Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Kerberos credential delegation: allowDelegation() and CLI --allow-delegate (winrs -allowdelegate)

Chiusa
#141 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@bertysentry ci sta già lavorando.

Dal 26/9/2026.

  • #182 di @bertysentry — aperta

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
48/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
java

Direzione di ricerca

Inizia leggendo KerberosAuthScheme e la validazione del builder del client, quindi segui l’analisi delle opzioni CLI e le pagine del manuale di Authentication e CLI. Verifica la configurazione della delega e il rifiuto dei meccanismi non Kerberos con unit test, quindi completa i prerequisiti documentati e la validazione dal vivo sull’host AD interno.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

winrs parity: -a[llow]d[elegate] — let the remote shell use the user's credentials to reach a further hop (a share on a third machine, a database, ...). Without delegation, anything the remote command does with the user's identity over the network fails with access denied (the classic double-hop problem).

Context

winrs implements this with CredSSP or Kerberos delegation. For this client:

  • Kerberos (in scope): the JDK GSS-API supports delegation natively — GSSContext.requestCredDeleg(true) on the context KerberosAuthScheme already creates. The TGT must be forwardable (forwardable = true in krb5.conf, or a forwardable ticket in the ticket cache), and the target service must be trusted for delegation in AD (OK-AS-DELEGATE; for constrained delegation the KDC decides). All pure JDK, zero new dependencies.
  • CredSSP (out of scope): NTLM-based delegation requires implementing CredSSP (TLS channel + SPNEGO inside TSRequest ASN.1 structures + credential submission). That is a whole new authentication protocol and a significant security surface; explicitly not part of this issue — file separately if ever needed.

Proposed API

try (WinRMClient client = WinRMClient.builder("server.example.net")
        .https()
        .authentication(AuthScheme.KERBEROS)
        .allowDelegation()                       // connection-scoped, Kerberos only
        .credentials("DOMAIN\user", password)
        .build()) {
    client.command("dir \\fileserver\share").execute();
}
  • Builder-level (delegation is a property of the authentication, not of one command).
  • build() rejects allowDelegation() when Kerberos is not among the requested schemes — silently ignoring it would give a false sense of security posture.
  • When the KDC does not grant a forwardable/delegable ticket, GSS reports it — surface a clear message (this is the number-one support question with delegation).

CLI

winrm-java -h server -u 'DOMAIN\user' -pf pw.txt \
  --https --kerberos --allow-delegate \
  exec 'dir \fileserver\share'

Usage error when --allow-delegate is given without --kerberos.

Acceptance criteria

  • requestCredDeleg(true) set on the GSS context iff delegation was requested; unit-testable at the KerberosAuthScheme level.
  • Configuration rejections (NTLM-only + delegation) at build() / CLI parse time with actionable messages.
  • Live validation against a real AD host with OK-AS-DELEGATE (see the internal test host) — the FakeWsmanServer speaks NTLM only, so delegation is covered by unit + live tests.
  • Documented on the Authentication page (including the krb5.conf forwardable and AD trust prerequisites) and in the CLI manual.

🤖 Generated with Claude Code

Lingua principale
Java
Stelle
13
Fork
4
Merge medio
2g 2h
PR unite (30g)
12

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di MetricsHub/winrm-java

Tutte le issue di MetricsHub/winrm-java

Issue simili

Altre issue su Java

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.