当前位置: 代码网 > it编程>编程语言>Java > Kafka SSL认证

Kafka SSL认证

2024年08月01日 Java 我要评论
参考:https://www.ibm.com/docs/zh/cloud-paks/cp-biz-automation/21.0.3?在kafka安装目录下/certificates生成keystore和trust文件,在其中一台机器声生成证书,然后将。文件拷贝其他broker节点上去即可。3.导入CA到truststore。1.生成keystore。

证书生成

在kafka安装目录下/certificates生成keystore和trust文件,在其中一台机器声生成证书,然后将
生成的server.keystore.jksserver.truststore.jks文件拷贝其他broker节点上去即可
1.生成keystore

[root@m1 certificates]# keytool -keystore server.keystore.jks -alias kafka -validity 3650 -genkey -keyalg rsa -storetype pkcs12  -storepass 123456 -keypass 123456  -dname "cn=*.machine.com, ou=jd, o=jd, l=beijing, st=beijing, c=cn"
[root@m1 certificates]# ls -al
total 4
drwxr-xr-x. 2 root root   33 may 21 17:08 .
drwxr-xr-x. 8 root root  149 may 21 17:03 ..
-rw-r--r--. 1 root root 2565 may 21 17:08 server.keystore.jks

2.创建ca(certificate authority:认证机构)

[root@m1 certificates]# openssl req -new -x509 -keyout ca-key -out ca-cert -days 3650 -passin pass:123456 -passout pass:123456 -subj "/c=cn/st=beijing/l=beijing/o=jd/cn=*.machine.com"
generating a 2048 bit rsa private key
.......................................................................+++
.................................................................+++
writing new private key to 'ca-key'
-----
[root@m1 certificates]# ls -al
total 12
drwxr-xr-x. 2 root root   62 may 21 17:13 .
drwxr-xr-x. 8 root root  149 may 21 17:03 ..
-rw-r--r--. 1 root root 1273 may 21 17:13 ca-cert
-rw-r--r--. 1 root root 1834 may 21 17:13 ca-key
-rw-r--r--. 1 root root 2565 may 21 17:08 server.keystore.jks

3.导入ca到truststore

[root@m1 certificates]# keytool -keystore server.truststore.jks -alias caroot -import -file  ca-cert -storepass 123456 -keypass 123456 -noprompt
certificate was added to keystore
[root@m1 certificates]# ls -al
total 16
drwxr-xr-x. 2 root root   91 may 21 17:18 .
drwxr-xr-x. 8 root root  149 may 21 17:03 ..
-rw-r--r--. 1 root root 1273 may 21 17:13 ca-cert
-rw-r--r--. 1 root root 1834 may 21 17:13 ca-key
-rw-r--r--. 1 root root 2565 may 21 17:08 server.keystore.jks
-rw-r--r--. 1 root root  962 may 21 17:18 server.truststore.jks

  1. 从keystore中导出证书
[root@m1 certificates]# keytool -keystore server.keystore.jks -alias kafka -certreq -file cert-file -storepass 123456 -keypass "123456
[root@m1 certificates]# ls -al
total 20
drwxr-xr-x. 2 root root  108 may 21 17:21 .
drwxr-xr-x. 8 root root  149 may 21 17:03 ..
-rw-r--r--. 1 root root 1273 may 21 17:13 ca-cert
-rw-r--r--. 1 root root 1834 may 21 17:13 ca-key
-rw-r--r--. 1 root root 1085 may 21 17:21 cert-file
-rw-r--r--. 1 root root 2565 may 21 17:08 server.keystore.jks
-rw-r--r--. 1 root root  962 may 21 17:18 server.truststore.jks

  1. 签发证书
[root@m1 certificates]# openssl x509 -req -ca ca-cert -cakey ca-key -in cert-file -out cert-signed -days 365 -cacreateserial -passin pass:123456
signature ok
subject=/c=cn/st=beijing/l=beijing/o=jd/ou=jd/cn=*.machine.com
getting ca private key
  1. 导入ca到keystore
[root@m1 certificates]# keytool -keystore server.keystore.jks -alias caroot -import -file ca-cert -storepass 123456 -keypass 123456 -noprompt
certificate was added to keystore
  1. 导入证书到keystore
[root@m1 certificates]# keytool -keystore server.keystore.jks -alias localhost -import -file cert-signed -storepass "123456" -keypass "123456"
:certificate was added to keystore

配置kafka broker

...
listeners=ssl://m1.machine.proxy:9093
advertised.listeners=ssl://m1.machine.proxy:9093

ssl.keystore.location=/export/server/kafka_2.11-2.4.1/certificates/server.keystore.jks
ssl.keystore.password=123456
ssl.truststore.location=/export/server/kafka_2.11-2.4.1/certificates/server.truststore.jks
ssl.truststore.password=123456
ssl.key.password=123456
ssl.endpoint.identification.algorithm=
security.inter.broker.protocol=ssl
ssl.client.auth=required
ssl.enabled.protocols=tlsv1.2
ssl.truststore.type=jks
ssl.keystore.type=jks
...

参考:https://www.ibm.com/docs/zh/cloud-paks/cp-biz-automation/21.0.3?topic=emitter-preparing-ssl-certificates-kafka

(0)

相关文章:

版权声明:本文内容由互联网用户贡献,该文观点仅代表作者本人。本站仅提供信息存储服务,不拥有所有权,不承担相关法律责任。 如发现本站有涉嫌抄袭侵权/违法违规的内容, 请发送邮件至 2386932994@qq.com 举报,一经查实将立刻删除。

发表评论

验证码:
Copyright © 2017-2025  代码网 保留所有权利. 粤ICP备2024248653号
站长QQ:2386932994 | 联系邮箱:2386932994@qq.com