore
    keytool -keystore server.keystore.jks -alias machine03.zheng.com -import -file cert-signed -storepass leonzheng
    keytool -keystore client.keystore.jks -alias machine03.zheng.com -import -file client-cert-signed -storepass leonzheng

    验证ssl
    openssl s_client -debug -connect 192.168.12.33:9093 -tls1
    openssl s_client -debug -connect 192.168.12.33:9092 -tls1


    config/server.properties

    ssl.client.auth=required
    ssl.keystore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/server.keystore.jks
    ssl.keystore.password=leonzheng
    ssl.key.password=leonzheng
    ssl.truststore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/server.truststore.jks
    ssl.truststore.password=leonzheng

    clientssl.properties

    security.protocol=SSL
    ssl.truststore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/client.truststore.jks
    ssl.truststore.password=leonzheng
    ssl.keystore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/client.keystore.jks
    ssl.keystore.password=leonzheng
    ssl.key.password=leonzheng

    bin/kafka-topics.sh --zookeeper 192.168.12.33:2181,192.168.12.33:2182,192.168.12.33:2183/kafka --create --topic testssl --partitions 3 --replication-factor 1

    bin/kafka-console-producer.sh --broker-list 192.168.12.33:9093 --topic testssl --producer.config /usr/local/kafka_2.11-0.10.1.0/ssl/clientssl.properties

    bin/kafka-console-consumer.sh --bootstrap-server 192.168.12.33:9093 --topic testssl --from-beginning --consumer.config /usr/local/kafka_2.11-0.10.1.0/ssl/clientssl.properties

    required的适用于对客户端安全验证比较严格的场景,比如某些操作只能由特定的设备发起才能被允许访问资源
    requested适用于对客户端安全验证比较宽松的场景,客户端可以决定是否提供验证信息,如果未提供或已提供未通过,仍然允许访问资源
  • 相关阅读:
    VM VirtualBox安装Centos6.5
    桥接
    程序员工作心法
    策略模式-鸭子怎么飞-实例
    策略模式-用什么方式去上班呢 实例
    观察者模式-订报纸,语音呼叫系统实例
    门面(Facade)模式--医院,保安系统实例
    Promise实例的resolve方法
    Promise实例的any方法
    Promise实例的race方法
  • 原文地址:https://www.cnblogs.com/LT-blogs/p/7154345.html
Copyright © 2011-2022 走看看