安全

HTTPS

师成师成· 更新于 2026-09-28· 阅读 9 分钟· 0 次阅读

登录后可跨设备保存划线和私人笔记登录

本文档介绍如何配置 Ozone HTTP Web 控制台以要求用户进行身份验证。

默认身份验证

默认情况下,Ozone HTTP Web 控制台(OM、SCM、S3G、Recon、Datanode)依据以下默认配置,允许无需身份验证即可访问。

属性值
ozone.security.http.kerberos.enabledfalse
ozone.http.filter.initializers

如果你的 Ozone 集群启用了 SPNEGO,并希望为所有 Ozone 服务禁用它,只需确保上述两个键按以上方式配置即可。

基于 Kerberos 的 SPNEGO 身份验证

不过,也可以将它们配置为通过 HTTP SPNEGO 协议(Firefox 和 Chrome 等浏览器支持)要求进行 Kerberos 身份验证。为此,首先必须配置以下键。

属性值
hadoop.security.authenticationkerberos
ozone.security.http.kerberos.enabledtrue
ozone.http.filter.initializersorg.apache.hadoop.security.AuthenticationFilterInitializer

之后,各个组件需要进行适当配置,以完全启用 SPNEGO 或 SIMPLE 身份验证。

为 OM HTTP 启用 SPNEGO 身份验证

属性值
ozone.om.http.auth.typekerberos
ozone.om.http.auth.kerberos.principalHTTP/_HOST@REALM
ozone.om.http.auth.kerberos.keytab/path/to/HTTP.keytab

为 S3G HTTP 启用 SPNEGO 身份验证

属性值
ozone.s3g.http.auth.typekerberos
ozone.s3g.http.auth.kerberos.principalHTTP/_HOST@REALM
ozone.s3g.http.auth.kerberos.keytab/path/to/HTTP.keytab

为 Recon HTTP 启用 SPNEGO 身份验证

属性值
ozone.recon.http.auth.typekerberos
ozone.recon.http.auth.kerberos.principalHTTP/_HOST@REALM
ozone.recon.http.auth.kerberos.keytab/path/to/HTTP.keytab

为 SCM HTTP 启用 SPNEGO 身份验证

属性值
ozone.scm.http.auth.typekerberos
ozone.scm.http.auth.kerberos.principalHTTP/_HOST@REALM
ozone.scm.http.auth.kerberos.keytab/path/to/HTTP.keytab

为 Datanode HTTP 启用 SPNEGO 认证

属性值
ozone.datanode.http.auth.typekerberos
ozone.datanode.http.auth.kerberos.principalHTTP/_HOST@REALM
ozone.datanode.http.auth.kerberos.keytab/path/to/HTTP.keytab

注意:Ozone Datanode 没有默认网页,因此无法访问 "/" 或 "/index.html"。但它通过 HTTP 提供了标准的 servlet,如 jmx/conf/jstack。

此外,Ozone HTTP Web 控制台支持与 Hadoop 的 Pseudo/Simple 认证等价的认证方式。如果启用该选项,则必须在首次浏览器交互时使用 user.name 查询字符串参数指定用户名,例如 http://scm:9876/?user.name=scmadmin。

为 OM HTTP 启用 SIMPLE 认证

属性值
ozone.om.http.auth.typesimple
ozone.om.http.auth.simple.anonymous.allowedfalse

如果不想在查询字符串参数中指定 user.name,请将 ozone.om.http.auth.simple.anonymous.allowed 改为 true。

为 S3G HTTP 启用 SIMPLE 认证

属性值
ozone.s3g.http.auth.typesimple
ozone.s3g.http.auth.simple.anonymous.allowedfalse

如果不想在查询字符串参数中指定 user.name,请将 ozone.s3g.http.auth.simple.anonymous.allowed 改为 true。

为 Recon HTTP 启用 SIMPLE 认证

属性值
ozone.recon.http.auth.typesimple
ozone.recon.http.auth.simple.anonymous.allowedfalse

如果不想在查询字符串参数中指定 user.name,请将 ozone.recon.http.auth.simple.anonymous.allowed 改为 true。

为 SCM HTTP 启用 SIMPLE 认证

属性值
ozone.scm.http.auth.typesimple
ozone.scm.http.auth.simple.anonymous.allowedfalse

如果不想在查询字符串参数中指定 user.name,请将 hdds.scm.http.auth.simple.anonymous.allowed 改为 true。

为 Datanode HTTP 启用 SIMPLE 认证

属性值
ozone.datanode.http.auth.typesimple
ozone.datanode.http.auth.simple.anonymous.allowedfalse

如果不想在查询字符串参数中指定 user.name,请将 hdds.datanode.http.auth.simple.anonymous.allowed 更改为 true。

评论

登录后参与评论

正在加载评论…