@zhangyy
2020-02-28T08:35:11.000000Z
字数 3449
阅读 365
大数据平台构建
# yum install krb5-server krb5-libs krb5-auth-dialog krb5-workstation -y

vim /etc/krb5.conf---includedir /etc/krb5.conf.d/[logging]default = FILE:/var/log/krb5libs.logkdc = FILE:/var/log/krb5kdc.logadmin_server = FILE:/var/log/kadmind.log[libdefaults]dns_lookup_kdc = falsedns_lookup_realm = falseticket_lifetime = 24hrenew_lifetime = 7dforwardable = truerdns = falsedefault_realm = GEMS.COMdefault_tgs_enctypes = rc4-hmacdefault_tkt_enctypes = rc4-hmacpermitted_enctypes = rc4-hmacudp_preference_limit = 1kdc_timeout = 3000# default_ccache_name = KEYRING:persistent:%{uid}[realms]GEMS.COM = {kdc = node01.yangyang.comadmin_server = node01.yangyang.com}[domain_realm].node01.yangyang.com = GEMS.COMnode01.yangyang.com = GEMS.COM
vim /var/kerberos/krb5kdc/kadm5.acl*/admin@GEMS.COM *

vim /var/kerberos/krb5kdc/kdc.conf----[kdcdefaults]kdc_ports = 88kdc_tcp_ports = 88[realms]GEMS.COM = {#master_key_type = aes256-ctsmax_renewable_life = 7dmax_life = 1dacl_file = /var/kerberos/krb5kdc/kadm5.acldict_file = /usr/share/dict/wordsadmin_keytab = /var/kerberos/krb5kdc/kadm5.keytabsupported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normaldefault_principal_flags = +renewable, +forwardable}

# kdb5_util create -r GEMS.COM -s---Loading random dataInitializing database '/var/kerberos/krb5kdc/principal' for realm 'GEMS.COM',master key name 'K/M@GEMS.COM'You will be prompted for the database Master Password.It is important that you NOT FORGET this password.Enter KDC database master key:Re-enter KDC database master key to verify:---输入认证的密码为: GEMS.COM

# kadmin.localAuthenticating as principal root/admin@GEMS.COM with password.kadmin.local: addprinc admin/admin@GEMS.COMWARNING: no policy specified for admin/admin@GEMS.COM; defaulting to no policyEnter password for principal "admin/admin@GEMS.COM": [输入密码]Re-enter password for principal "admin/admin@GEMS.COM": [输入密码]Principal "admin/admin@GEMS.COM" created.kadmin.local: exit

service krb5kdc startservice kadmin startchkconfig krb5kdc onchkconfig kadmin on
kinit admin/admin@GEMS.COM---> 输入密码:admin# klist

全部节点都要安装:yum -y install krb5-libs krb5-workstation (所有节点都要安装)CM节点安装额外组件yum -y install openldap-clients (kdc-server 节点安装)

scp /etc/krb5.conf node02:/etcscp /etc/krb5.conf node03:/etc

# unzip jce_policy-8.zip# cd UnlimitedJCEPolicyJDK8/# cp -p *.jar /usr/java/jdk1.8.0_151/jre/lib/security/# scp *.jar node02:/usr/java/jdk1.8.0_151/jre/lib/security/# scp *.jar node03:/usr/java/jdk1.8.0_151/jre/lib/security/


3.2.1 配置jdk 的目录:

3.2.2 KDC添加Cloudera Manager管理员账号
kadmin.local---Authenticating as principal admin/admin@GEMS.COM with password.kadmin.local: addprinc cloudera-scm/admin@GEMS.COMWARNING: no policy specified for cloudera-scm/admin@GEMS.COM; defaulting to no policyEnter password for principal "cloudera-scm/admin@GEMS.COM": [输入密码]Re-enter password for principal "cloudera-scm/admin@GEMS.COM": [输入密码]Principal "cloudera-scm/admin@GEMS.COM" created.密码为: Cloudera-scm---













