You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用mongo-java-driver连接Kerberos认证的MongoDB服务

问题:Java连接Kerberos认证MongoDB时的keytab选择问题

环境与已完成操作

  • Kerberos服务端部署在一台EC2实例,另一台EC2实例作为客户端,安装了Kerberos客户端、MongoDB 6.0.2企业版及mongosh 1.10.6
  • 已创建用户主体admn@KAFKA.SECURE和服务主体mongodb/ip-***.ap-south-1.compute.internal@KAFKA.SECURE,并从Kerberos服务端导出对应的keytab文件到客户端实例
  • 已成功启动带Kerberos认证的MongoDB服务,且能通过mongosh正常连接

创建主体与导出keytab命令

sudo kadmin.local -q "add_principal -randkey admn@KAFKA.SECURE"
sudo kadmin.local -q "xst -kt /tmp/admn.user.keytab admn@KAFKA.SECURE"
sudo kadmin.local -q "add_principal -randkey mongodb/ip-***.ap-south-1.compute.internal@KAFKA.SECURE"
sudo kadmin.local -q "xst -kt /tmp/mongokb.service.keytab mongodb/ip-***.ap-south-1.compute.internal@KAFKA.SECURE"
kinit -kt /tmp/admn.user.keytab admn

启动MongoDB服务命令

env KRB5_KTNAME=/tmp/mongokb.service.keytab mongod --auth --setParameter authenticationMechanisms=GSSAPI --bind_ip_all

mongosh连接命令

mongosh --host ip-**.compute.internal --authenticationMechanism=GSSAPI --authenticationDatabase='$external' --username admn@KAFKA.SECURE

Java代码与配置文件

Java连接代码

System.setProperty("java.security.krb5.realm","KAFKA.SECURE");
System.setProperty("java.security.krb5.kdc", "ec2-***.compute.amazonaws.com");
System.setProperty("javax.security.auth.useSubjectCredsOnly","false");
System.setProperty("sun.security.krb5.debug","true");
System.setProperty("java.security.auth.login.config","/tmp/gss-jaas.conf");
System.setProperty("java.security.krb5.conf","/tmp/krb5.conf");

MongoCredential credential = MongoCredential.createGSSAPICredential("admn@KAFKA.SECURE");
com.mongodb.client.MongoClient mongoClient = MongoClients.create(
        MongoClientSettings.builder()
                .applyToClusterSettings(builder -> 
                        builder.hosts(Arrays.asList(new ServerAddress("ip-***", 27017))))
                .credential(credential)
                .build());

MongoDatabase db=mongoClient.getDatabase("admin");
System.out.print("Db Name:"+db.getName());
final Bson ping = new BasicDBObject("dbstats", 1);      
db.runCommand(ping);

krb5.conf配置

includedir D:/krb5.conf.d/

[logging]
    default = FILE:/var/log/krb5libs.log
    kdc = FILE:/var/log/krb5kdc.log
    admin_server = FILE:/var/log/kadmind.log

[libdefaults]
    ticket_lifetime = 24h
    renew_lifetime = 7d    
    default_realm = KAFKA.SECURE
    kdc_timesync = 1
[realms]
 KAFKA.SECURE = {
      admin_server = ec2-**.compute.amazonaws.com
      kdc  = ec2-**.compute.amazonaws.com
   }

gss-jaas.conf配置

com.sun.security.jgss.initiate {
com.sun.security.auth.module.Krb5LoginModule required
useKeyTab=true
useTicketCache=false
principal="mongodb/ip-***.internal@KAFKA.SECURE"
doNotPrompt=true 
storeKey=true
keyTab="D:/mongokb.service.keytab" 
debug=true;};

遇到的错误

初始连接错误

GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)

相关Kerberos调试日志片段

Debug is  true storeKey false useTicketCache false useKeyTab true doNotPrompt true ticketCache is null isInitiator true KeyTab is D:/mongokb.service.keytab refreshKrb5Config is false principal is mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE tryFirstPass is false useFirstPass is false storePass is false clearPass is false
Looking for keys for: mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE
Found unsupported keytype (25) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE
Found unsupported keytype (26) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE
Added key: 23version: 3
Added key: 17version: 3
Added key: 18version: 3
Looking for keys for: mongodb/ip-***.compute.internal@KAFKA.SECURE
Found unsupported keytype (25) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE
Found unsupported keytype (26) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE
Added key: 23version: 3
Added key: 17version: 3
Added key: 18version: 3
Using builtin default etypes for default_tkt_enctypes
default etypes for default_tkt_enctypes: 18 17 20 19 16 23.
>>> KrbAsReq creating message
>>> KrbKdcReq send: kdc=ec2-**.compute.amazonaws.com UDP:88, timeout=30000, number of retries =3, #bytes=208
>>> KDCCommunication: kdc=ec2-**.amazonaws.com UDP:88, timeout=30000,Attempt =1, #bytes=208
>>> KrbKdcReq send: #bytes read=840
>>> KdcAccessibility: remove ec2-***.compute.amazonaws.com
Looking for keys for: mongodb/ip-***.compute.internal@KAFKA.SECURE
Found unsupported keytype (25) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE
Found unsupported keytype (26) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE
Added key: 23version: 3
Added key: 17version: 3
Added key: 18version: 3
>>> EType: sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType
>>> KrbAsRep cons in KrbAsReq.getReply mongodb/ip-***.compute.internal
principal is mongodb/ip-**.compute.internal@KAFKA.SECURE
Will use keytab
Commit Succeeded 

Found ticket for mongodb/ip-**.compute.internal@KAFKA.SECURE to go to krbtgt/KAFKA.SECURE@KAFKA.SECURE expiring on Thu Nov 09 16:05:19 IST 2023

合并keytab后的错误

尝试将服务主体条目添加到admn.user.keytab:

add_entry -password -p mongodb/ip**.ap-south-1.compute.internal -k 3 -e aes256-cts-hmac-sha1-96
wkt /tmp/admn.user.keytab

修改gss-jaas.conf指定该keytab后,出现校验和错误:

Caused by: KrbException: Checksum failed
        at sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType.decrypt(Aes256CtsHmacSha1EType.java:102)

提问

连接启用Kerberos认证的MongoDB服务应使用哪个keytab文件?

内容的提问来源于stack exchange,提问作者prathyusha magam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 17:04:56