Created 10-28-2015 08:44 AM
This is secure HDP 2.3 cluster. And zookeeper services run as non-default service user.
Is it supported to configure a kerberized kafka cluster to connect with zookeepers having non-default service users ?
Created 10-28-2015 10:53 AM
@rmaruthiyodan@hortonworks.com - It's supported as far as I know. You are using zookprusr (example) for zookepper , as long as zookeeper service is up , we are good.
Kafka Kerberos Doc
Client { // used for zookeeper connection com.sun.security.auth.module.Krb5LoginModule required useKeyTab=true keyTab="/etc/security/keytabs/kafka.service.keytab" storeKey=true useTicketCache=false serviceName="zookeeper" principal="kafka/c6401.ambari.apache.org@EXAMPLE.COM"; };
Created 10-28-2015 10:19 AM
@rmaruthiyodan@hortonworks.com
I know there are customers doing that and as far as I know, its supported. Are you facing any issues?
Created 10-28-2015 10:53 AM
@rmaruthiyodan@hortonworks.com - It's supported as far as I know. You are using zookprusr (example) for zookepper , as long as zookeeper service is up , we are good.
Kafka Kerberos Doc
Client { // used for zookeeper connection com.sun.security.auth.module.Krb5LoginModule required useKeyTab=true keyTab="/etc/security/keytabs/kafka.service.keytab" storeKey=true useTicketCache=false serviceName="zookeeper" principal="kafka/c6401.ambari.apache.org@EXAMPLE.COM"; };