Skip to main content

PyKerberos Package

This Python package is a high-level wrapper for Kerberos (GSSAPI) operations. The goal is to avoid having to build a module that wraps the entire Kerberos.framework, and instead offer a limited set of functions that do what is needed for client/server Kerberos authentication based on http://www.ietf.org/rfc/rfc4559.txt.

Much of the C-code here is adapted from Apache's mod_auth_kerb-5.0rc7.

Build

In this directory, run:

python setup.py build

Testing

To run the tests in the tests folder, you must have a valid Kerberos setup on the test machine. You can use the script .travis.sh as quick and easy way to setup a Kerberos KDC and Apache web endpoint that can be used for the tests. Otherwise you can also run the following to run a self contained Docker container

docker run \
-v $(pwd):/app \
-w /app \
-e PYENV=2.7.13 \
-e KERBEROS_USERNAME=administrator \
-e KERBEROS_PASSWORD=Password01 \
-e KERBEROS_REALM=example.com \
-e KERBEROS_PORT=80 \
ubuntu:16.04 \
/bin/bash .travis.sh

The docker command needs to be run in the same directory as this library and you can test it with different Python versions by changing the value of the PYENV environment value set in the command.

Please have a look at testing_notes.md for more information.

IMPORTANT

The checkPassword method provided by this library is meant only for testing purposes as it does not offer any protection against possible KDC spoofing. That method should not be used in any production code.

Channel Bindings

You can use this library to authenticate with Channel Binding support. Channel Bindings are tags that identify the particular data channel being used with the authentication. You can use Channel bindings to offer more proof of a valid identity. Some services like Microsoft's Extended Protection can enforce Channel Binding support on authorisation and you can use this library to meet those requirements.

More details on Channel Bindings as set through the GSSAPI can be found here https://docs.oracle.com/cd/E19455-01/806-3814/overview-52/index.html. Using TLS as a example this is how you would add Channel Binding support to your authentication mechanism. The following code snippet is based on RFC5929 https://tools.ietf.org/html/rfc5929 using the 'tls-server-endpoint-point' type.

import hashlib

def get_channel_bindings_application_data(socket):
    # This is a highly simplified example, there are other use cases
    # where you might need to use different hash types or get a socket
    # object somehow.
    server_certificate = socket.getpeercert(True)
    certificate_hash = hashlib.sha256(server_certificate).hexdigest().upper()
    certificate_digest = base64.b16decode(certificate_hash)
    application_data = b'tls-server-end-point:%s' % certificate_digest

    return application_data

def main():
    # Code to setup a socket with the server
    # A lot of code to setup the handshake and start the auth process
    socket = getsocketsomehow()

    # Connect to the host and start the auth process

    # Build the channel bindings object
    application_data = get_channel_bindings_application_data(socket)
    channel_bindings = kerberos.channelBindings(application_data=application_data)

    # More work to get responses from the server

    result, context = kerberos.authGSSClientInit(kerb_spn, gssflags=gssflags, principal=principal)

    # Pass through the channel_bindings object as created in the kerberos.channelBindings method
    result = kerberos.authGSSClientStep(context, neg_resp_value, channel_bindings=channel_bindings)

    # Repeat as necessary

Python APIs

See kerberos.py.

Copyright and License

Copyright (c) 2006-2021 Apple Inc. All rights reserved.

This software is licensed under the Apache License, Version 2.0. The Apache License is a well-established open source license, enabling collaborative open source software development.

See the "LICENSE" file for the full text of the license terms.

Release files for kerberos 1.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for kerberos 1.3.1
File Size Uploaded
kerberos-1.3.1.tar.gz 19.1 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for kerberos 1.3.1
File Interpreter ABI Platform
kerberos-1.3.1-cp39-cp39-macosx_10_9_x86_64.whl CPython 3.9 CPython 3.9 macOS 10.9+ x86-64 Details
kerberos-1.3.1-cp38-cp38-macosx_10_15_x86_64.whl CPython 3.8 CPython 3.8 macOS 10.15+ x86-64 Details
kerberos-1.3.1-cp27-cp27m-macosx_11_1_x86_64.whl CPython 2.7 CPython 2.7 pymalloc macosx 11 1 x86 64 Details

Total release size: 92.9 kB

Release files / kerberos-1.3.1.tar.gz

Download URL kerberos-1.3.1.tar.gz
Size 19.1 kB
Tags Source
SHA-256 checksum
How to use checksums
cdd046142a4e0060f96a00eb13d82a5d9ebc0f2d7934393ed559bac773460a2c
BLAKE2b-256 checksum
How to use checksums
39cdf98699a6e806b9d974ea1d3376b91f09edcb90415adbf31e3b56ee99ba64
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.3.0 pkginfo/1.6.1 requests/2.25.0 setuptools/51.1.2 requests-toolbelt/0.9.1 tqdm/4.54.1 CPython/3.9.1

Release files / kerberos-1.3.1-cp39-cp39-macosx_10_9_x86_64.whl

Download URL kerberos-1.3.1-cp39-cp39-macosx_10_9_x86_64.whl
Size 20.2 kB
Tags CPython 3.9 macOS 10.9+ x86-64
SHA-256 checksum
How to use checksums
2002b3b1541fc51e2c081ee7048f55e5d9ca63dd09f0d7b951c263920db3a0bb
BLAKE2b-256 checksum
How to use checksums
aa9ad10386fa7da4588e61fdafdbac2953576f7de6f693d112c74f09a9749fb6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.3.0 pkginfo/1.6.1 requests/2.25.0 setuptools/51.1.2 requests-toolbelt/0.9.1 tqdm/4.54.1 CPython/3.9.1

Release files / kerberos-1.3.1-cp38-cp38-macosx_10_15_x86_64.whl

Download URL kerberos-1.3.1-cp38-cp38-macosx_10_15_x86_64.whl
Size 33.2 kB
Tags CPython 3.8 macOS 10.15+ x86-64
SHA-256 checksum
How to use checksums
2e03c6a9d201d4aab5f899bfb8150de15335955bfce8ca43bfe9a41d7aae54dc
BLAKE2b-256 checksum
How to use checksums
69ec7f6d97eccefc748dd2d077b4fa1c608aab0fd0fa3638a7adb7a120408ff7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.3.0 pkginfo/1.6.1 requests/2.25.0 setuptools/51.1.2 requests-toolbelt/0.9.1 tqdm/4.54.1 CPython/3.9.1

Release files / kerberos-1.3.1-cp27-cp27m-macosx_11_1_x86_64.whl

Download URL kerberos-1.3.1-cp27-cp27m-macosx_11_1_x86_64.whl
Size 20.3 kB
Tags CPython 2.7 CPython 2.7 pymalloc macosx 11 1 x86 64
SHA-256 checksum
How to use checksums
98a695c072efef535cb2b5f98e474d00671588859a94ec96c2c1508a113ff3aa
BLAKE2b-256 checksum
How to use checksums
3e0e8336794ba89768623aec55aac4424b6db4608bb812f308f9b793093c045d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.3.0 pkginfo/1.6.1 requests/2.25.0 setuptools/51.1.2 requests-toolbelt/0.9.1 tqdm/4.54.1 CPython/3.9.1

Release history Release notifications | RSS feed

This release

1.3.1 This release

4 release files

1.3.0

1 release file

1.2.5

1 release file

1.2.4

1 release file

1.2.3

1 release file

1.2.2

1 release file

1.2.0

1.1.2

1 release file

1.1.1

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page