I am developing an application that requires to authenticate with proxy using negotiate. User may not have Kerberos client installed. I am trying to achieve this using MIT Kerberos Library in order to avoid platform dependecy. I have successfully got TKT using krb5_get_init_creds_password and verified it krb5_verify_init_creds. Now I want ot create SPNEGO token to be sent in HTTP header using this TKT. Can anyone tell me any API or method to create SPNEGO token?
How to create SPNEGO token to be sent in HTTP header from Kerberos TKT?
3.5k Views Asked by Ajit Singh At
1
There are 1 best solutions below
Related Questions in KERBEROS
- Windows client damage authorization header (Kerberos) => IIS 400 (Bad Request)
- Configure Kerberos auth for TFS 2013
- Single Sign-On in Windows Applications using AD login
- C# RestSharp library and Kerberos authentication
- Hiveserver2 Kerberos
- Passing Kerberos ticket as parameter in SOAP web service call
- Spring security kerberos validate token error
- Hadoop Kerberos security
- Authenticate scripts on HDFS using key.tab file
- Making my own Kerberos Authentication Ticket
- Using Java 8 S4U2Proxy - A good example needed
- Connect to HBase using tunnel
- Hive Server2 ACID transactions not working
- How to specify the TGT kerberos ticket cache in beeline
- Java GSSAPI Credentials with Active Directory
Related Questions in SPNEGO
- Implementing SSO in Apache, Jetty or Java Web Service
- Alternative for NegotiationAuthenticator class from JBoss EAP 6 in WildFly 10.1?
- Tomcat Kerberos Spnego authorization not working
- Running SPNEGO Kerberos in parallel with username/password authentication
- java.lang.ClassNotFoundException: org.jboss.security.negotiation.NegotiationAuthenticator
- SPNEGO with Java prompting password many times
- How does SPN with Kerberos works
- Kerberos/SPNEGO authentication through Apache to Cherrypy
- curl on Windows: "GSSException: Defective token detected (Mechanism level: GSSHeader did not find the right tag)"
- Any code examples of SpnegoContextToken with Java client?
- Java SSO using SPNEGO
- WCF Interoperability Kerberos SPNego Enabled Web Service
- authenticate user on server side for Swing clients using kerberos/spnego
- how to pass kerberos ticket to jboss server (5.1.0 AS) from swing client
- Spnego keytab authentication in Tomcat on Windows Server fails
Related Questions in PROXY-AUTHENTICATION
- Visual Studio build - "(407) Proxy Authentication Required" when build xamarin Droid project
- how to use a proxy connection with android studio
- Set system proxy && authentication in C++ on Windows
- Proxy Authentication in Python
- My WCF service is throwing Error when running through a windows service
- In java EE 6: When could I change properties on EntityManager?
- WSDL2Objc code crash behind authentication HTTP proxy - Help to understand the crash log
- Couchdb and proxy authentication
- DotNet HttpClient.DefaultProxy Property not reading system settings on Win10
- C# Selenium Proxy Authentication with Chrome Driver
- Proxy Authentication -- HTTP/HTML Details?
- How can I hide a custom origin server from the public when using AWS CloudFront?
- How do I auth a user:pass proxy in golang
- How to provide Credentials in http Proxy in Dotnetbrowser?
- Is it possible to configure proxy authentication username and password in windows?
Related Questions in NEGOTIATE
- C# HTTPWebRequest against Negotiate/Basic with Realm Site
- Problem with Apache PHP CURL and CURLAUTH_NEGOTIATE authentication against EWS Exchange Webservice
- Win SSPI Negotiate auth when running a service and client both locally
- Fate of Application messages in middle of an SSL renegotiation
- SignalR Error! signalr/negotiate gets a "403 - Forbidden: Access is denied." error
- webHDFS curl --negotiate on Windows
- IIS web app stops working if Negotiate:kerberos is selected as provider under windows auhentication
- SignalR working on Localhost, BUT not working on Server win server 2019 with IIS
- How to use Windows authentication as an alternative to password login? ASP.NET Core
- How to find if NTLM or Kerberos is used from WWW-Authenticate: Negotiate header
- configuring kerberose-sso-negotiate in multiple domains
- How do people make Java SPNEGO client work in Windows?
- Get Angular working with Waffle Spring boot + Spring Security and embedded tomcat
- How to create SPNEGO token to be sent in HTTP header from Kerberos TKT?
- singlar/negotiate no json response - no singlar/connect
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
You can use gss_init_sec_context for the purpose.
Some background:-
SPNEGO is an abstraction on top of kerberos for HTTP based communication(which does not use the security context for encryption though)
for this pupose do the following:-
Now that you have krb5_get_init_creds_password and have got the krb5 mech credential create an in memory credential cache using krb5_cc_new_unique and then initialize it.
Now use krb5_cc_store_cred to store it into that cache
Use gss_krb5_import_cred to get a GSSAPI token
Now you have all the necessary preauth info. All you need to do is to use gss_init_sec_context for create an input token.
Now here is a good part, latest MIT Kerberos libraries support SPNEGO natively. There is an OID structure called gss_OID that you need to create. For SPNEGO that is:-
and then pass this as an argument to gss_init_sec_context.
If you are using an older MIT Kerberos library then I suggest you use fbopenssl for this purpose. You can check out curl source code to check out how it is done.