Skip to main content

OARepo Kerberos

Library for handling Kerberos authentication in OARepo repositories.

How to use

  1. Get a keytab file from your KDC and configure your repository to use it. This involves setting the KRB5_KTNAME flask application configuration to the location of the keytab file.

  2. Configure your repository to use its hostname in gssapi. This involves setting the 'GSSAPI_HOSTNAME' flask application configuration to the hostname of your repository.

  3. Test the Kerberos authentication by making requests to your repository and verifying that they are authenticated using Kerberos.

Limitations

Multi-leg SPNEGO is not supported

Authentication must complete in a single round trip. The negotiation cannot be resumed either — a fresh GSSAPI security context is built per request, and the continuation token is discarded unless that context completed — so a request needing a second leg is answered with 501 Not Implemented.

Successful Kerberos authentication logs the user in, which sets a session cookie. If a client then sends that cookie and Authorization: Negotiate ... on a later request, it is presenting two credentials that may name different principals, so the server refuses with 400 Bad Request rather than silently picking one.

Metadata

Release files for oarepo-kerberos 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for oarepo-kerberos 0.2.0
File Size Uploaded
oarepo_kerberos-0.2.0.tar.gz 5.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for oarepo-kerberos 0.2.0
File Interpreter ABI Platform
oarepo_kerberos-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 13.9 kB

Release files / oarepo_kerberos-0.2.0.tar.gz

Download URL oarepo_kerberos-0.2.0.tar.gz
Size 5.7 kB
Tags Source
SHA-256 checksum
How to use checksums
c8f25cf156bb37b90be837cb4447019bb906f971c8e477df97e4b63e0c6b1223
BLAKE2b-256 checksum
How to use checksums
9f11345db01baeb83c057cef243231fe47cf816e5126daec367c818ea81d6a9d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / oarepo_kerberos-0.2.0-py3-none-any.whl

Download URL oarepo_kerberos-0.2.0-py3-none-any.whl
Size 8.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
74838b0ac45ebbfcf4983f9c4e8c9af1b63a129db1177622a6101c01d162d5e6
BLAKE2b-256 checksum
How to use checksums
af72d99ce2c872045e9f88b8c00ab885602bba230e3c3337f1f915229087ea2c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page