Steven Hall
11/17/2022, 1:25 AMSeunghyun
11/17/2022, 7:31 AMMayank
Steven Hall
11/17/2022, 5:34 PMSeunghyun
11/17/2022, 5:49 PMOAuth2 authentication for accessing Kafka Cluster using Okta.
Can you try out this? you can add the following within streamConfig
security.protocol=SASL_PLAINTEXT
sasl.mechanism=OAUTHBEARER
sasl.login.callback.handler.class=com.oauth2.security.oauthbearer.OAuthAuthenticateLoginCallbackHandler
sasl.jaas.config=org.apache.kafka.common.security.oauthbearer.OAuthBearerLoginModule required OAUTH_LOGIN_SERVER=<OAuth-server-url> OAUTH_LOGIN_ENDPOINT='/oauth2/default/v1/token' OAUTH_LOGIN_GRANT_TYPE=client_credentials OAUTH_LOGIN_SCOPE=kafka OAUTH_AUTHORIZATION='Basic <encoded-producer-clientId:clientsecret>' OAUTH_INTROSPECT_SERVER=<OAuth-server-url> OAUTH_INTROSPECT_ENDPOINT='/oauth2/default/v1/introspect' OAUTH_INTROSPECT_AUTHORIZATION='Basic <encoded-producer-clientId:clientsecret>';
https://medium.com/egen/how-to-configure-oauth2-authentication-for-apache-kafka-cluster-using-okta-8c60d4a85b43Seunghyun
11/17/2022, 5:53 PMSeunghyun
11/17/2022, 5:56 PM' -> \'
e.g.
"streamConfigs": {
"security.protocol": "SASL_PLAINTEXT"
"sasl.mechanism": "OAUTHBEARER"
"sasl.login.callback.handler.class": "com.oauth2.security.oauthbearer.OAuthAuthenticateLoginCallbackHandler",
"sasl.jaas.config": "org.apache.kafka.common.security.oauthbearer.OAuthBearerLoginModule required OAUTH_LOGIN_SERVER=<OAuth-server-url> OAUTH_LOGIN_ENDPOINT=\'/oauth2/default/v1/token\' OAUTH_LOGIN_GRANT_TYPE=client_credentials OAUTH_LOGIN_SCOPE=kafka OAUTH_AUTHORIZATION=\'Basic <encoded-producer-clientId:clientsecret>\' OAUTH_INTROSPECT_SERVER=<OAuth-server-url> OAUTH_INTROSPECT_ENDPOINT=\'/oauth2/default/v1/introspect\' OAUTH_INTROSPECT_AUTHORIZATION=\'Basic <encoded-producer-clientId:clientsecret>\'"
}Steven Hall
11/17/2022, 6:11 PMSeunghyun
11/17/2022, 6:14 PMSteven Hall
11/17/2022, 6:52 PMAtul Patil
11/07/2023, 10:38 AM"sasl.mechanism": "OAUTHBEARER"
_"security.protocol": "SASL_PLAINTEXT"_
_"sasl.jaas.config": "org.apache.kafka.common.security.oauthbearer.OAuthBearerLoginModule required oauth.client.id=\"<client_id>\" oauth.client.secret=\"<client_secret>\" oauth.token.endpoint.uri=\"<oauth_token_endpoint_uri>";"_
"sasl.login.callback.handler.class": "com.oauth2.security.oauthbearer.OAuthAuthenticateLoginCallbackHandler"But, I'm getting an exception:
<http://org.apache.pinot.shaded.org|org.apache.pinot.shaded.org>.apache.kafka.common.config.ConfigException: Invalid value com.oauth2.security.oauthbearer.OAuthAuthenticateLoginCallbackHandler for configuration sasl.login.callback.handler.class: Class com.oauth2.security.oauthbearer.OAuthAuthenticateLoginCallbackHandler could not be found.
Do you/the team have any suggestions? Thanks!Steven Hall
11/07/2023, 11:54 PM