Reply
Highlighted
New Contributor
Posts: 5
Registered: ‎08-24-2017
Accepted Solution

Kafka ACL authorizer for Active Directory

[ Edited ]

I'm using Cloudera enterprise and Kafka 0.10.x.

 

To secure Kafka I've enabled Kerberos and configured Kafka to use the SimpleACLAuthorizer which stores ACLs in ZooKeeper.  Instead of using this I'd like to check Active Directory instead to determine topic authorization.  I can't seem to find an implementation.  Does one exist?

 

Cloudera Employee
Posts: 198
Registered: ‎01-09-2014

Re: Kafka ACL authorizer for Active Directory

Your best bet would to use sentry to provide the authorization with kerberos and AD. You can use sssd on the linux nodes to make the AD users and groups available to kafka:

https://www.cloudera.com/documentation/enterprise/latest/topics/sg_auth_overview.html

https://www.cloudera.com/documentation/kafka/latest/topics/kafka_security.html

-pd
Announcements