You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
96 lines
3.0 KiB
96 lines
3.0 KiB
9 years ago
|
/**
|
||
|
* Licensed to the Apache Software Foundation (ASF) under one or more contributor license agreements. See the NOTICE
|
||
|
* file distributed with this work for additional information regarding copyright ownership. The ASF licenses this file
|
||
|
* to You under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the
|
||
|
* License. You may obtain a copy of the License at
|
||
|
*
|
||
|
* http://www.apache.org/licenses/LICENSE-2.0
|
||
|
*
|
||
|
* Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
|
||
|
* an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
|
||
|
* specific language governing permissions and limitations under the License.
|
||
|
*/
|
||
|
|
||
|
|
||
|
KafkaClient {
|
||
9 years ago
|
{% if client_sasl_mechanism == "GSSAPI" %}
|
||
|
{% if is_ibm_jdk %}
|
||
9 years ago
|
com.ibm.security.auth.module.Krb5LoginModule required debug=false
|
||
|
credsType=both
|
||
|
useKeytab="file:/mnt/security/keytab"
|
||
|
principal="client@EXAMPLE.COM";
|
||
|
{% else %}
|
||
|
com.sun.security.auth.module.Krb5LoginModule required debug=false
|
||
|
doNotPrompt=true
|
||
|
useKeyTab=true
|
||
|
storeKey=true
|
||
|
keyTab="/mnt/security/keytab"
|
||
|
principal="client@EXAMPLE.COM";
|
||
9 years ago
|
{% endif %}
|
||
|
{% elif client_sasl_mechanism == "PLAIN" %}
|
||
|
org.apache.kafka.common.security.plain.PlainLoginModule required
|
||
|
username="client"
|
||
|
password="client-secret";
|
||
|
{% endif %}
|
||
|
|
||
9 years ago
|
};
|
||
|
|
||
|
KafkaServer {
|
||
9 years ago
|
{% if "GSSAPI" in enabled_sasl_mechanisms %}
|
||
|
{% if is_ibm_jdk %}
|
||
|
com.ibm.security.auth.module.Krb5LoginModule required debug=false
|
||
|
credsType=both
|
||
|
useKeytab="file:/mnt/security/keytab"
|
||
|
principal="kafka/{{ node.account.hostname }}@EXAMPLE.COM";
|
||
|
{% else %}
|
||
9 years ago
|
com.sun.security.auth.module.Krb5LoginModule required debug=false
|
||
|
doNotPrompt=true
|
||
|
useKeyTab=true
|
||
|
storeKey=true
|
||
|
keyTab="/mnt/security/keytab"
|
||
|
principal="kafka/{{ node.account.hostname }}@EXAMPLE.COM";
|
||
9 years ago
|
{% endif %}
|
||
|
{% endif %}
|
||
|
{% if "PLAIN" in enabled_sasl_mechanisms %}
|
||
|
org.apache.kafka.common.security.plain.PlainLoginModule required
|
||
|
username="kafka"
|
||
|
password="kafka-secret"
|
||
|
user_client="client-secret"
|
||
|
user_kafka="kafka-secret";
|
||
|
{% endif %}
|
||
9 years ago
|
};
|
||
|
|
||
9 years ago
|
{% if zk_sasl %}
|
||
|
Client {
|
||
9 years ago
|
{% if is_ibm_jdk %}
|
||
|
com.ibm.security.auth.module.Krb5LoginModule required debug=false
|
||
|
credsType=both
|
||
|
useKeytab="file:/mnt/security/keytab"
|
||
|
principal="zkclient@EXAMPLE.COM";
|
||
|
{% else %}
|
||
|
com.sun.security.auth.module.Krb5LoginModule required
|
||
|
useKeyTab=true
|
||
|
keyTab="/mnt/security/keytab"
|
||
|
storeKey=true
|
||
|
useTicketCache=false
|
||
|
principal="zkclient@EXAMPLE.COM";
|
||
|
{% endif %}
|
||
9 years ago
|
};
|
||
|
|
||
|
Server {
|
||
9 years ago
|
{% if is_ibm_jdk %}
|
||
|
com.ibm.security.auth.module.Krb5LoginModule required debug=false
|
||
|
credsType=both
|
||
|
useKeyTab="file:/mnt/security/keytab"
|
||
|
principal="zookeeper/{{ node.account.hostname }}@EXAMPLE.COM";
|
||
|
{% else %}
|
||
|
com.sun.security.auth.module.Krb5LoginModule required
|
||
|
useKeyTab=true
|
||
|
keyTab="/mnt/security/keytab"
|
||
|
storeKey=true
|
||
|
useTicketCache=false
|
||
|
principal="zookeeper/{{ node.account.hostname }}@EXAMPLE.COM";
|
||
9 years ago
|
{% endif %}
|
||
9 years ago
|
};
|
||
9 years ago
|
{% endif %}
|