Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created 10-28-2015 08:44 AM
This is secure HDP 2.3 cluster. And zookeeper services run as non-default service user.
Is it supported to configure a kerberized kafka cluster to connect with zookeepers having non-default service users ?
Created 10-28-2015 10:53 AM
@[email protected] - It's supported as far as I know. You are using zookprusr (example) for zookepper , as long as zookeeper service is up , we are good.
Kafka Kerberos Doc
Client { // used for zookeeper connection
com.sun.security.auth.module.Krb5LoginModule required
useKeyTab=true
keyTab="/etc/security/keytabs/kafka.service.keytab"
storeKey=true
useTicketCache=false
serviceName="zookeeper"
principal="kafka/[email protected]";
};
Created 10-28-2015 10:19 AM
I know there are customers doing that and as far as I know, its supported. Are you facing any issues?
Created 10-28-2015 10:53 AM
@[email protected] - It's supported as far as I know. You are using zookprusr (example) for zookepper , as long as zookeeper service is up , we are good.
Kafka Kerberos Doc
Client { // used for zookeeper connection
com.sun.security.auth.module.Krb5LoginModule required
useKeyTab=true
keyTab="/etc/security/keytabs/kafka.service.keytab"
storeKey=true
useTicketCache=false
serviceName="zookeeper"
principal="kafka/[email protected]";
};