You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在非Ambari部署的RHEL7单节点HDFS Web UI配置Kerberos认证

Hadoop Web UI 安全认证配置方案(无Ambari的RHEL7单节点集群)

一、Kerberos自动认证配置修正

结合你能通过kinit正常获取AD票据的情况,问题大概率出在Hadoop服务端的Kerberos认证配置上,以下是关键配置要点:

1. core-site.xml 必配参数

确保以下参数正确设置(对照你的截图检查遗漏或错误):

  • hadoop.security.authentication:设为kerberos
  • hadoop.security.authorization:设为true
  • hadoop.http.authentication.type:设为kerberos
  • hadoop.http.authentication.kerberos.principal:格式为HTTP/<主机名>@AD域名(例如HTTP/node1.example.com@EXAMPLE.COM,主机名需与反向解析一致,且AD中已注册该SPN)
  • hadoop.http.authentication.kerberos.keytab:指定HTTP服务对应的keytab文件路径(例如/etc/security/keytabs/http.service.keytab),文件权限设为600,属主为Hadoop运行用户
  • hadoop.http.authentication.simple.anonymous.allowed:设为false,禁止匿名访问

2. 其他组件配置补充

  • hdfs-site.xml:
    • dfs.web.authentication.kerberos.principal:同core-site.xml中的HTTP主体
    • dfs.web.authentication.kerberos.keytab:对应HTTP服务的keytab路径
  • yarn-site.xml:
    • yarn.webapp.address:设置为主机名(而非localhost),确保SPN匹配
    • yarn.http.policy:设为HTTP_AND_HTTPS或HTTPS_ONLY
  • mapred-site.xml:
    • mapreduce.jobhistory.webapp.address:设置为主机名
    • mapreduce.jobhistory.http.authentication.type:设为kerberos
    • mapreduce.jobhistory.http.authentication.kerberos.principal:同HTTP主体格式
    • mapreduce.jobhistory.http.authentication.kerberos.keytab:对应keytab路径

3. 关键操作步骤

  1. AD中注册SPN并生成keytab:
    • 注册SPN:setspn -A HTTP/<主机名> <AD服务用户>
    • 生成keytab:ktpass /princ HTTP/<主机名>@AD域名 /mapuser <AD服务用户>@AD域名 /pass * /out <keytab路径> /crypto ALL /ptype KRB5_NT_PRINCIPAL
  2. 重启Hadoop服务:执行stop-all.sh后再执行start-all.sh,或逐个重启NameNode、ResourceManager、JobHistoryServer等组件
  3. 客户端浏览器配置:确保浏览器支持Kerberos认证(例如Chrome需在chrome://flags/#negotiate-auth-delegate-whitelist添加集群域名),且客户端已通过kinit获取票据,此时访问Web UI应自动完成认证

二、HTTP Basic登录界面配置(替代Kerberos)

若不需要Kerberos自动认证,可配置账号密码登录界面:

1. core-site.xml 参数调整

  • hadoop.http.authentication.type:设为simple
  • hadoop.http.authentication.simple.anonymous.allowed:设为false

2. 配置账号密码文件

  1. 创建认证配置文件$HADOOP_CONF_DIR/hadoop-http-auth.conf,内容如下:
<?xml version="1.0"?>
<configuration>
  <property>
    <name>hadoop.http.authentication.simple.htpasswd.file</name>
    <value>/etc/hadoop/htpasswd</value>
  </property>
</configuration>
  1. 生成账号密码文件:htpasswd -c /etc/hadoop/htpasswd admin(按提示输入密码),文件权限设为600,属主为Hadoop运行用户

3. 重启服务

重启所有Hadoop服务后,访问Web UI会弹出登录框,输入配置的账号密码即可登录

三、故障排查要点

  • 查看Hadoop服务日志(例如$HADOOP_LOG_DIR/hadoop-hadoop-namenode-<主机名>.log),排查Kerberos认证相关错误(如SPN不匹配、keytab权限问题)
  • 验证keytab有效性:执行kinit -kt <keytab路径> HTTP/<主机名>@AD域名,确认能正常获取票据
  • 检查主机名解析:确保主机名可正向、反向解析,Kerberos对主机名匹配要求严格,禁止使用localhost

内容的提问来源于stack exchange,提问作者Logan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 18:50:24