{"id":6509,"date":"2021-08-25T13:44:37","date_gmt":"2021-08-25T05:44:37","guid":{"rendered":"https:\/\/nj.transwarp.cn:8180\/?p=6509"},"modified":"2025-11-04T17:22:08","modified_gmt":"2025-11-04T09:22:08","slug":"guardian-3-2-x-%e7%89%88%e6%9c%ac%e5%a6%82%e4%bd%95%e6%9e%84%e9%80%a0%e5%b8%a6%e6%9c%89hostname%e7%9a%84principal%e5%92%8ckeytab","status":"publish","type":"post","link":"https:\/\/kbwp.transwarp.cn\/?p=6509","title":{"rendered":"guardian 3.2.x \u7248\u672c\u5982\u4f55\u6784\u9020\u5e26\u6709hostname\u7684principal\u548ckeytab"},"content":{"rendered":"<h3>\u80cc\u666f<\/h3>\n<hr \/>\n<p>\u8d8a\u6765\u8d8a\u591a\u7684\u73b0\u573a\u9700\u6c42\u5bf9\u63a5\u5f00\u6e90\u7684\u4ea7\u54c1\uff0c\u6bd4\u5982Spark\u3001presto\u7b49\uff0c\u5982\u679c\u96c6\u7fa4\u5f00\u4e86Guardian\u5b89\u5168\uff0c\u8fd9\u4e9b\u5f00\u6e90\u7684\u53ef\u80fd\u4f1a\u7528\u5230\u5e26hostname\u7684Principal\uff0c\u4e0d\u5e26hostname\u4f1a\u62a5\u9519\u3002<\/p>\n<p><code>kadmin.guardian<\/code>\u662fkerberos-guardian\u7684\u4ea4\u4e92\u5f0f\u547d\u4ee4\u884c\u5de5\u5177, \u5728Guardian server\u7684pod\u7684\u4efb\u610f\u76ee\u5f55\u4e0b\uff0c\u6267\u884c<code>kadmin.guardian<\/code>\u6307\u4ee4\u5373\u53ef\u6267\u884c\u3002<\/p>\n<p>\u6240\u8c13\u7684V2\u662f\u6307\u914d\u5408guardian-3.2.X\u53ca\u4ee5\u4e0a\u7248\u672c\u7684guardian\u4f7f\u7528\u7684<code>kadmin.guardian<\/code>\u5de5\u5177\uff08\u4e0d\u9002\u7528\u4e8eguardian-3.1.X\u53ca\u4ee5\u4e0b\u7248\u672c\uff09\u3002v1\u7248\u672c\u8bf7\u53c2\u8003 KB: <a href=\"https:\/\/nj.transwarp.cn:8180\/?p=6507\" title=\"guardian 3.2.0 \u4ee5\u4e0b\u7248\u672c\u5982\u4f55\u6784\u9020\u5e26\u6709hostname\u7684principal\u548ckeytab\">guardian 3.2.0 \u4ee5\u4e0b\u7248\u672c\u5982\u4f55\u6784\u9020\u5e26\u6709hostname\u7684principal\u548ckeytab<\/a><\/p>\n<p><font color=red>\u6ce8\u610f\uff1a\u672c\u6587\u9002\u7528\u4e8eguardian 3.2.0 \u53ca\u4ee5\u4e0a\u7248\u672c\uff0c\u53ef\u4ee5\u901a\u8fc7\u4e0b\u9762\u7684\u547d\u4ee4\u67e5\u770b\u5bb9\u5668\u6b63\u5728\u4f7f\u7528\u7684guardian\u7248\u672c\u3002<\/font><\/p>\n<p><code>kubectl describe po $(kubectl get po -o wide | grep -i guardian-server | head -1 | awk &#039;{print $1}&#039;) | grep -i &quot;image:&quot;<\/code><\/p>\n<p>\u5b98\u65b9\u5185\u90e8\u94fe\u63a5\uff1a<a href=\"http:\/\/wiki.transwarp.io:8090\/pages\/viewpage.action?pageId=24588058\">http:\/\/wiki.transwarp.io:8090\/pages\/viewpage.action?pageId=24588058<\/a><\/p>\n<h3>\u89e3\u51b3\u65b9\u6848<\/h3>\n<hr \/>\n<p>\u8fd9\u91cc\u4ee5realm\u4e3aTDH\u7684\u96c6\u7fa4\u4e3a\u4f8b\uff0c\u9700\u8981\u521b\u5efa\u4e00\u4e2a <code>test000\/tdh001@TDHBAK<\/code>\u7684principal\uff0c\u5e76\u6784\u9020\u5176keytab<\/p>\n<h4>1\u3001addprinc\u521b\u5efaprincipal<\/h4>\n<pre><code class=\"language-shell\"># \u9996\u5148\u9700\u8981\u8fdb\u5165\u5230guardian server\u7684pod\u5185\uff0c\u6211\u4eec\u7684\u811a\u672c\u5b58\u653e\u5728\/usr\/lib\/guardian\/scripts\/kadmin.guardian\n> kubectl exec -it $(kubectl get po -o wide | grep -i guardian-server | head -1 | awk '{print $1}') bash<\/code><\/pre>\n<pre><code class=\"language-shell\"># \u6267\u884clistprincs\u8f93\u51fa\u6240\u6709principal\u4fe1\u606f\n# -w \u540e\u9762\u7684\u5bc6\u7801\uff0c\u53ef\u4ee5\u5230manager\u6570\u636e\u5e93\u5185\u6267\u884c SELECT value FROM transwarp_manager.service_config  where name='guardian.ds.root.password' \u67e5\u770b\uff0c\u5e76\u4e0d\u662fadmin\u79df\u6237\u7684\u5bc6\u7801\u54e6\n\n> \/usr\/lib\/guardian\/scripts\/kadmin.guardian -H172.22.25.71 -w123456 -P8380 -T -q \"listprincs\"<\/code><\/pre>\n<p><font color=red>\u6ce8\u610f\uff1a\u4e0b\u9762\u8fd9\u6b65\u6784\u9020principal\u7684\u65f6\u5019\uff0c-rTDHBAK\uff0c\u8fd9\u91cc\u7684realm\u662f\u4f60\u671f\u671b\u6784\u9020\u7684principal\u91cc\u9762\u7684realm\u3002<\/font><\/p>\n<pre><code class=\"language-shell\"># \u6267\u884caddprinc\u6784\u9020principal\n> \/usr\/lib\/guardian\/scripts\/kadmin.guardian -H172.22.25.71 -w123456 -P8380 -rTDHBAK -T -q \"addprinc -pw 123456 test000\/tdh001\"<\/code><\/pre>\n<p>\u53ef\u4ee5\u901a\u8fc7 <code>kadmin.guardian -help<\/code> \u6216\u8005<code>kadmin.guardian -h<\/code>\u67e5\u770b\u4f7f\u7528\u8bf4\u660e<\/p>\n<pre><code class=\"language-ruby\"> -b <arg>   The zookeeper parent znode for HA, guardian is default\n -d <arg>   The suffix of the ds server, such as dc=tdh\n -H <arg>   The host of ds server, the default is localhost\n -P <arg>   The port of ds server, the default is 10389\n -p <arg>   The dn used to connect to the ds server, such as\n            uid=admin,ou=system\n -Q <arg>   The zookeeper quorum for HA\n -q <arg>   The kadmin query, must be xst, addprinc, listprincs, addent\n -r <arg>   The realm of the kerberos, such as TDH\n -T         Whether TLS should be used\n -w <arg>   The password used to connect to the ds server<\/code><\/pre>\n<pre><code class=\"language-shell\"># \u9a8c\u8bc1principal\u662f\u5426\u6dfb\u52a0\u6210\u529f\n> \/usr\/lib\/guardian\/scripts\/kadmin.guardian -H172.22.25.71 -w123456 -P8380 -T -q \"listprincs\" | grep 'test000\/tdh001@TDHBAK'<\/code><\/pre>\n<h4>2\u3001xst -k \u751f\u6210keytab\u6587\u4ef6<\/h4>\n<p><font color=red>\u6ce8\u610f\uff0c-rTDH\uff0c\u8fd9\u4e2arealm\u4f7f\u7528\u7684\u662f\u4f60\u5f53\u524d\u96c6\u7fa4\u7684realm\u3002 <\/font><\/p>\n<p><font color=red>\u4e0b\u9762\u7684xst\u547d\u4ee4\u91cc\u9762\u4e0d\u9700\u8981\u5199realm\uff08\u5426\u5219\u6709\u53ef\u80fd\u62a5\u9519principal\u627e\u4e0d\u5230\uff09\uff0c\u56e0\u4e3a\u5bf9\u4e8eprincipal\u6765\u8bf4test000\/tdh001\u662f\u552f\u4e00\u7684\u3002<\/font><\/p>\n<pre><code class=\"language-shell\">[root@jiujiu-tdh-71 scripts]# \/usr\/lib\/guardian\/scripts\/kadmin.guardian -w123456 -rTDH -T -q\"xst -k \/tmp\/test000.keytab test000\/tdh001\"\n[root@jiujiu-tdh-71 scripts]# ls \/tmp\/test000.keytab \n\/tmp\/test000.keytab\n\n# \u6821\u9a8ckeytab\u4e2d\u7684principal\u4fe1\u606f\n[root@jiujiu-tdh-71 scripts]# klist -ket \/tmp\/test000.keytab\nKeytab name: FILE:\/tmp\/test000.keytab\nKVNO Timestamp           Principal\n---- ------------------- ------------------------------------------------------\n   0 10\/12\/2021 10:42:21 test000\/tdh001@TDHBAK (aes128-cts-hmac-sha1-96) \n   0 10\/12\/2021 10:42:21 test000\/tdh001@TDHBAK (aes256-cts-hmac-sha1-96) \n   0 10\/12\/2021 10:42:21 test000\/tdh001@TDHBAK (DEPRECATED:des3-hmac-sha1) \n   0 10\/12\/2021 10:42:21 test000\/tdh001@TDHBAK (DEPRECATED:des-cbc-md5) \n   0 10\/12\/2021 10:42:21 test000\/tdh001@TDHBAK (DEPRECATED:arcfour-hmac) \n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u80cc\u666f \u8d8a\u6765\u8d8a\u591a\u7684\u73b0\u573a\u9700\u6c42\u5bf9\u63a5\u5f00\u6e90\u7684\u4ea7\u54c1\uff0c\u6bd4\u5982Spark\u3001presto\u7b49\uff0c\u5982\u679c\u96c6\u7fa4\u5f00\u4e86Guardian\u5b89\u5168\uff0c\u8fd9\u4e9b ..<\/p>\n<div class=\"clear-fix\"><\/div>\n<p><a href=\"https:\/\/kbwp.transwarp.cn\/?p=6509\" title=\"read more...\">Read more<\/a><\/p>\n","protected":false},"author":12,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[38],"tags":[],"class_list":["post-6509","post","type-post","status-publish","format-standard","hentry","category-configuration"],"acf":[],"_links":{"self":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts\/6509","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6509"}],"version-history":[{"count":4,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts\/6509\/revisions"}],"predecessor-version":[{"id":17621,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=\/wp\/v2\/posts\/6509\/revisions\/17621"}],"wp:attachment":[{"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kbwp.transwarp.cn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}