- Info:
See github for the latest source.
About
A native Kerberos client implementation for Python on Windows. This module mimics the API of pykerberos to implement Kerberos authentication with Microsoft’s Security Support Provider Interface (SSPI). It supports Python 3.10+.
Installation
WinKerberos is in the Python Package Index (pypi). Use pip to install it:
python -m pip install winkerberos
WinKerberos requires Windows 7 / Windows Server 2008 R2 or newer.
Building and installing from source
You must have the correct version of VC++ installed for your version of Python:
Python 3.10+ - Visual Studio 2015+ (Any version)
Once you have the required compiler installed, run the following command from the root directory of the WinKerberos source:
pip install .
Building HTML documentation
First install Sphinx:
python -m pip install Sphinx
Then run the following command from the root directory of the WinKerberos source:
pip install -e . python -m sphinx -b html doc doc/_build
Examples
This is a simplified example of a complete authentication session following RFC-4752, section 3.1:
import winkerberos as kerberos
def send_response_and_receive_challenge(response):
# Your server communication code here...
pass
def authenticate_kerberos(service, user, channel_bindings=None):
# Initialize the context object with a service principal.
status, ctx = kerberos.authGSSClientInit(service)
# GSSAPI is a "client goes first" SASL mechanism. Send the
# first "response" to the server and receive its first
# challenge.
if channel_bindings is not None:
status = kerberos.authGSSClientStep(ctx, "", channel_bindings=channel_bindings)
else:
status = kerberos.authGSSClientStep(ctx, "")
response = kerberos.authGSSClientResponse(ctx)
challenge = send_response_and_receive_challenge(response)
# Keep processing challenges and sending responses until
# authGSSClientStep reports AUTH_GSS_COMPLETE.
while status == kerberos.AUTH_GSS_CONTINUE:
if channel_bindings is not None:
status = kerberos.authGSSClientStep(
ctx, challenge, channel_bindings=channel_bindings
)
else:
status = kerberos.authGSSClientStep(ctx, challenge)
response = kerberos.authGSSClientResponse(ctx) or ""
challenge = send_response_and_receive_challenge(response)
# Decrypt the server's last challenge
kerberos.authGSSClientUnwrap(ctx, challenge)
data = kerberos.authGSSClientResponse(ctx)
# Encrypt a response including the user principal to authorize.
kerberos.authGSSClientWrap(ctx, data, user)
response = kerberos.authGSSClientResponse(ctx)
# Complete authentication.
send_response_and_receive_challenge(response)
Channel bindings can be generated with help from the cryptography module. See https://tools.ietf.org/html/rfc5929#section-4.1 for the rules regarding hash algorithm choice:
from cryptography import x509
from cryptography.hazmat.backends import default_backend
from cryptography.hazmat.primitives import hashes
def channel_bindings(ssl_socket):
server_certificate = ssl_socket.getpeercert(True)
cert = x509.load_der_x509_certificate(server_certificate, default_backend())
hash_algorithm = cert.signature_hash_algorithm
if hash_algorithm.name in ("md5", "sha1"):
digest = hashes.Hash(hashes.SHA256(), default_backend())
else:
digest = hashes.Hash(hash_algorithm, default_backend())
digest.update(server_certificate)
application_data = b"tls-server-end-point:" + digest.finalize()
return kerberos.channelBindings(application_data=application_data)
Viewing API Documentation without Sphinx
Use the help function in the python interactive shell:
>>> import winkerberos
>>> help(winkerberos)
Metadata
Release files for winkerberos 0.13.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| winkerberos-0.13.0.tar.gz | 35.7 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| winkerberos-0.13.0-cp314-cp314t-win_amd64.whl | CPython 3.14 | CPython 3.14 free-threading | Windows x86-64 | Details |
| winkerberos-0.13.0-cp314-cp314t-win32.whl | CPython 3.14 | CPython 3.14 free-threading | Windows x86-32 | Details |
| winkerberos-0.13.0-cp314-cp314-win_amd64.whl | CPython 3.14 | CPython 3.14 | Windows x86-64 | Details |
| winkerberos-0.13.0-cp314-cp314-win32.whl | CPython 3.14 | CPython 3.14 | Windows x86-32 | Details |
| winkerberos-0.13.0-cp313-cp313-win_amd64.whl | CPython 3.13 | CPython 3.13 | Windows x86-64 | Details |
| winkerberos-0.13.0-cp313-cp313-win32.whl | CPython 3.13 | CPython 3.13 | Windows x86-32 | Details |
| winkerberos-0.13.0-cp312-cp312-win_amd64.whl | CPython 3.12 | CPython 3.12 | Windows x86-64 | Details |
| winkerberos-0.13.0-cp312-cp312-win32.whl | CPython 3.12 | CPython 3.12 | Windows x86-32 | Details |
| winkerberos-0.13.0-cp311-cp311-win_amd64.whl | CPython 3.11 | CPython 3.11 | Windows x86-64 | Details |
| winkerberos-0.13.0-cp311-cp311-win32.whl | CPython 3.11 | CPython 3.11 | Windows x86-32 | Details |
| winkerberos-0.13.0-cp310-cp310-win_amd64.whl | CPython 3.10 | CPython 3.10 | Windows x86-64 | Details |
| winkerberos-0.13.0-cp310-cp310-win32.whl | CPython 3.10 | CPython 3.10 | Windows x86-32 | Details |
Total release size: 359.9 kB
Release files / winkerberos-0.13.0.tar.gz
| Download URL | winkerberos-0.13.0.tar.gz |
|---|---|
| Size | 35.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f3fbb67346fe8ed697e125724b0699d5c2a15b9a5f9151d25a1be88df8dac427
|
|
BLAKE2b-256 checksum How to use checksums |
ca6c455f043bc28694a278125d1fc2ab7cbf0ce0953c97bbe1021f08fd19c7b8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp314-cp314t-win_amd64.whl
| Download URL | winkerberos-0.13.0-cp314-cp314t-win_amd64.whl |
|---|---|
| Size | 28.7 kB |
| Tags | CPython 3.14 CPython 3.14 free-threading Windows x86-64 |
|
SHA-256 checksum How to use checksums |
441884c0bda4bee0125fdbd7fee6a232dab58b4a64be8950eb17a8a7404a5440
|
|
BLAKE2b-256 checksum How to use checksums |
e7a6cc5f24b3f1a46a826b7e30ef56fdc1fe22315fef96de8e22afbdd5d98e7a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp314-cp314t-win32.whl
| Download URL | winkerberos-0.13.0-cp314-cp314t-win32.whl |
|---|---|
| Size | 26.5 kB |
| Tags | CPython 3.14 CPython 3.14 free-threading Windows x86-32 |
|
SHA-256 checksum How to use checksums |
5bc5e40a816d94d4a5abd665fe62088c1ee91ee9a1f5d787032a63004842fedf
|
|
BLAKE2b-256 checksum How to use checksums |
29bacd8186479046b7a749cee8d4d9fd50e3ce3330d8ea611efe4b8b741f0c3b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp314-cp314-win_amd64.whl
| Download URL | winkerberos-0.13.0-cp314-cp314-win_amd64.whl |
|---|---|
| Size | 28.5 kB |
| Tags | CPython 3.14 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
5d5add54d10e31671f7c28c90ccafe98b45cec6d7519949ba30add51e34aee9a
|
|
BLAKE2b-256 checksum How to use checksums |
977c5a418e8d292e3fea1012ccf029b38fae430542fab1beaf6fc60cf138cc08
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp314-cp314-win32.whl
| Download URL | winkerberos-0.13.0-cp314-cp314-win32.whl |
|---|---|
| Size | 26.2 kB |
| Tags | CPython 3.14 Windows x86-32 |
|
SHA-256 checksum How to use checksums |
46cc29fa95744076a0dd2a167158574826509a5e4aa052b81a2b535aab4af14a
|
|
BLAKE2b-256 checksum How to use checksums |
80d9d12d310fdf9ace70f7469ecfd9f112dc39cb7e1f77348228c06a6bd72c57
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp313-cp313-win_amd64.whl
| Download URL | winkerberos-0.13.0-cp313-cp313-win_amd64.whl |
|---|---|
| Size | 27.9 kB |
| Tags | CPython 3.13 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
c45e84a35a3b87b88d0e6d7b55d40712dc021f80af3cb9e81091651e6a73510d
|
|
BLAKE2b-256 checksum How to use checksums |
9c26b17649b0707e4d8cd9d0d4ceadcef06eff2fc76fcb444cb187763158ae63
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp313-cp313-win32.whl
| Download URL | winkerberos-0.13.0-cp313-cp313-win32.whl |
|---|---|
| Size | 25.7 kB |
| Tags | CPython 3.13 Windows x86-32 |
|
SHA-256 checksum How to use checksums |
38fefdfc77a7f82c3cc9f83c7d1b6f242e6d3ea200bfde9b640f7dfe9fdf9bda
|
|
BLAKE2b-256 checksum How to use checksums |
9283b1f52594cc2c3ce18c67a04aecb0cb4fb3f4769c268d194cc5f4863150fa
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp312-cp312-win_amd64.whl
| Download URL | winkerberos-0.13.0-cp312-cp312-win_amd64.whl |
|---|---|
| Size | 27.9 kB |
| Tags | CPython 3.12 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
59f01879c62adcda5af857fd78d2b2dfdfd99cf6179b92d38e2f2bd12db75bf7
|
|
BLAKE2b-256 checksum How to use checksums |
52c2ff9074cf423d82bdfb48ac89e64f360533ba4e2079e8485be8377a8c54fe
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp312-cp312-win32.whl
| Download URL | winkerberos-0.13.0-cp312-cp312-win32.whl |
|---|---|
| Size | 25.7 kB |
| Tags | CPython 3.12 Windows x86-32 |
|
SHA-256 checksum How to use checksums |
3454b8bb9c11091e4775a8bd692dfbe45f2eab12f3a4837b820c2505088dfdd2
|
|
BLAKE2b-256 checksum How to use checksums |
3afa02de79d7dbec9122a6778678ed432ebffb228c48b16cfba3007c45a6e8fd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp311-cp311-win_amd64.whl
| Download URL | winkerberos-0.13.0-cp311-cp311-win_amd64.whl |
|---|---|
| Size | 27.9 kB |
| Tags | CPython 3.11 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
6bc03e66a737bfd11964e6cdc5f03a8cd0baed798f991b1467075c65980c4157
|
|
BLAKE2b-256 checksum How to use checksums |
6e5bbafa1cfb9f047be139ffae330f6eafa0487f8bf82164ead756e0bc2bc047
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp311-cp311-win32.whl
| Download URL | winkerberos-0.13.0-cp311-cp311-win32.whl |
|---|---|
| Size | 25.6 kB |
| Tags | CPython 3.11 Windows x86-32 |
|
SHA-256 checksum How to use checksums |
a23c83854650416545000c4630e94b16fa14c7b400bd5f08a79718e04eff9135
|
|
BLAKE2b-256 checksum How to use checksums |
ce0905c4d2fb93f5478fd1b6146c4fa3fbb80839576a34062e5677f2dec3a430
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp310-cp310-win_amd64.whl
| Download URL | winkerberos-0.13.0-cp310-cp310-win_amd64.whl |
|---|---|
| Size | 27.9 kB |
| Tags | CPython 3.10 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
a1293325d69bfd75aefecde45ee1e52a0adfc29f2e19650eea9a87fddaa20b02
|
|
BLAKE2b-256 checksum How to use checksums |
de909b1e787831496683c494f50e05fe08a0579e51c4d3b8bbc90d7fadbf8858
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency logRelease files / winkerberos-0.13.0-cp310-cp310-win32.whl
| Download URL | winkerberos-0.13.0-cp310-cp310-win32.whl |
|---|---|
| Size | 25.6 kB |
| Tags | CPython 3.10 Windows x86-32 |
|
SHA-256 checksum How to use checksums |
e6df7ab4c4e39e3e1d539b32ea20df84dc7ac32391391bf415c2a8051082051d
|
|
BLAKE2b-256 checksum How to use checksums |
05457199a756e3b25757cbf5986c8af040647aba24b039493eddff7950007f31
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Dec 3, 2025.
Transparency log