拷貝KDC A的數(shù)據(jù)追加到KDC B埋凯,使得在B集群節(jié)點(diǎn)可以通過認(rèn)證訪問A集群內(nèi)的服務(wù)。
1 KDC A
將KDC A的DATABASE數(shù)據(jù)導(dǎo)出,然后發(fā)送到KDC B點(diǎn)
[root@node1a198 krb5kdc]# kdb5_util dump /var/kerberos/krb5kdc/kdc2.dump
[root@node1a198 krb5kdc]# scp kdc2.dump node1a142:/var/kerberos/krb5kdc/
2 KDC B
將KDC A點(diǎn)導(dǎo)出的DATABASE數(shù)據(jù)導(dǎo)入KDC B點(diǎn)數(shù)據(jù)庫
[root@node1a142 krb5kdc]# kdb5_util load -update kdc2.dump
[root@node1a142 krb5kdc]# kadmin.local -q listprincs|grep node1a141
HTTP/node1a141@HADOOP.COM
hdfs/node1a141@HADOOP.COM
hive/node1a141@HADOOP.COM
mapred/node1a141@HADOOP.COM
sentry/node1a141@HADOOP.COM
spark/node1a141@HADOOP.COM
yarn/node1a141@HADOOP.COM
zookeeper/node1a141@HADOOP.COM
[root@node1a142 krb5kdc]# kinit admin
Password for admin@HADOOP.COM:
3 驗(yàn)證
在B集群節(jié)點(diǎn)上訪問A集群的hdfs服務(wù)正常
[root@node1a142 krb5kdc]# hdfs dfs -ls hdfs://node1a203:8020/
Found 9 items
drwxr-xr-x - root supergroup 0 2017-05-27 18:55 hdfs://node1a203:8020/cdtest
drwx------ - hbase hbase 0 2017-05-22 18:51 hdfs://node1a203:8020/hbase
drwx------ - hbase hbase 0 2017-07-07 12:43 hdfs://node1a203:8020/hbase1
drwxr-xr-x - hbase hbase 0 2017-05-11 10:46 hdfs://node1a203:8020/hbase2
drwxr-xr-x - root supergroup 0 2016-12-01 17:30 hdfs://node1a203:8020/home
drwxr-xr-x - mdss supergroup 0 2016-12-13 18:30 hdfs://node1a203:8020/idfs
drwxr-xr-x - hdfs supergroup 0 2017-05-22 18:51 hdfs://node1a203:8020/system
drwxrwxrwt - hdfs supergroup 0 2017-07-07 12:27 hdfs://node1a203:8020/tmp
drwxrwxr-x+ - hdfs supergroup 0 2017-05-04 15:48 hdfs://node1a203:8020/user