如何使用mongo-java-driver连接Kerberos认证的MongoDB服务
问题:Java连接Kerberos认证MongoDB时的keytab选择问题
环境与已完成操作
- Kerberos服务端部署在一台EC2实例,另一台EC2实例作为客户端,安装了Kerberos客户端、MongoDB 6.0.2企业版及mongosh 1.10.6
- 已创建用户主体
admn@KAFKA.SECURE和服务主体mongodb/ip-***.ap-south-1.compute.internal@KAFKA.SECURE,并从Kerberos服务端导出对应的keytab文件到客户端实例 - 已成功启动带Kerberos认证的MongoDB服务,且能通过mongosh正常连接
创建主体与导出keytab命令
sudo kadmin.local -q "add_principal -randkey admn@KAFKA.SECURE" sudo kadmin.local -q "xst -kt /tmp/admn.user.keytab admn@KAFKA.SECURE" sudo kadmin.local -q "add_principal -randkey mongodb/ip-***.ap-south-1.compute.internal@KAFKA.SECURE" sudo kadmin.local -q "xst -kt /tmp/mongokb.service.keytab mongodb/ip-***.ap-south-1.compute.internal@KAFKA.SECURE" kinit -kt /tmp/admn.user.keytab admn
启动MongoDB服务命令
env KRB5_KTNAME=/tmp/mongokb.service.keytab mongod --auth --setParameter authenticationMechanisms=GSSAPI --bind_ip_all
mongosh连接命令
mongosh --host ip-**.compute.internal --authenticationMechanism=GSSAPI --authenticationDatabase='$external' --username admn@KAFKA.SECURE
Java代码与配置文件
Java连接代码
System.setProperty("java.security.krb5.realm","KAFKA.SECURE"); System.setProperty("java.security.krb5.kdc", "ec2-***.compute.amazonaws.com"); System.setProperty("javax.security.auth.useSubjectCredsOnly","false"); System.setProperty("sun.security.krb5.debug","true"); System.setProperty("java.security.auth.login.config","/tmp/gss-jaas.conf"); System.setProperty("java.security.krb5.conf","/tmp/krb5.conf"); MongoCredential credential = MongoCredential.createGSSAPICredential("admn@KAFKA.SECURE"); com.mongodb.client.MongoClient mongoClient = MongoClients.create( MongoClientSettings.builder() .applyToClusterSettings(builder -> builder.hosts(Arrays.asList(new ServerAddress("ip-***", 27017)))) .credential(credential) .build()); MongoDatabase db=mongoClient.getDatabase("admin"); System.out.print("Db Name:"+db.getName()); final Bson ping = new BasicDBObject("dbstats", 1); db.runCommand(ping);
krb5.conf配置
includedir D:/krb5.conf.d/ [logging] default = FILE:/var/log/krb5libs.log kdc = FILE:/var/log/krb5kdc.log admin_server = FILE:/var/log/kadmind.log [libdefaults] ticket_lifetime = 24h renew_lifetime = 7d default_realm = KAFKA.SECURE kdc_timesync = 1 [realms] KAFKA.SECURE = { admin_server = ec2-**.compute.amazonaws.com kdc = ec2-**.compute.amazonaws.com }
gss-jaas.conf配置
com.sun.security.jgss.initiate { com.sun.security.auth.module.Krb5LoginModule required useKeyTab=true useTicketCache=false principal="mongodb/ip-***.internal@KAFKA.SECURE" doNotPrompt=true storeKey=true keyTab="D:/mongokb.service.keytab" debug=true;};
遇到的错误
初始连接错误
GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)
相关Kerberos调试日志片段
Debug is true storeKey false useTicketCache false useKeyTab true doNotPrompt true ticketCache is null isInitiator true KeyTab is D:/mongokb.service.keytab refreshKrb5Config is false principal is mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE tryFirstPass is false useFirstPass is false storePass is false clearPass is false Looking for keys for: mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE Found unsupported keytype (25) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE Found unsupported keytype (26) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE Added key: 23version: 3 Added key: 17version: 3 Added key: 18version: 3 Looking for keys for: mongodb/ip-***.compute.internal@KAFKA.SECURE Found unsupported keytype (25) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE Found unsupported keytype (26) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE Added key: 23version: 3 Added key: 17version: 3 Added key: 18version: 3 Using builtin default etypes for default_tkt_enctypes default etypes for default_tkt_enctypes: 18 17 20 19 16 23. >>> KrbAsReq creating message >>> KrbKdcReq send: kdc=ec2-**.compute.amazonaws.com UDP:88, timeout=30000, number of retries =3, #bytes=208 >>> KDCCommunication: kdc=ec2-**.amazonaws.com UDP:88, timeout=30000,Attempt =1, #bytes=208 >>> KrbKdcReq send: #bytes read=840 >>> KdcAccessibility: remove ec2-***.compute.amazonaws.com Looking for keys for: mongodb/ip-***.compute.internal@KAFKA.SECURE Found unsupported keytype (25) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE Found unsupported keytype (26) for mongodb/ip-**.ap-south-1.compute.internal@KAFKA.SECURE Added key: 23version: 3 Added key: 17version: 3 Added key: 18version: 3 >>> EType: sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType >>> KrbAsRep cons in KrbAsReq.getReply mongodb/ip-***.compute.internal principal is mongodb/ip-**.compute.internal@KAFKA.SECURE Will use keytab Commit Succeeded Found ticket for mongodb/ip-**.compute.internal@KAFKA.SECURE to go to krbtgt/KAFKA.SECURE@KAFKA.SECURE expiring on Thu Nov 09 16:05:19 IST 2023
合并keytab后的错误
尝试将服务主体条目添加到admn.user.keytab:
add_entry -password -p mongodb/ip**.ap-south-1.compute.internal -k 3 -e aes256-cts-hmac-sha1-96 wkt /tmp/admn.user.keytab
修改gss-jaas.conf指定该keytab后,出现校验和错误:
Caused by: KrbException: Checksum failed at sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType.decrypt(Aes256CtsHmacSha1EType.java:102)
提问
连接启用Kerberos认证的MongoDB服务应使用哪个keytab文件?
内容的提问来源于stack exchange,提问作者prathyusha magam
相关产品推荐
相关产品推荐

