---
title: 2-way SSL with Kafka
description: In this post, we are going to use 2 different clients to connect the Kafka broker with 2-way SSL. We will use Advantco Kafka adapter as well as Kafka console to produce and consume messages from the broker.
image: https://resources.advantco.com/hubfs/Imported_Blog_Media/keystore_export_cert1.png
---

# 2-way SSL with Kafka

[ Admin ](https://resources.advantco.com/knowledge-base/author/admin)  Aug 1, 2019 12:00:00 AM

In this post, we are going to use 2 different clients to connect the Kafka broker with 2-way SSL. We will use Advantco Kafka adapter as well as Kafka console to produce and consume messages from the broker.

With 2-way SSL, here is how a client requests a resource in an encrypted channel:

1. A client requests a protected topic from the broker
2. The broker presents its identity by a certificate
3. The client verifies the broker certificate
4. In the other way, the client also sends its certificate to the broker for the verification
5. The broker verifies the client certificate
6. If success, the broker grants access to the topic to the client

In this post, we just focus on how to setup on client side, and we assume the broker is set up with SSL/TLS and ready to use. We will need this information from the broker for the connectivity:

- The port that the broker listening for SSL (SSL://{port} or SASL_SSL://{port}).
- The certificate for the server authentication. It could be exported from the truststore (server.truststore.jks) or the keystore (server.keystore.jks). Let say a cluster with multiple brokers and we have a different keystore for each broker, but the CA Root certificate to sign the CSR for each keystore/broker is the same. Let name it as caroot_godaddy.crt for reference later.
- The client authentication flag by setting client.auth has to be “requested” or “required”.

We are using terms “keystore” and “truststore” frequently throughout the article. Let explain it first, “keystore” is a repository/file that stores private-public keys and certificates, and “truststore” is a repository/file that stores only certificates.

Now we have the certificate from the broker (caroot_godaddy.crt) for the server authentication (aka 1-way SSL). For the client authentication (second way SSL), we need a keystore which includes public-private keys and a signed certificate (self-signed or from a trusted CA) and a CA Root certificate that signed the certificate.

**Create a keytstore and a CA Root certificate**

The CA Root certificate is to sign the certificate signing request (CSR), and we can generate it to sign the certificate (self-signed) or we can export it from a trusted CA.

Let create a keystore for the client.

Create a client keystore

```
keytool -genkey -keystore client.keystore.jks -validity 3650 -storepass "password1" -keypass "password1" -dname "CN=client1" -alias client1 -storetype pkcs12
```

Create a client cert sign request (CSR)

```
keytool -keystore client.keystore.jks -certreq -file client-cert-sign-request -alias client1 -storepass "password1" -keypass "password1"
```

The CSR file could be signed by a trusted CA or by self-signed.

Here are steps if we want to sign the certificate by ourselves

- Create CA key and CA cert
  
  ```
  openssl req -new -x509 -keyout ca-key -out ca-cert -days 3650
  ```
- Sign the CSR file with the CA key and CA cert
  
  ```
  openssl x509 -req -CA ca-cert -CAkey ca-key -in client-cert-sign-request -out client-cert-signed -days 3650 -CAcreateserial -passin pass:password1
  ```
- Create a complete chain certificate. Use any text editor to copy content of file ca-cert and client-cert-signed to a new file called completeChain.crt. Similar with Unix command
  
  ```
  cat ca-cert client-cert-signed > completeChain.crt
  ```

Now we will import the certificate chain to the keystore.

```
keytool -keystore client.keystore.jks -import -file completeChain.crt -alias client1 -storepass "password1" -keypass "password1" -noprompt
```

The keystore is ready to use. The last step is to export the CA Root certificate.

*If we signed the certificate by ourselves then the ca-cert is the CA Root certificate.*

We are using KeyStore Explorer to export the CA Root certificate. ![2-way SSL with Kafka](https://resources.advantco.com/hubfs/Imported_Blog_Media/keystore_export_cert1.png)

![2-way SSL with Kafka](https://resources.advantco.com/hubfs/Imported_Blog_Media/keystore_export_cert2.png) Name the CA Root certificate to *carootsapcpip0520.crt*

**Import the CA Root certificate to Kafka broker**

This step should be performed by Kafka team. We send the CA Root certificate file from the previous step and ask them to import it to the broker truststore.

Assume the broker truststore file name is server.truststore.jks

```
keytool -keystore server.truststore.jks -alias carootsapcpip0520 -import -file carootsapcpip0520.crt -storepass "{password of truststore}" -noprompt
```

*This step is not always required. Like in a corporation we are using the same trusted CA to sign certificates for multiple system including Kafka brokers, then the CA Root certificate is already in the truststore.*

**Make a connection with Advantco Kafka Adapter**

There are different versions for 2 platforms SAP CPI/HCI and PI/PO, but the adapter configuration is identical.

The 2-way SSL can be used for none authentication mode as long as other authentication modes such as Kerberos, Plain, SCRAM..

We have a keystore *(client.keystore.jks)* and a certificate *(caroot_godaddy.crt)* from the previous steps, let import it to the Key Storage for referencing in the channel configuration later.

Java KeyStore (JKS) format of the keystore is not supported by PI/PO Key Storage, we have to convert it to P12 format.

Convert JKS to P12

```
keytool -importkeystore -srckeystore client.keystore.jks -destkeystore client.keystore.p12 -deststoretype pkcs12
```

Key Storage View SAP_KAFKA_CLIENT

![2-way SSL with Kafka](https://resources.advantco.com/hubfs/Imported_Blog_Media/nw_keystorage_view.png)

 

*Similar with SAP CPI/HCI, create 2 entries one for Keystore and one for Certificate. The cloud platform supports JKS, so we don’t have to convert the keystore to P12 format.*

Here is an example of 2-way SSL with Kerberos

![2-way SSL with Kafka](https://resources.advantco.com/hubfs/Imported_Blog_Media/nw_kafkachannel_configuration.png)

 

**Test the connectivity with Kafka console**

The best way to test 2-way SSL is using Kafka console, we don’t have to write any line of code to test it.

Simply download Kafka from Apache Kafka website to the client, it includes kafka-console-producer and kafka-console-consumer in bin directory. We will use one of it to test the connectivity.

To use the console we have to create 2 things:

Wrapper the server certificate *(caroot_godaddy.crt)* to a client truststore

```
keytool -keystore client.truststore.jks -alias CARoot -import -file caroot_godaddy.crt -storepass "password1" -noprompt
```

Create a client property *file client-ssl.properties* and copy it to kafka bin directory, should have following lines:

```
security.protocol=SSL
    ssl.truststore.location=client.truststore.jks
    ssl.truststore.password=password1
    ssl.endpoint.identification.algorithm=
    ssl.keystore.location=client.keystore.jks
    ssl.keystore.password=password1
    ssl.key.password=password1
    
```

It’s ready to use the kafka console producer to produce a test message to a topic

```
./bin/kafka-console-producer --broker-list {broker name}:{port} --producer.config client-ssl.properties –topic {topic name}
```

We are done. Hope you find it useful.

Please reach out to our sales team at [sales@advantco.com](mailto:sales@advantco.com) if you have any questions.

[Kafka](https://resources.advantco.com/knowledge-base/tag/kafka), [Kafka-PO-CPI](https://resources.advantco.com/knowledge-base/tag/kafka-po-cpi)

## Read On

[![](https://resources.advantco.com/hs-fs/hubfs/Imported_Blog_Media/pulsar-system-architecture.png?width=352&name=pulsar-system-architecture.png) ](https://resources.advantco.com/knowledge-base/content/apache-pulsar-adapter-for-sap-po)

### [Apache Pulsar adapter for SAP PO](https://resources.advantco.com/knowledge-base/content/apache-pulsar-adapter-for-sap-po)

**Overview**

[![](https://resources.advantco.com/hs-fs/hubfs/Imported_Blog_Media/1-34.png?width=352&name=1-34.png) ](https://resources.advantco.com/knowledge-base/content/apache-kafka-integration)

### [Apache Kafka Integration](https://resources.advantco.com/knowledge-base/content/apache-kafka-integration)

With capabilities like real-time data processing, fast, scalable, durable, and fault-tolerant...

[![](https://resources.advantco.com/hs-fs/hubfs/Imported_Blog_Media/1AdvantcoKafkaWorkbench.png?width=352&name=1AdvantcoKafkaWorkbench.png) ](https://resources.advantco.com/knowledge-base/content/kafka-adapter-with-avro-serialization-and-schema-registry)

### [Kafka adapter with Avro serialization and Schema Registry](https://resources.advantco.com/knowledge-base/content/kafka-adapter-with-avro-serialization-and-schema-registry)

Confluent Schema Registry stores Avro schemas for Kafka producer and consumer so that...

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Admin",
    "url" : "https://resources.advantco.com/knowledge-base/author/admin"
  },
  "dateModified" : "2022-05-02T19:07:02.235Z",
  "datePublished" : "2019-08-01T04:00:00.000Z",
  "headline" : "2-way SSL with Kafka",
  "image" : [ "https://resources.advantco.com/hubfs/Imported_Blog_Media/keystore_export_cert1.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://resources.advantco.com/knowledge-base/content/2-way-ssl-with-kafka",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://resources.advantco.com/hubfs/Advantco%20logo%20AAC%20V1%20Ai%20file%201.png"
    },
    "name" : "Advantco International"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "NewsArticle",
  "author" : [ {
    "@type" : "Person",
    "name" : "Admin",
    "url" : "https://resources.advantco.com/knowledge-base/author/admin"
  } ],
  "dateModified" : "2022-05-02T19:07:02",
  "datePublished" : "2019-08-01T04:00:00",
  "headline" : "2-way SSL with Kafka",
  "image" : [ "https://f.hubspotusercontent20.net/hubfs/6260070/Imported_Blog_Media/keystore_export_cert1.png" ]
}
```

```json
{
  "@context" : "http://schema.org",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "United States",
    "addressLocality" : "Charlotte",
    "addressRegion" : "NC",
    "postalCode" : "28203",
    "streetAddress" : "1235 East Blvd, Suite E #382 "
  },
  "alternateName" : "advantco",
  "areaServed" : {
    "@type" : "GeoCircle",
    "geoMidpoint" : {
      "@type" : "GeoCoordinates",
      "latitude" : "40.75996223497667",
      "longitude" : "-73.98761007334504"
    },
    "geoRadius" : "150 km"
  },
  "description" : "Feature rich Advantco adapters integrates SAP &amp; Oracle system with top enterprise platforms like Kafka, Salesforce, Azure, and more.",
  "email" : "webadmin@advantco.com",
  "image" : "https://www.advantco.com/hs-fs/hubfs/unnamed%20(2).webp?width=450&height=60&name=unnamed%20(2).webp",
  "logo" : "https://6260070.fs1.hubspotusercontent-na1.net/hubfs/6260070/Advantco%20logo%20AAC%20V1%20Ai%20file%201.png",
  "mainEntityOfPage" : {
    "@id" : "https://resources.advantco.com/knowledge-base/content/2-way-ssl-with-kafka",
    "@type" : "WebPage",
    "description" : "In this post, we are going to use 2 different clients to connect the Kafka broker with 2-way SSL. We will use Advantco Kafka adapter as well as Kafka console to produce and consume messages from the broker."
  },
  "naics" : "513210",
  "name" : "Advantco International",
  "sameAs" : [ "https://www.linkedin.com/company/advantco-international-llc" ],
  "telephone" : "",
  "url" : "https://www.advantco.com/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "WebPage",
  "about" : [ {
    "@id" : "https://resources.advantco.com/knowledge-base/content/advantco-pre-packaged-content-solution",
    "@type" : "WebPage"
  }, {
    "@id" : "https://www.advantco.com/sap-hana-sdi-integration-adapters/sap-hana-sdi-salesforce-integration",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/salesforce-integration-common-requirements-and-use-cases",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/the-top-5-advantages-of-sap-and-salesforce-integration",
    "@type" : "WebPage"
  }, {
    "@id" : "https://www.advantco.com/sap-integration-adapters/sap-salesforce-integration",
    "@type" : "WebPage"
  } ],
  "mainEntity" : {
    "@type" : "WebPage"
  },
  "url" : "https://www.advantco.com/sap-integration-adapters/sap-salesforce-integration"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "WebPage",
  "about" : [ {
    "@id" : "https://resources.advantco.com/knowledge-base/receiving-events-from-dynamics-365-crm-using-webhooks",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/microsoft-dynamics-crm-adapter-for-sap-process-orchestration-and-sap-integration-suite-now-available-on-sap-store",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/adapters-for-sap-hci-integration-with-ms-dynamics-crm-and-rabbitmq",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/sap-cloud-platform-integration-enhancing-the-third-party-application-connectivity-with-new-offerings",
    "@type" : "WebPage"
  } ],
  "mainEntity" : {
    "@type" : "WebPage"
  },
  "url" : "https://www.advantco.com/sap-integration-adapters/sap-microsoft-dynamics-integration"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "WebPage",
  "about" : [ {
    "@id" : "https://resources.advantco.com/knowledge-base/content/sap-cloud-platform-integration-enhancing-the-third-party-application-connectivity-with-new-offerings",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/using-advantco-aws-adapter-to-integrate-sap-and-aws-business-environments",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/integrating-sap-and-aws-business-environments-with-the-advantco-aws-adapter",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/product/adapter/aws",
    "@type" : "WebPage"
  } ],
  "mainEntity" : {
    "@type" : "WebPage"
  },
  "url" : "https://www.advantco.com/sap-integration-adapters/sap-aws-integration"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "WebPage",
  "about" : [ {
    "@id" : "https://resources.advantco.com/knowledge-base/content/google-cloud-platform-adapter-from-advantco-international-now-available-on-sap-store",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/product/adapter/google-cloud-platform-adapter-for-sap-cpi",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/advantco-google-cloud-platform-adapter-integrating-sap-with-gcp",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/advantco-google-cloud-platform-adapter-integrating-sap-with-gcp",
    "@type" : "WebPage"
  } ],
  "mainEntity" : {
    "@type" : "WebPage"
  },
  "url" : "https://www.advantco.com/sap-integration-adapters/sap-google-cloud-integration"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "WebPage",
  "about" : [ {
    "@id" : "https://resources.advantco.com/knowledge-base/consumer-electronics-retailer-turns-to-advantco-amqp-azure-adapters",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/adapters-for-sap-hci-integration-with-ms-dynamics-crm-and-rabbitmq",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/integration-with-microsoft-azure-cloud",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/using-rabbitmqamqp-broker-for-extreme-high-volume-integration-with-sap-hybris-commerce-solution-with-sap-pipo",
    "@type" : "WebPage"
  } ],
  "mainEntity" : {
    "@type" : "WebPage"
  },
  "url" : "https://www.advantco.com/sap-integration-adapters/sap-azure-integration"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "WebPage",
  "about" : [ {
    "@id" : "https://resources.advantco.com/knowledge-base/lessons-learned-from-kafka-integrations-using-the-advantco-kafka-adapter-for-sap-integration-suite",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/kafka-adapter-for-sap-process-orchestration-and-sap-integration-suite-now-available-on-sap-store",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/advantco-kafka-adapter-enables-automobile-leader-to-use-big-data",
    "@type" : "WebPage"
  }, {
    "@id" : "https://resources.advantco.com/knowledge-base/content/kafka-adapter-with-avro-serialization-and-schema-registry",
    "@type" : "WebPage"
  } ],
  "mainEntity" : {
    "@type" : "WebPage"
  },
  "url" : "https://www.advantco.com/sap-integration-adapters/sap-kafka-integration"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "WebPage",
  "about" : [ {
    "@id" : "https://www.advantco.com/sap-integration-adapters/sap-salesforce-integration",
    "@type" : "WebPage"
  }, {
    "@id" : "https://www.advantco.com/sap-integration-adapters/sap-microsoft-dynamics-integration",
    "@type" : "WebPage"
  }, {
    "@id" : "https://www.advantco.com/sap-integration-adapters/sap-aws-integration",
    "@type" : "WebPage"
  }, {
    "@id" : "https://www.advantco.com/sap-integration-adapters/sap-google-cloud-integration",
    "@type" : "WebPage"
  }, {
    "@id" : "https://www.advantco.com/sap-integration-adapters/sap-azure-integration",
    "@type" : "WebPage"
  }, {
    "@id" : "https://www.advantco.com/sap-integration-adapters/sap-kafka-integration",
    "@type" : "WebPage"
  } ],
  "mainEntity" : {
    "@type" : "WebPage"
  },
  "url" : "https://www.advantco.com/"
}
```

```json
{
  "@context" : "https://schema.org/",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://advantco.com/",
    "name" : "Home",
    "position" : 1
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "ProfessionalService",
  "areaServed" : {
    "@type" : "GeoShape",
    "address" : {
      "@type" : "PostalAddress",
      "addressCountry" : "US"
    }
  },
  "description" : "Advantco helps organizations update and transform their integration landscapes by migrating to SAP BTP Integration Suite, enabling secure, scalable, cloud-native connectivity across SAP and non-SAP systems.",
  "image" : "https://www.advantco.com/hs-fs/hubfs/1-2.png?width=2000&height=1015&name=1-2.png",
  "logo" : "https://www.advantco.com/hs-fs/hubfs/unnamed%20(2).webp?width=300&height=40&name=unnamed%20(2).webp",
  "name" : "SAP BTP Integration Suite Migration Services",
  "provider" : {
    "@type" : "Organization",
    "contactPoint" : {
      "@type" : "ContactPoint",
      "availableLanguage" : [ "English" ],
      "contactType" : "customer support",
      "url" : "https://www.advantco.com/contact-us"
    },
    "logo" : "https://www.advantco.com/hs-fs/hubfs/unnamed%20(2).webp?width=300&height=40&name=unnamed%20(2).webp",
    "name" : "Advantco",
    "sameAs" : [ "https://www.linkedin.com/company/advantco-international-llc/", "https://x.com/AdvantcoAdapter" ],
    "url" : "https://www.advantco.com"
  },
  "serviceType" : [ "SAP BTP Integration Suite Migration", "Legacy Middleware Migration", "Clean Core & Customization Rationalization", "ABAP & API Development" ],
  "url" : "https://www.advantco.com/sap-btp-integration-suite-migration"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "ProfessionalService",
  "description" : "Advantco offers secure, scalable, and cost-optimized AWS cloud services — from landing zone setup and migration to managed operations and AI/ML solutions.",
  "image" : "https://www.advantco.com/hs-fs/hubfs/4%20(1)-1.png?width=316&height=300&name=4%20(1)-1.png",
  "logo" : "https://www.advantco.com/hs-fs/hubfs/unnamed%20(2).webp?width=300&height=40&name=unnamed%20(2).webp",
  "name" : "AWS Cloud Services",
  "provider" : {
    "@type" : "Organization",
    "contactPoint" : {
      "@type" : "ContactPoint",
      "availableLanguage" : [ "English" ],
      "contactType" : "customer support",
      "url" : "https://www.advantco.com/contact-us"
    },
    "logo" : "https://www.advantco.com/hs-fs/hubfs/unnamed%20(2).webp?width=300&height=40&name=unnamed%20(2).webp",
    "name" : "Advantco",
    "sameAs" : [ "https://www.linkedin.com/company/advantco-international-llc/", "https://x.com/AdvantcoAdapter" ],
    "url" : "https://www.advantco.com"
  },
  "serviceType" : [ "AWS Landing Zone Setup", "AWS Application Migration", "Managed AWS Cloud Operations", "AWS AI/ML Solutions" ],
  "url" : "https://www.advantco.com/aws-cloud-services"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "ProfessionalService",
  "areaServed" : {
    "@type" : "Country",
    "name" : "Worldwide"
  },
  "description" : "Advantco helps organizations harness the full power of Google Cloud by designing, migrating, and managing secure, scalable, and cost-optimized workloads end-to-end.",
  "image" : "https://www.advantco.com/hs-fs/hubfs/4%20(1)-1.png?width=316&height=300&name=4%20(1)-1.png",
  "logo" : "https://www.advantco.com/hs-fs/hubfs/unnamed%20(2).webp?width=300&height=40&name=unnamed%20(2).webp",
  "name" : "Google Cloud Services",
  "provider" : {
    "@type" : "Organization",
    "contactPoint" : {
      "@type" : "ContactPoint",
      "availableLanguage" : [ "English" ],
      "contactType" : "customer support",
      "url" : "https://www.advantco.com/contact-us"
    },
    "logo" : "https://www.advantco.com/hs-fs/hubfs/unnamed%20(2).webp?width=300&height=40&name=unnamed%20(2).webp",
    "name" : "Advantco",
    "sameAs" : [ "https://www.linkedin.com/company/advantco-international-llc/", "https://x.com/AdvantcoAdapter" ],
    "url" : "https://www.advantco.com"
  },
  "serviceType" : [ "Google Cloud Foundation Setup", "Application Migration & Modernization", "Managed Google Cloud Operations", "Data Analytics & AI/ML Solutions" ],
  "url" : "https://www.advantco.com/google-cloud-services"
}
```