kadmin
//生成随机key的principal
addprinc -randkey root/master1@JENKIN.COM
//生成指定key的principal
addprinc admin/admin
//查看principal
listprincs
//修改admin/admin的密码
change_password -pw xxxx admin/admin
//删除principal
delete_principal admin/admin
//为principal生成keytab,可同时添加多个
xst -norandkey -k /var/kerberos/krb5kdc/keytab/root.keytab root/master1@HADOOP.COM host/master1@HADOOP.COM
客户端
kadmin.local //以超管身份进入kadmin
kadmin //进入kadmin模式,需输入密码
kdb5_util create -r JENKIN.COM -s //创建数据库
service krb5kdc start //启动kdc服务
service kadmin start //启动kadmin服务
service kprop start //启动kprop服务
kdb5_util dump /var/kerberos/krb5kdc/slave_data //生成dump文件
kprop -f /var/kerberos/krb5kdc/slave_data master2.com //将master数据库同步是slave
kinit -k -t /var/kerberos/krb5kdc/keytab/root.keytab root/master1@JENKIN.COM //测试keytab是否可用
klist -e -k -t /var/kerberos/krb5kdc/keytab/root.keytab //查看keytab
网友评论