# Install and configure RBAC

**URL:** <https://forum.confluent.io/t/install-and-configure-rbac/3284>\
**Category:** Ops\
**Created:** [4 November 2021 16:48 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284 "2021-11-04T16:48:36Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![GiuseppeR](https://avatars.discourse-cdn.com/v4/letter/g/d07c76/32.png) [@GiuseppeR](https://forum.confluent.io/u/GiuseppeR)\
**Post date:** [4 November 2021 16:48 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284/1 "2021-11-04T16:48:36Z")

</div>

I have a cluster running Confluent platform on a remote server. I need to manage users: some users can create a topic, other can subscribe to a topic, etc.  
I see there is a RBAC system…but it seems to use it, it is necessary to migrate to confluent server:

[https://docs.confluent.io/platform/current/installation/migrate-confluent-server.html](https://docs.confluent.io/platform/current/installation/migrate-confluent-server.html)

but my cluster doesn’t run confluent kafka: if I try with:

> sudo systemctl stop confluent-kafka  
> Failed to stop confluent-kafka.service: Unit confluent-kafka.service not loaded.

Confluent server is not a free component? I need to buy it?  
If I need to configure RBAC throught API

([Configure RBAC using the REST API | Confluent Documentation](https://docs.confluent.io/platform/current/security/rbac/rbac-config-using-rest-api.html))

what are:

```auto
<path-to-your-cacert> --key <path-to-your-private-key> --cert <path-to-your-cert>

```

Someone can help me to understand how install and configure RBAC on Confluent platform?  
Thanks.

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [5 November 2021 14:19 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284/2 "2021-11-05T14:19:51Z")

</div>

Hi @GiuseppeR ,

maybe we should first of all clarify your environment.

Do you know how the Kafka environment has been installed?  
Just guessing but maybe it was installed with tarballs and not with rpm packages.

Could you check if there is a file like `/etc/kafka/server.properties` ?

And also whether there is binary called `confluent`  
(I would try with `which` or `locate`)

HTH,  
Michael

---

<div class="post-metadata">

**Author:** ![GiuseppeR](https://avatars.discourse-cdn.com/v4/letter/g/d07c76/32.png) [@GiuseppeR](https://forum.confluent.io/u/GiuseppeR)\
**Post date:** [5 November 2021 14:50 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284/3 "2021-11-05T14:50:04Z")

</div>

Hi @mmuehlbeyer thank you for your reply.  
Confluent Platform is installed on an Ubuntu server.  
I installed Confluent Platform throught the zip file (confluent-6.1.0.zip).  
Yes there is a server.properties.  
With the command:

> locale confluent.bin

no result.  
Hoping this can help to give me some suggestion.  
Thanks.  
g

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [5 November 2021 15:07 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284/4 "2021-11-05T15:07:20Z")

</div>

Hi,

as you‘ve installed via zip file there is no systems service by the default (afaik)

Did you start the confluent platform/kafka manually or not yet?

If you would keep the zip installation path you could download the confluent entrrprise zip and extract to a new location and then proceed.

Best,  
Michael

---

<div class="post-metadata">

**Author:** ![GiuseppeR](https://avatars.discourse-cdn.com/v4/letter/g/d07c76/32.png) [@GiuseppeR](https://forum.confluent.io/u/GiuseppeR)\
**Post date:** [5 November 2021 15:48 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284/5 "2021-11-05T15:48:03Z")

</div>

Yes I start manually Confluent platform with the command:

```auto
confluent local services start/stop

```

I try to find Confluent enterprise on the download page:

[https://www.confluent.io/installation](https://www.confluent.io/installation)

but there is not any enterprise version!  
It seems there is an older version…any other suggestion?  
Thanks.  
g

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [8 November 2021 08:43 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284/6 "2021-11-08T08:43:21Z")

</div>

ok I see

the enterprise edition is not named “enterprise” explicitly.  
the community edition is named explicitly, e.g [https://packages.confluent.io/archive/7.0/confluent-community-7.0.0.tar.gz](https://packages.confluent.io/archive/7.0/confluent-community-7.0.0.tar.gz)

therefore I guess you’re already running the correct binaries.

for configuring rbac please have a look at

[https://docs.confluent.io/platform/current/security/rbac/enable-rbac-running-cluster.html#enable-rbac-in-a-running-cluster](https://docs.confluent.io/platform/current/security/rbac/enable-rbac-running-cluster.html#enable-rbac-in-a-running-cluster)

[https://docs.confluent.io/platform/current/kafka/incremental-security-upgrade.html#kafka-adding-security](https://docs.confluent.io/platform/current/kafka/incremental-security-upgrade.html#kafka-adding-security)

Best,  
Michael

---

<div class="post-metadata">

**Author:** ![GiuseppeR](https://avatars.discourse-cdn.com/v4/letter/g/d07c76/32.png) [@GiuseppeR](https://forum.confluent.io/u/GiuseppeR)\
**Post date:** [9 November 2021 15:38 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284/7 "2021-11-09T15:38:58Z")

</div>

Hi @mmuehlbeyer It seems confluent server is a commercial component…so I need to open source software…  
So I need to secure communication with clients-broker…I read this tutorial:

[https://docs.confluent.io/platform/current/security/security\_tutorial.html#security-tutorial](https://docs.confluent.io/platform/current/security/security_tutorial.html#security-tutorial)

but It is not clear how configure the clients, for example common configuration what do they refer to? where do they take place?  
My cluster have 1 broker, 1 producer and 3 consumers…I need the communication with producer-kafka and kafka-consumer uses a secure protocol.  
Hoping in your help.  
Thanks.

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [9 November 2021 16:24 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284/8 "2021-11-09T16:24:37Z")

</div>

Hi @GiuseppeR

talking about producer and consumers

which kind of consumers are you using? java, pyhthon,…?

---

<div class="post-metadata">

**Author:** ![GiuseppeR](https://avatars.discourse-cdn.com/v4/letter/g/d07c76/32.png) [@GiuseppeR](https://forum.confluent.io/u/GiuseppeR)\
**Post date:** [9 November 2021 16:41 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284/9 "2021-11-09T16:41:01Z")

</div>

I’m sorry…I’m using python.  
g

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [10 November 2021 08:53 UTC](https://forum.confluent.io/t/install-and-configure-rbac/3284/10 "2021-11-10T08:53:12Z")

</div>

ok I see

I’m not that deep in dev topics but there is quite nice blog about python and ssl

> **[Connecting to Kafka cluster using SSL with Python](https://dev.to/adityakanekar/connecting-to-kafka-cluster-using-ssl-with-python-k2e)**
>
> This article specifically talks about how to write producer and consumer for Kafka cluster secured...
