How to use multiple Kerberos files (krb5) Kafka API?












0















I am connecting to multiple Kafka clusters from my code and both the kafka clusters requires keytab and krb5.conf.



Since krb5.conf is set as a system property, I am able to connect to only one kafka server, the other one fails since krb5 doesn't match.



Is there a way to pass krb5.conf without setting it in system property?



Here is the error I was getting when i set the multiple krb5.conf to the system property as it overrides the first one:



Caused by: sun.security.krb5.KrbException: Client not found in Kerberos 
database (6)
at sun.security.krb5.KrbAsRep.<init>(KrbAsRep.java:76)
at sun.security.krb5.KrbAsReqBuilder.send(KrbAsReqBuilder.java:316)
at sun.security.krb5.KrbAsReqBuilder.action(KrbAsReqBuilder.java:361)
at

com.sun.security.auth.module.Krb5LoginModule.attemptAuthentication(Krb5Login Module.java:766)









share|improve this question























  • Are your kafka clusters on the same realm ? krb5.conf does support multiple realms. It seems your problem is how to use multiple keytabs/principals instead.

    – Gery
    Jan 7 at 17:30
















0















I am connecting to multiple Kafka clusters from my code and both the kafka clusters requires keytab and krb5.conf.



Since krb5.conf is set as a system property, I am able to connect to only one kafka server, the other one fails since krb5 doesn't match.



Is there a way to pass krb5.conf without setting it in system property?



Here is the error I was getting when i set the multiple krb5.conf to the system property as it overrides the first one:



Caused by: sun.security.krb5.KrbException: Client not found in Kerberos 
database (6)
at sun.security.krb5.KrbAsRep.<init>(KrbAsRep.java:76)
at sun.security.krb5.KrbAsReqBuilder.send(KrbAsReqBuilder.java:316)
at sun.security.krb5.KrbAsReqBuilder.action(KrbAsReqBuilder.java:361)
at

com.sun.security.auth.module.Krb5LoginModule.attemptAuthentication(Krb5Login Module.java:766)









share|improve this question























  • Are your kafka clusters on the same realm ? krb5.conf does support multiple realms. It seems your problem is how to use multiple keytabs/principals instead.

    – Gery
    Jan 7 at 17:30














0












0








0








I am connecting to multiple Kafka clusters from my code and both the kafka clusters requires keytab and krb5.conf.



Since krb5.conf is set as a system property, I am able to connect to only one kafka server, the other one fails since krb5 doesn't match.



Is there a way to pass krb5.conf without setting it in system property?



Here is the error I was getting when i set the multiple krb5.conf to the system property as it overrides the first one:



Caused by: sun.security.krb5.KrbException: Client not found in Kerberos 
database (6)
at sun.security.krb5.KrbAsRep.<init>(KrbAsRep.java:76)
at sun.security.krb5.KrbAsReqBuilder.send(KrbAsReqBuilder.java:316)
at sun.security.krb5.KrbAsReqBuilder.action(KrbAsReqBuilder.java:361)
at

com.sun.security.auth.module.Krb5LoginModule.attemptAuthentication(Krb5Login Module.java:766)









share|improve this question














I am connecting to multiple Kafka clusters from my code and both the kafka clusters requires keytab and krb5.conf.



Since krb5.conf is set as a system property, I am able to connect to only one kafka server, the other one fails since krb5 doesn't match.



Is there a way to pass krb5.conf without setting it in system property?



Here is the error I was getting when i set the multiple krb5.conf to the system property as it overrides the first one:



Caused by: sun.security.krb5.KrbException: Client not found in Kerberos 
database (6)
at sun.security.krb5.KrbAsRep.<init>(KrbAsRep.java:76)
at sun.security.krb5.KrbAsReqBuilder.send(KrbAsReqBuilder.java:316)
at sun.security.krb5.KrbAsReqBuilder.action(KrbAsReqBuilder.java:361)
at

com.sun.security.auth.module.Krb5LoginModule.attemptAuthentication(Krb5Login Module.java:766)






apache-kafka kerberos






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Jan 3 at 15:39









SrinivasSrinivas

72110




72110













  • Are your kafka clusters on the same realm ? krb5.conf does support multiple realms. It seems your problem is how to use multiple keytabs/principals instead.

    – Gery
    Jan 7 at 17:30



















  • Are your kafka clusters on the same realm ? krb5.conf does support multiple realms. It seems your problem is how to use multiple keytabs/principals instead.

    – Gery
    Jan 7 at 17:30

















Are your kafka clusters on the same realm ? krb5.conf does support multiple realms. It seems your problem is how to use multiple keytabs/principals instead.

– Gery
Jan 7 at 17:30





Are your kafka clusters on the same realm ? krb5.conf does support multiple realms. It seems your problem is how to use multiple keytabs/principals instead.

– Gery
Jan 7 at 17:30












0






active

oldest

votes












Your Answer






StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");

StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f54025441%2fhow-to-use-multiple-kerberos-files-krb5-kafka-api%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f54025441%2fhow-to-use-multiple-kerberos-files-krb5-kafka-api%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Monofisismo

Angular Downloading a file using contenturl with Basic Authentication

Olmecas