Skip to main content
Info:

See github for the latest source.

Author:

Bernie Hackett <bernie@mongodb.com>

About

A native Kerberos client implementation for Python on Windows. This module mimics the API of pykerberos to implement Kerberos authentication with Microsoft’s Security Support Provider Interface (SSPI). It supports Python 3.10+.

Installation

WinKerberos is in the Python Package Index (pypi). Use pip to install it:

python -m pip install winkerberos

WinKerberos requires Windows 7 / Windows Server 2008 R2 or newer.

Building and installing from source

You must have the correct version of VC++ installed for your version of Python:

  • Python 3.10+ - Visual Studio 2015+ (Any version)

Once you have the required compiler installed, run the following command from the root directory of the WinKerberos source:

pip install .

Building HTML documentation

First install Sphinx:

python -m pip install Sphinx

Then run the following command from the root directory of the WinKerberos source:

pip install -e .
python -m sphinx -b html doc doc/_build

Examples

This is a simplified example of a complete authentication session following RFC-4752, section 3.1:

import winkerberos as kerberos


def send_response_and_receive_challenge(response):
    # Your server communication code here...
    pass


def authenticate_kerberos(service, user, channel_bindings=None):
    # Initialize the context object with a service principal.
    status, ctx = kerberos.authGSSClientInit(service)

    # GSSAPI is a "client goes first" SASL mechanism. Send the
    # first "response" to the server and receive its first
    # challenge.
    if channel_bindings is not None:
        status = kerberos.authGSSClientStep(ctx, "", channel_bindings=channel_bindings)
    else:
        status = kerberos.authGSSClientStep(ctx, "")
    response = kerberos.authGSSClientResponse(ctx)
    challenge = send_response_and_receive_challenge(response)

    # Keep processing challenges and sending responses until
    # authGSSClientStep reports AUTH_GSS_COMPLETE.
    while status == kerberos.AUTH_GSS_CONTINUE:
        if channel_bindings is not None:
            status = kerberos.authGSSClientStep(
                ctx, challenge, channel_bindings=channel_bindings
            )
        else:
            status = kerberos.authGSSClientStep(ctx, challenge)

        response = kerberos.authGSSClientResponse(ctx) or ""
        challenge = send_response_and_receive_challenge(response)

    # Decrypt the server's last challenge
    kerberos.authGSSClientUnwrap(ctx, challenge)
    data = kerberos.authGSSClientResponse(ctx)
    # Encrypt a response including the user principal to authorize.
    kerberos.authGSSClientWrap(ctx, data, user)
    response = kerberos.authGSSClientResponse(ctx)

    # Complete authentication.
    send_response_and_receive_challenge(response)

Channel bindings can be generated with help from the cryptography module. See https://tools.ietf.org/html/rfc5929#section-4.1 for the rules regarding hash algorithm choice:

from cryptography import x509
from cryptography.hazmat.backends import default_backend
from cryptography.hazmat.primitives import hashes


def channel_bindings(ssl_socket):
    server_certificate = ssl_socket.getpeercert(True)
    cert = x509.load_der_x509_certificate(server_certificate, default_backend())
    hash_algorithm = cert.signature_hash_algorithm
    if hash_algorithm.name in ("md5", "sha1"):
        digest = hashes.Hash(hashes.SHA256(), default_backend())
    else:
        digest = hashes.Hash(hash_algorithm, default_backend())
    digest.update(server_certificate)
    application_data = b"tls-server-end-point:" + digest.finalize()
    return kerberos.channelBindings(application_data=application_data)

Viewing API Documentation without Sphinx

Use the help function in the python interactive shell:

>>> import winkerberos
>>> help(winkerberos)

Metadata

Release files for winkerberos 0.13.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for winkerberos 0.13.0
File Size Uploaded
winkerberos-0.13.0.tar.gz 35.7 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for winkerberos 0.13.0
File
winkerberos-0.13.0-cp314-cp314t-win_amd64.whl CPython 3.14 CPython 3.14 free-threading Windows x86-64 Details
winkerberos-0.13.0-cp314-cp314t-win32.whl CPython 3.14 CPython 3.14 free-threading Windows x86-32 Details
winkerberos-0.13.0-cp314-cp314-win_amd64.whl CPython 3.14 CPython 3.14 Windows x86-64 Details
winkerberos-0.13.0-cp314-cp314-win32.whl CPython 3.14 CPython 3.14 Windows x86-32 Details
winkerberos-0.13.0-cp313-cp313-win_amd64.whl CPython 3.13 CPython 3.13 Windows x86-64 Details
winkerberos-0.13.0-cp313-cp313-win32.whl CPython 3.13 CPython 3.13 Windows x86-32 Details
winkerberos-0.13.0-cp312-cp312-win_amd64.whl CPython 3.12 CPython 3.12 Windows x86-64 Details
winkerberos-0.13.0-cp312-cp312-win32.whl CPython 3.12 CPython 3.12 Windows x86-32 Details
winkerberos-0.13.0-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
winkerberos-0.13.0-cp311-cp311-win32.whl CPython 3.11 CPython 3.11 Windows x86-32 Details
winkerberos-0.13.0-cp310-cp310-win_amd64.whl CPython 3.10 CPython 3.10 Windows x86-64 Details
winkerberos-0.13.0-cp310-cp310-win32.whl CPython 3.10 CPython 3.10 Windows x86-32 Details

Total release size: 359.9 kB

Release files / winkerberos-0.13.0.tar.gz

Download URL winkerberos-0.13.0.tar.gz
Size 35.7 kB
Tags Source
SHA-256 checksum
How to use checksums
f3fbb67346fe8ed697e125724b0699d5c2a15b9a5f9151d25a1be88df8dac427
BLAKE2b-256 checksum
How to use checksums
ca6c455f043bc28694a278125d1fc2ab7cbf0ce0953c97bbe1021f08fd19c7b8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp314-cp314t-win_amd64.whl

Download URL winkerberos-0.13.0-cp314-cp314t-win_amd64.whl
Size 28.7 kB
Tags CPython 3.14 CPython 3.14 free-threading Windows x86-64
SHA-256 checksum
How to use checksums
441884c0bda4bee0125fdbd7fee6a232dab58b4a64be8950eb17a8a7404a5440
BLAKE2b-256 checksum
How to use checksums
e7a6cc5f24b3f1a46a826b7e30ef56fdc1fe22315fef96de8e22afbdd5d98e7a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp314-cp314t-win32.whl

Download URL winkerberos-0.13.0-cp314-cp314t-win32.whl
Size 26.5 kB
Tags CPython 3.14 CPython 3.14 free-threading Windows x86-32
SHA-256 checksum
How to use checksums
5bc5e40a816d94d4a5abd665fe62088c1ee91ee9a1f5d787032a63004842fedf
BLAKE2b-256 checksum
How to use checksums
29bacd8186479046b7a749cee8d4d9fd50e3ce3330d8ea611efe4b8b741f0c3b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp314-cp314-win_amd64.whl

Download URL winkerberos-0.13.0-cp314-cp314-win_amd64.whl
Size 28.5 kB
Tags CPython 3.14 Windows x86-64
SHA-256 checksum
How to use checksums
5d5add54d10e31671f7c28c90ccafe98b45cec6d7519949ba30add51e34aee9a
BLAKE2b-256 checksum
How to use checksums
977c5a418e8d292e3fea1012ccf029b38fae430542fab1beaf6fc60cf138cc08
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp314-cp314-win32.whl

Download URL winkerberos-0.13.0-cp314-cp314-win32.whl
Size 26.2 kB
Tags CPython 3.14 Windows x86-32
SHA-256 checksum
How to use checksums
46cc29fa95744076a0dd2a167158574826509a5e4aa052b81a2b535aab4af14a
BLAKE2b-256 checksum
How to use checksums
80d9d12d310fdf9ace70f7469ecfd9f112dc39cb7e1f77348228c06a6bd72c57
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp313-cp313-win_amd64.whl

Download URL winkerberos-0.13.0-cp313-cp313-win_amd64.whl
Size 27.9 kB
Tags CPython 3.13 Windows x86-64
SHA-256 checksum
How to use checksums
c45e84a35a3b87b88d0e6d7b55d40712dc021f80af3cb9e81091651e6a73510d
BLAKE2b-256 checksum
How to use checksums
9c26b17649b0707e4d8cd9d0d4ceadcef06eff2fc76fcb444cb187763158ae63
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp313-cp313-win32.whl

Download URL winkerberos-0.13.0-cp313-cp313-win32.whl
Size 25.7 kB
Tags CPython 3.13 Windows x86-32
SHA-256 checksum
How to use checksums
38fefdfc77a7f82c3cc9f83c7d1b6f242e6d3ea200bfde9b640f7dfe9fdf9bda
BLAKE2b-256 checksum
How to use checksums
9283b1f52594cc2c3ce18c67a04aecb0cb4fb3f4769c268d194cc5f4863150fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp312-cp312-win_amd64.whl

Download URL winkerberos-0.13.0-cp312-cp312-win_amd64.whl
Size 27.9 kB
Tags CPython 3.12 Windows x86-64
SHA-256 checksum
How to use checksums
59f01879c62adcda5af857fd78d2b2dfdfd99cf6179b92d38e2f2bd12db75bf7
BLAKE2b-256 checksum
How to use checksums
52c2ff9074cf423d82bdfb48ac89e64f360533ba4e2079e8485be8377a8c54fe
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp312-cp312-win32.whl

Download URL winkerberos-0.13.0-cp312-cp312-win32.whl
Size 25.7 kB
Tags CPython 3.12 Windows x86-32
SHA-256 checksum
How to use checksums
3454b8bb9c11091e4775a8bd692dfbe45f2eab12f3a4837b820c2505088dfdd2
BLAKE2b-256 checksum
How to use checksums
3afa02de79d7dbec9122a6778678ed432ebffb228c48b16cfba3007c45a6e8fd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp311-cp311-win_amd64.whl

Download URL winkerberos-0.13.0-cp311-cp311-win_amd64.whl
Size 27.9 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
6bc03e66a737bfd11964e6cdc5f03a8cd0baed798f991b1467075c65980c4157
BLAKE2b-256 checksum
How to use checksums
6e5bbafa1cfb9f047be139ffae330f6eafa0487f8bf82164ead756e0bc2bc047
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp311-cp311-win32.whl

Download URL winkerberos-0.13.0-cp311-cp311-win32.whl
Size 25.6 kB
Tags CPython 3.11 Windows x86-32
SHA-256 checksum
How to use checksums
a23c83854650416545000c4630e94b16fa14c7b400bd5f08a79718e04eff9135
BLAKE2b-256 checksum
How to use checksums
ce0905c4d2fb93f5478fd1b6146c4fa3fbb80839576a34062e5677f2dec3a430
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp310-cp310-win_amd64.whl

Download URL winkerberos-0.13.0-cp310-cp310-win_amd64.whl
Size 27.9 kB
Tags CPython 3.10 Windows x86-64
SHA-256 checksum
How to use checksums
a1293325d69bfd75aefecde45ee1e52a0adfc29f2e19650eea9a87fddaa20b02
BLAKE2b-256 checksum
How to use checksums
de909b1e787831496683c494f50e05fe08a0579e51c4d3b8bbc90d7fadbf8858
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log

Release files / winkerberos-0.13.0-cp310-cp310-win32.whl

Download URL winkerberos-0.13.0-cp310-cp310-win32.whl
Size 25.6 kB
Tags CPython 3.10 Windows x86-32
SHA-256 checksum
How to use checksums
e6df7ab4c4e39e3e1d539b32ea20df84dc7ac32391391bf415c2a8051082051d
BLAKE2b-256 checksum
How to use checksums
05457199a756e3b25757cbf5986c8af040647aba24b039493eddff7950007f31
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page