Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Info:

See github for the latest source.

Author:

Bernie Hackett <bernie@mongodb.com>

About

A native Kerberos client implementation for Python on Windows. This module mimics the API of pykerberos to implement Kerberos authentication with Microsoft’s Security Support Provider Interface (SSPI). It supports Python 3.8+.

Installation

WinKerberos is in the Python Package Index (pypi). Use pip to install it:

python -m pip install winkerberos

WinKerberos requires Windows 7 / Windows Server 2008 R2 or newer.

Building and installing from source

You must have the correct version of VC++ installed for your version of Python:

  • Python 3.8+ - Visual Studio 2015+ (Any version)

Once you have the required compiler installed, run the following command from the root directory of the WinKerberos source:

pip install .

Building HTML documentation

First install Sphinx:

python -m pip install Sphinx

Then run the following command from the root directory of the WinKerberos source:

pip install -e .
python -m sphinx -b html doc doc/_build

Examples

This is a simplified example of a complete authentication session following RFC-4752, section 3.1:

import winkerberos as kerberos


def send_response_and_receive_challenge(response):
    # Your server communication code here...
    pass


def authenticate_kerberos(service, user, channel_bindings=None):
    # Initialize the context object with a service principal.
    status, ctx = kerberos.authGSSClientInit(service)

    # GSSAPI is a "client goes first" SASL mechanism. Send the
    # first "response" to the server and receive its first
    # challenge.
    if channel_bindings is not None:
        status = kerberos.authGSSClientStep(ctx, "", channel_bindings=channel_bindings)
    else:
        status = kerberos.authGSSClientStep(ctx, "")
    response = kerberos.authGSSClientResponse(ctx)
    challenge = send_response_and_receive_challenge(response)

    # Keep processing challenges and sending responses until
    # authGSSClientStep reports AUTH_GSS_COMPLETE.
    while status == kerberos.AUTH_GSS_CONTINUE:
        if channel_bindings is not None:
            status = kerberos.authGSSClientStep(
                ctx, challenge, channel_bindings=channel_bindings
            )
        else:
            status = kerberos.authGSSClientStep(ctx, challenge)

        response = kerberos.authGSSClientResponse(ctx) or ""
        challenge = send_response_and_receive_challenge(response)

    # Decrypt the server's last challenge
    kerberos.authGSSClientUnwrap(ctx, challenge)
    data = kerberos.authGSSClientResponse(ctx)
    # Encrypt a response including the user principal to authorize.
    kerberos.authGSSClientWrap(ctx, data, user)
    response = kerberos.authGSSClientResponse(ctx)

    # Complete authentication.
    send_response_and_receive_challenge(response)

Channel bindings can be generated with help from the cryptography module. See https://tools.ietf.org/html/rfc5929#section-4.1 for the rules regarding hash algorithm choice:

from cryptography import x509
from cryptography.hazmat.backends import default_backend
from cryptography.hazmat.primitives import hashes


def channel_bindings(ssl_socket):
    server_certificate = ssl_socket.getpeercert(True)
    cert = x509.load_der_x509_certificate(server_certificate, default_backend())
    hash_algorithm = cert.signature_hash_algorithm
    if hash_algorithm.name in ("md5", "sha1"):
        digest = hashes.Hash(hashes.SHA256(), default_backend())
    else:
        digest = hashes.Hash(hash_algorithm, default_backend())
    digest.update(server_certificate)
    application_data = b"tls-server-end-point:" + digest.finalize()
    return kerberos.channelBindings(application_data=application_data)

Viewing API Documentation without Sphinx

Use the help function in the python interactive shell:

>>> import winkerberos
>>> help(winkerberos)

Metadata

Release files for winkerberos 0.11.0rc1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for winkerberos 0.11.0rc1
File Size Uploaded
winkerberos-0.11.0rc1.tar.gz 35.6 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for winkerberos 0.11.0rc1
File
winkerberos-0.11.0rc1-cp312-cp312-win_amd64.whl CPython 3.12 CPython 3.12 Windows x86-64 Details
winkerberos-0.11.0rc1-cp312-cp312-win32.whl CPython 3.12 CPython 3.12 Windows x86-32 Details
winkerberos-0.11.0rc1-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
winkerberos-0.11.0rc1-cp311-cp311-win32.whl CPython 3.11 CPython 3.11 Windows x86-32 Details
winkerberos-0.11.0rc1-cp310-cp310-win_amd64.whl CPython 3.10 CPython 3.10 Windows x86-64 Details
winkerberos-0.11.0rc1-cp310-cp310-win32.whl CPython 3.10 CPython 3.10 Windows x86-32 Details
winkerberos-0.11.0rc1-cp39-cp39-win_amd64.whl CPython 3.9 CPython 3.9 Windows x86-64 Details
winkerberos-0.11.0rc1-cp39-cp39-win32.whl CPython 3.9 CPython 3.9 Windows x86-32 Details
winkerberos-0.11.0rc1-cp38-cp38-win_amd64.whl CPython 3.8 CPython 3.8 Windows x86-64 Details
winkerberos-0.11.0rc1-cp38-cp38-win32.whl CPython 3.8 CPython 3.8 Windows x86-32 Details

Total release size: 300.6 kB

Release files / winkerberos-0.11.0rc1.tar.gz

Download URL winkerberos-0.11.0rc1.tar.gz
Size 35.6 kB
Tags Source
SHA-256 checksum
How to use checksums
08ef149b73af012a897ea365754d2cb4db38b820f3deebf8d47d1126de6474e1
BLAKE2b-256 checksum
How to use checksums
e2dce41c3e38e9ab6d4f67251f37c84f0b7faf1031dffe31467bf6bd289019a9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4

Release files / winkerberos-0.11.0rc1-cp312-cp312-win_amd64.whl

Download URL winkerberos-0.11.0rc1-cp312-cp312-win_amd64.whl
Size 27.7 kB
Tags CPython 3.12 Windows x86-64
SHA-256 checksum
How to use checksums
0e537dac96b986955767f49814c5bf020549738eea03852add5de6483250d5fc
BLAKE2b-256 checksum
How to use checksums
5da59b190f24e0abfe33c8ecf7211a56127612ac2021ad5dfbbc8ecf60e8158a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4

Release files / winkerberos-0.11.0rc1-cp312-cp312-win32.whl

Download URL winkerberos-0.11.0rc1-cp312-cp312-win32.whl
Size 25.4 kB
Tags CPython 3.12 Windows x86-32
SHA-256 checksum
How to use checksums
3347c46aa3e4d510fa43cf6e43f1e60165266d0826565db53737c57409b649ff
BLAKE2b-256 checksum
How to use checksums
b8e5d09e1cabd7d0fd4aef88cbb23e5eefb41743f1cbcde550c40f370dca8cc0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4

Release files / winkerberos-0.11.0rc1-cp311-cp311-win_amd64.whl

Download URL winkerberos-0.11.0rc1-cp311-cp311-win_amd64.whl
Size 27.7 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
04e8af6d7b3d9ef2cc32182b50a7c6a9801b43f80b0086577cd18d5e80b86df3
BLAKE2b-256 checksum
How to use checksums
ed78f59e984abdd2dfb3cbc69a946ec57b299cad8e1af9e895e24520644d1900
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4

Release files / winkerberos-0.11.0rc1-cp311-cp311-win32.whl

Download URL winkerberos-0.11.0rc1-cp311-cp311-win32.whl
Size 25.3 kB
Tags CPython 3.11 Windows x86-32
SHA-256 checksum
How to use checksums
718530e79a6efcbd4531e923f7b2beccd065ee4912e8e49f7b48dcef7456ee22
BLAKE2b-256 checksum
How to use checksums
2f54363a11b21ba92c631395ec096705c5a26401793cd756d3e2ae9505abfdda
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4

Release files / winkerberos-0.11.0rc1-cp310-cp310-win_amd64.whl

Download URL winkerberos-0.11.0rc1-cp310-cp310-win_amd64.whl
Size 27.7 kB
Tags CPython 3.10 Windows x86-64
SHA-256 checksum
How to use checksums
d64d717506f2bf17263a9c52991bf231aa3e0717bde2c63729f9c87885b878c4
BLAKE2b-256 checksum
How to use checksums
99f0526059f3562fa2519b4d64032dd4b972cbe748a9aae3f828fe13667b66fd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4

Release files / winkerberos-0.11.0rc1-cp310-cp310-win32.whl

Download URL winkerberos-0.11.0rc1-cp310-cp310-win32.whl
Size 25.3 kB
Tags CPython 3.10 Windows x86-32
SHA-256 checksum
How to use checksums
37557bd7b96983e3cd8e7aa0946a1cf4ca6a484b3ba4ba2fa1e329abdff5d7cf
BLAKE2b-256 checksum
How to use checksums
9f98b81b886153d0ff5a854cdc4e9136f5db67621cae831a15caefacf14c72d3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4

Release files / winkerberos-0.11.0rc1-cp39-cp39-win_amd64.whl

Download URL winkerberos-0.11.0rc1-cp39-cp39-win_amd64.whl
Size 27.7 kB
Tags CPython 3.9 Windows x86-64
SHA-256 checksum
How to use checksums
59abe0fb66573ff5ee92e69c495490ea7e54df25f8015d7d54b164319f67a0e1
BLAKE2b-256 checksum
How to use checksums
5014e44ebfaa03fb0e5b56a43b4e98623bd15128fbc6463a838225b925e89f9a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4

Release files / winkerberos-0.11.0rc1-cp39-cp39-win32.whl

Download URL winkerberos-0.11.0rc1-cp39-cp39-win32.whl
Size 25.3 kB
Tags CPython 3.9 Windows x86-32
SHA-256 checksum
How to use checksums
769a414b5a86f7a3548dd9364bc637f26355f321f88b07398fedf22b0c27e03b
BLAKE2b-256 checksum
How to use checksums
0e1d6bc9556118b3ca8476249214d393abc4674bd0be8a06324da1b518d78d60
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4

Release files / winkerberos-0.11.0rc1-cp38-cp38-win_amd64.whl

Download URL winkerberos-0.11.0rc1-cp38-cp38-win_amd64.whl
Size 27.7 kB
Tags CPython 3.8 Windows x86-64
SHA-256 checksum
How to use checksums
9db3c1d84f0d24a0a801adfbf4c16f9d88edb3fa287013c7b472e43b3d3e0f77
BLAKE2b-256 checksum
How to use checksums
d6f5d9c7e06201cae208e8df22923f6d1a209e4f4c38edc53e71a1d9d1c255a6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4

Release files / winkerberos-0.11.0rc1-cp38-cp38-win32.whl

Download URL winkerberos-0.11.0rc1-cp38-cp38-win32.whl
Size 25.3 kB
Tags CPython 3.8 Windows x86-32
SHA-256 checksum
How to use checksums
5da97fc0d256f7dca801e40a63da836525521de8876e83f407f2908a7d89ae7f
BLAKE2b-256 checksum
How to use checksums
20657126b6d98a68919b113c90bec6e3cf142c5d3c237148896d7a5a2990427c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.1.0 CPython/3.12.4
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page