#!/bin/bash
# 生成服务器keystore(密钥和证书)keytool -keystore server.keystore.jks -alias machine03.zheng.com -validity 365 -keyalg RSA -storepass leonzheng -keypass leonzheng -genkey -dname "C=CN,ST=FJ,L=FZ,O=LEON,OU=LEON,CN=ZHENG.COM"# 生成客户端keystore(密钥和证书)keytool -keystore client.keystore.jks -alias machine03.zheng.com -validity 365 -keyalg RSA -storepass leonzheng -keypass leonzheng -genkey -dname "C=CN,ST=FJ,L=FZ,O=LEON,OU=LEON,CN=ZHENG.COM"# 创建CA证书openssl req -new -x509 -keyout ca.key -out ca.crt -days 365 -passout pass:leonzheng -subj "/C=CN/ST=FJ/L=FZ/O=LEON/OU=LEON/CN=ZHENG.COM"# 将CA证书导入到服务器truststorekeytool -keystore server.truststore.jks -alias CARoot -import -file ca.crt -storepass leonzheng# 将CA证书导入到客户端truststorekeytool -keystore client.truststore.jks -alias CARoot -import -file ca.crt -storepass leonzheng# 导出服务器证书keytool -keystore server.keystore.jks -alias machine03.zheng.com -certreq -file cert-file -storepass leonzhengkeytool -keystore client.keystore.jks -alias machine03.zheng.com -certreq -file client-cert-file -storepass leonzheng# 用CA证书给服务器证书签名openssl x509 -req -CA ca.crt -CAkey ca.key -in cert-file -out cert-signed -days 365 -CAcreateserial -passin pass:leonzhengopenssl x509 -req -CA ca.crt -CAkey ca.key -in client-cert-file -out client-cert-signed -days 365 -CAcreateserial -passin pass:leonzheng# 将CA证书导入服务器keystorekeytool -keystore server.keystore.jks -alias CARoot -import -file ca.crt -storepass leonzhengkeytool -keystore client.keystore.jks -alias CARoot -import -file ca.crt -storepass leonzheng# 将已签名的服务器证书导入服务器keystorekeytool -keystore server.keystore.jks -alias machine03.zheng.com -import -file cert-signed -storepass leonzhengkeytool -keystore client.keystore.jks -alias machine03.zheng.com -import -file client-cert-signed -storepass leonzheng验证sslopenssl s_client -debug -connect 192.168.12.33:9093 -tls1openssl s_client -debug -connect 192.168.12.33:9092 -tls1config/server.propertiesssl.client.auth=requiredssl.keystore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/server.keystore.jksssl.keystore.password=leonzhengssl.key.password=leonzhengssl.truststore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/server.truststore.jksssl.truststore.password=leonzhengclientssl.propertiessecurity.protocol=SSLssl.truststore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/client.truststore.jksssl.truststore.password=leonzhengssl.keystore.location=/usr/local/kafka_2.11-0.10.1.0/ssl/client.keystore.jksssl.keystore.password=leonzhengssl.key.password=leonzhengbin/kafka-topics.sh --zookeeper 192.168.12.33:2181,192.168.12.33:2182,192.168.12.33:2183/kafka --create --topic testssl --partitions 3 --replication-factor 1bin/kafka-console-producer.sh --broker-list 192.168.12.33:9093 --topic testssl --producer.config /usr/local/kafka_2.11-0.10.1.0/ssl/clientssl.properties
bin/kafka-console-consumer.sh --bootstrap-server 192.168.12.33:9093 --topic testssl --from-beginning --consumer.config /usr/local/kafka_2.11-0.10.1.0/ssl/clientssl.properties