Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

All users can create Kafka topics even without kinit authentication

All users can create Kafka topics even without kinit authentication

New Contributor

With hdp2.6 clusters with kerberos and ranger enabled, all users can create topics even without kinit authentication. is this normal? Is there any option to control?

2 REPLIES 2
Highlighted

Re: All users can create Kafka topics even without kinit authentication

Contributor

@Maxwell

please check Kafka Brokers -> listeners has the value correct value and update the listener config to below and restarted Ambari and Kafka.


PLAINTEXTSASL://localhost:6667, PLAINTEXT://localhost:6668

Re: All users can create Kafka topics even without kinit authentication

New Contributor

Hi Rishi, Already configured this parameter, my create topic command:

Bin/kafka-topics.sh --zookeeper xxx:2181,xxx1:2181,xxx2:2181 --create -topic test --replication-factor 1 --partitions 3 --config retention.bytes=107374182400 --config retention.ms=604800000

74404-20180514100426.png

In addition, ordinary users can create Topics without authorization through the Java API through Ranger. Please help me, thank you very much.