Jonathan Turner 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
..
asn1tools 3196640dcd Version 8 %!s(int64=6) %!d(string=hai) anos
client 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
config f1c93a8558 add client diagnostics method %!s(int64=6) %!d(string=hai) anos
credentials 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
crypto 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
examples 4ba5599782 fix logging so as not to lose the source line ref %!s(int64=6) %!d(string=hai) anos
gssapi 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
iana 3196640dcd Version 8 %!s(int64=6) %!d(string=hai) anos
kadmin 3196640dcd Version 8 %!s(int64=6) %!d(string=hai) anos
keytab 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
krberror 3196640dcd Version 8 %!s(int64=6) %!d(string=hai) anos
messages 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
pac 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
service 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
spnego 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
test 3196640dcd Version 8 %!s(int64=6) %!d(string=hai) anos
types 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
README.md 1a5195b523 fix comments %!s(int64=6) %!d(string=hai) anos
USAGE.md f1c93a8558 add client diagnostics method %!s(int64=6) %!d(string=hai) anos
go.mod 9a6cc2d3ff Tidy dependencies %!s(int64=6) %!d(string=hai) anos
go.sum 9a6cc2d3ff Tidy dependencies %!s(int64=6) %!d(string=hai) anos
gokrb5.go 56d95dcbd4 godoc fix %!s(int64=6) %!d(string=hai) anos

README.md

gokrb5

It is recommended to use the latest version: Version

Development will be focused on the latest major version. New features will only be targeted at this version.

Versions Dependency Management Import Path Usage Godoc Go Report Card
v8 Go modules import "github.com/jcmturner/gokrb5/v8/{sub-package}" Usage GoDoc Go Report Card
v7 gopkg.in import "gopkg.in/jcmturner/gokrb5.v7/{sub-package}" Usage GoDoc Go Report Card

Go Version Support

Go version Go version Go version

gokrb5 may work with other versions of Go but they are not tested.

Features

  • Pure Go - no dependency on external libraries
  • No platform specific code
  • Server Side
    • HTTP handler wrapper implements SPNEGO Kerberos authentication
    • HTTP handler wrapper decodes Microsoft AD PAC authorization data
  • Client Side
    • Client that can authenticate to an SPNEGO Kerberos authenticated web service
    • Ability to change client's password
  • General
    • Kerberos libraries for custom integration
    • Parsing Keytab files
    • Parsing krb5.conf files
    • Parsing client credentials cache files such as /tmp/krb5cc_$(id -u $(whoami))

Implemented Encryption & Checksum Types

Implementation Encryption ID Checksum ID RFC
des3-cbc-sha1-kd 16 12 3961
aes128-cts-hmac-sha1-96 17 15 3962
aes256-cts-hmac-sha1-96 18 16 3962
aes128-cts-hmac-sha256-128 19 19 8009
aes256-cts-hmac-sha384-192 20 20 8009
rc4-hmac 23 -138 4757

The following is working/tested:

  • Tested against MIT KDC (1.6.3 is the oldest version tested against) and Microsoft Active Directory (Windows 2008 R2)
  • Tested against a KDC that supports PA-FX-FAST.
  • Tested against users that have pre-authentication required using PA-ENC-TIMESTAMP.
  • Microsoft PAC Authorization Data is processed and exposed in the HTTP request context. Available if Microsoft Active Directory is used as the KDC.

Contributing

If you are interested in contributing to gokrb5, great! Please read the contribution guidelines.


References

Useful Links

Thanks

  • Greg Hudson from the MIT Consortium for Kerberos and Internet Trust for providing useful advice.

Contributing

Thank you for your interest in contributing to gokrb5 please read the contribution guide as it should help you get started.

Known Issues

Issue Worked around? References
The Go standard library's encoding/asn1 package cannot unmarshal into slice of asn1.RawValue Yes https://github.com/golang/go/issues/17321
The Go standard library's encoding/asn1 package cannot marshal into a GeneralString Yes - using https://github.com/jcmturner/gofork/tree/master/encoding/asn1 https://github.com/golang/go/issues/18832
The Go standard library's encoding/asn1 package cannot marshal into slice of strings and pass stringtype parameter tags to members Yes - using https://github.com/jcmturner/gofork/tree/master/encoding/asn1 https://github.com/golang/go/issues/18834
The Go standard library's encoding/asn1 package cannot marshal with application tags Yes
The Go standard library's x/crypto/pbkdf2.Key function uses the int type for iteraction count limiting meaning the 4294967296 count specified in https://tools.ietf.org/html/rfc3962 section 4 cannot be met on 32bit systems Yes - using https://github.com/jcmturner/gofork/tree/master/x/crypto/pbkdf2 https://go-review.googlesource.com/c/crypto/+/85535