Kerberos credential delegation: allowDelegation() and CLI --allow-delegate (winrs -allowdelegate)
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Stack tecnologico
- java
- Ambito
- authentication, cli, documentation, testing
Direzione di ricerca
Inizia leggendo KerberosAuthScheme e la validazione del builder del client, quindi segui l’analisi delle opzioni CLI e le pagine del manuale di Authentication e CLI. Verifica la configurazione della delega e il rifiuto dei meccanismi non Kerberos con unit test, quindi completa i prerequisiti documentati e la validazione dal vivo sull’host AD interno.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
winrs parity:
-a[llow]d[elegate]— let the remote shell use the user's credentials to reach a further hop (a share on a third machine, a database, ...). Without delegation, anything the remote command does with the user's identity over the network fails with access denied (the classic double-hop problem).
Context
winrs implements this with CredSSP or Kerberos delegation. For this client:
- Kerberos (in scope): the JDK GSS-API supports delegation natively —
GSSContext.requestCredDeleg(true)on the contextKerberosAuthSchemealready creates. The TGT must be forwardable (forwardable = trueinkrb5.conf, or a forwardable ticket in the ticket cache), and the target service must be trusted for delegation in AD (OK-AS-DELEGATE; for constrained delegation the KDC decides). All pure JDK, zero new dependencies. - CredSSP (out of scope): NTLM-based delegation requires implementing CredSSP (TLS channel + SPNEGO inside TSRequest ASN.1 structures + credential submission). That is a whole new authentication protocol and a significant security surface; explicitly not part of this issue — file separately if ever needed.
Proposed API
try (WinRMClient client = WinRMClient.builder("server.example.net")
.https()
.authentication(AuthScheme.KERBEROS)
.allowDelegation() // connection-scoped, Kerberos only
.credentials("DOMAIN\user", password)
.build()) {
client.command("dir \\fileserver\share").execute();
}
- Builder-level (delegation is a property of the authentication, not of one command).
build()rejectsallowDelegation()when Kerberos is not among the requested schemes — silently ignoring it would give a false sense of security posture.- When the KDC does not grant a forwardable/delegable ticket, GSS reports it — surface a clear message (this is the number-one support question with delegation).
CLI
winrm-java -h server -u 'DOMAIN\user' -pf pw.txt \
--https --kerberos --allow-delegate \
exec 'dir \fileserver\share'
Usage error when --allow-delegate is given without --kerberos.
Acceptance criteria
requestCredDeleg(true)set on the GSS context iff delegation was requested; unit-testable at theKerberosAuthSchemelevel.- Configuration rejections (NTLM-only + delegation) at
build()/ CLI parse time with actionable messages. - Live validation against a real AD host with
OK-AS-DELEGATE(see the internal test host) — the FakeWsmanServer speaks NTLM only, so delegation is covered by unit + live tests. - Documented on the Authentication page (including the krb5.conf
forwardableand AD trust prerequisites) and in the CLI manual.
🤖 Generated with Claude Code
- Lingua principale
- Java
- Stelle
- 13
- Fork
- 4
- Merge medio
- 2g 2h
- PR unite (30g)
- 12
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di MetricsHub/winrm-java
-
stdin fed to a command that exits without reading it fails the run with WSManFault 232Forse già presa @bertysentry l’ha presa oggi. Aperta
MetricsHub/winrm-java#183 · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 38/100
MetricsHub/winrm-java#176 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 48/100
MetricsHub/winrm-java#175 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di MetricsHub/winrm-java
Issue simili
-
P2 testing
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
I maintainer di solito rispondono entro 1 giorno
-
area/core kind/bug status/triage team/core-shared
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
checkstyle/checkstyle#21755 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
spring-projects/spring-integration#11495 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno