赞
踩
keytool -keystore server.keystore.jks -alias kafka-server -validity 365 -keyalg RSA -genkey
查看
keytool -list -keystore server.keystore.jks -v
keytool -keystore client.keystore.jks -alias kafka-client -validity 365 -keyalg RSA -genkey
查看
keytool -list -keystore client.keystore.jks -v
openssl req -new -x509 -keyout ca.key -out ca.crt -days 365
keytool -keystore server.trustkeystore.jks -alias CARoot -import -file ca.crt
keytool -keystore client.trustkeystore.jks -alias CARoot -import -file ca.crt
keytool -keystore server.keystore.jks -alias kafka-server -certreq -file kafka.server.crt
keytool -keystore client.keystore.jks -alias kafka-client -certreq -file kafka.client.crt
openssl x509 -req -CA ca.crt -CAkey ca.key -in kafka.server.crt -out kafka.server.signed.crt -days 365 -CAcreateserial
openssl x509 -req -CA ca.crt -CAkey ca.key -in kafka.client.crt -out kafka.client.signed.crt -days 365 -CAcreateserial
keytool -keystore server.keystore.jks -alias CARoot -import -file ca.crt
keytool -keystore client.keystore.jks -alias CARoot -import -file ca.crt
keytool -keystore server.keystore.jks -alias kafka-server -import -file kafka.server.signed.crt
keytool -keystore client.keystore.jks -alias kafka-client -import -file kafka.client.signed.crt
scp -r cert root@hadoop101:`pwd`
scp -r cert root@hadoop102:`pwd`
cp server.properties server-ssl.properties
vim server-ssl.properties
listeners=PLAINTEXT://hadoop100:9092,SSL://hadoop100:9093
security.inter.broker.protocol=SSL
ssl.keystore.location=/opt/kafka_2.13-3.6.1/cert/server.keystore.jks
ssl.keystore.password=123456
ssl.key.password=123456
ssl.truststore.location=/opt/kafka_2.13-3.6.1/cert/server.trustkeystore.jks
ssl.truststore.password=123456
ssl.client.auth=required
启动kafka
nohup /opt/kafka_2.13-3.6.1/bin/kafka-server-start.sh /opt/kafka_2.13-3.6.1/config/server-ssl.properties > /dev/null 2>&1 &
security.inter.broker.protocol=SSL
ssl.keystore.location=/opt/kafka_2.13-3.6.1/cert/server.keystore.jks
ssl.keystore.password=123456
ssl.key.password=123456
ssl.truststore.location=/opt/kafka_2.13-3.6.1/cert/server.trustkeystore.jks
ssl.truststore.password=123456
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。