Skip to content

[WIP] Feature/master/netty kerberos proxy auth - #7276

Open
dagnir wants to merge 9 commits into
masterfrom
feature/master/netty-kerberos-proxy-auth
Open

[WIP] Feature/master/netty kerberos proxy auth#7276
dagnir wants to merge 9 commits into
masterfrom
feature/master/netty-kerberos-proxy-auth

Conversation

@dagnir

@dagnir dagnir commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Motivation and Context

Modifications

Testing

Screenshots (if appropriate)

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)

Checklist

  • I have read the CONTRIBUTING document
  • Local run of mvn install succeeds
  • My code follows the code style of this project
  • My change requires a change to the Javadoc documentation
  • I have updated the Javadoc documentation accordingly
  • I have added tests to cover my changes
  • All new and existing tests passed
  • I have added a changelog entry. Adding a new entry must be accomplished by running the scripts/new-change script and following the instructions. Commit the new file created by the script in .changes/next-release with your changes.
  • My change is to implement 1.11 parity feature and I have updated LaunchChangelog

License

  • I confirm that this pull request can be released under the Apache 2 license

dagnir added 5 commits August 3, 2026 12:54
* Initial support for Kerberos auth

This commit adds
 - A new enum `ProxyAuthScheme` that enumerates the proxy auth
   mechanisms supported by Netty
 - `ProxyAuthGenerator` (internal) that knows how to generate the auth
   params for its respective auth scheme
 - `NegotiateProxyAuthGenerator` for Kerberos

* wip

* Document OID
This reverts commit b20454f.
* Add basic auth impl

* Checkstyle and dependency issues
* Switch to AuthGenerator in tunnel pool

Use the new AuthGenerator mechanism in the `Http1TunnelConnectionPool`
and `AwaitCloseChannelPoolMap` classes. For now, supports only using
BASIC auth; Kerberos will be added in a subsequent PR.

* Allow empty username, pass

Original impl allowed empty (e.g. whitespace) in username and pass for
BASIC auth so preserve that behavior.
* Support ProxyAuthScheme

This commit Adds a `ProxyAuthScheme` configuration option in
`ProxyConfiguration` and adds support for `NEGOTIATE` auth scheme.

For backwards compatibility, if username and password are set on the
config and the proxy auth scheme is *not* set, the client assumes
`BASIC` auth scheme. If `NEGOTIATE` is configured, `username` and
`password` are ignored.

* Fix test
@dagnir
dagnir requested a review from a team as a code owner August 14, 2026 16:15
dagnir added 4 commits August 14, 2026 09:16
requestMutualAuth(true) asked for mutual authentication that was never
established: the proxy's response token is never consumed, so there is
nothing to verify it against. Preemptive single-leg Negotiate cannot
verify it either, so the call is dropped rather than wired up.

The com.sun.security.auth.module.Krb5LoginModule import existed only to
satisfy a javadoc {@link}. Referring to the class by name in {@code}
instead keeps the documentation while dropping a compile-time reference
to a JDK-implementation-specific class.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant