Skip to main content

tech.pisoft.teagent.GSSAPIAuthenticationContext

The GSSAPIAuthenticationContext class is a Kerberos login: the Key Service's channel-bound GSS-API module, GSSAPIAuthentication (ks AM10, ADR 0106), driven as ADR 0166 records it.

The Kerberos half runs in te_gss_initiator, the native initiator the Java and TypeScript agents share (pinned MIT krb5, channel-binding aware): this agent keeps its own TLS connection, reads its own RFC 9266 exporter (TEAgentConnection#getChannelBinding()), hands the helper the binding and each of the key server's tokens on stdin, and relays each token the helper answers with as one AUTH_UPDATE. Mutual authentication and integrity are requested and confirmed by the helper before it reports the context established. JGSS is not used: its Kerberos provider cannot declare channel-binding awareness, which the key server requires.

The key server's anchor is REQUIRED: the presented chain is verified against it before any token is sent, and a context naming none is refused by name. Open the login with TEAgentSSLAuthenticConnection#open(String, int, AuthenticationContext), which also verifies the key server at the handshake.

The credential is a Kerberos ticket the caller already holds: a credential cache named by setCredentialCache(String), the default cache when none is named, or the ticket-granting ticket in a JAAS Subject (setSubject(Subject)), which is written for the length of the login only to a private, owner-only cache file and removed after it. No password crosses this API.

Since: 8.1

© Pi Soft, 2018-2026 · Tricryption Engine 8.1

Inheritance​

Static Public Attributes​

TypeNameDescription
final StringINITIATOR_SYS_PROPERTYSystem property naming the te_gss_initiator executable when setInitiatorPath(String) was not called.
final StringINITIATOR_ENVEnvironment variable naming the te_gss_initiator executable when neither the setter nor the system property names one.
final StringINITIATOR_NAMEThe executable's name, resolved on PATH when nothing else names it.

Public Member Functions​

MemberDescription
GSSAPIAuthenticationContext()The GSSAPIAuthenticationContext constructor is the default class constructor.
void setServicePrincipal(String principal)The setServicePrincipal method names the key server's Kerberos service (its acceptor name, e.g.
String getServicePrincipal()The getServicePrincipal method returns the service principal set, or null.
void setCredentialCache(String ccache)The setCredentialCache method names the Kerberos credential cache the ticket is read from (FILE:/path, KCM:, ...).
String getCredentialCache()The getCredentialCache method returns the cache name set, or null.
void setSubject(Subject subject)The setSubject method takes the credential from a JAAS Subject that holds a Kerberos ticket-granting ticket (a javax.security.auth.kerberos.KerberosTicket among its private credentials, as Krb5LoginModule leaves it).
Subject getSubject()The getSubject method returns the Subject set, or null.
void setServerAnchor(InputStream anchor)The setServerAnchor method names the certificate(s) the key server's chain must verify against (PEM or DER, one or more; a certificate that is not self-signed pins it).
void setServerAnchorFile(String path)The setServerAnchorFile method reads the key server's anchor from a file (PEM or DER).
boolean hasServerAnchor()The hasServerAnchor method reports whether an anchor has been named.
void setInitiatorPath(String path)The setInitiatorPath method names the te_gss_initiator executable.
void setKrb5Config(String path)The setKrb5Config method names the Kerberos profile the initiator reads (KRB5_CONFIG in its environment).
void setSecret(Object objSec)The setSecret method takes another GSSAPIAuthenticationContext's settings.

Static Public Member Functions​

MemberDescription
GSSAPIAuthenticationContext getInstance()The getInstance method is a factory method that gets an instance of the GSSAPIAuthenticationContext class.

Member Function Documentation​

GSSAPIAuthenticationContext()​

The GSSAPIAuthenticationContext constructor is the default class constructor.

void setServicePrincipal(String principal)​

The setServicePrincipal method names the key server's Kerberos service (its acceptor name, e.g.

ks/host.example@REALM). A ticket for any other service is refused by the key server.

Parameters

ParameterDescription
principalthe service principal; required.

String getServicePrincipal()​

The getServicePrincipal method returns the service principal set, or null.

void setCredentialCache(String ccache)​

The setCredentialCache method names the Kerberos credential cache the ticket is read from (FILE:/path, KCM:, ...).

Unset, and with no Subject, the initiator reads the default cache. Setting it clears a Subject set earlier.

Parameters

ParameterDescription
ccachethe cache name; null for the default.

String getCredentialCache()​

The getCredentialCache method returns the cache name set, or null.

void setSubject(Subject subject)​

The setSubject method takes the credential from a JAAS Subject that holds a Kerberos ticket-granting ticket (a javax.security.auth.kerberos.KerberosTicket among its private credentials, as Krb5LoginModule leaves it).

Setting it clears a credential cache set earlier.

Parameters

ParameterDescription
subjectthe Subject; null to clear.

Subject getSubject()​

The getSubject method returns the Subject set, or null.

void setServerAnchor(InputStream anchor)​

The setServerAnchor method names the certificate(s) the key server's chain must verify against (PEM or DER, one or more; a certificate that is not self-signed pins it).

Required.

Parameters

ParameterDescription
anchora stream holding the anchor certificate(s).

Exceptions

ExceptionDescription
TEAgentExceptionnaming why the stream holds no usable certificate.

void setServerAnchorFile(String path)​

The setServerAnchorFile method reads the key server's anchor from a file (PEM or DER).

Parameters

ParameterDescription
paththe anchor file.

Exceptions

ExceptionDescription
TEAgentExceptionwhen the file cannot be read or holds no certificate.

boolean hasServerAnchor()​

The hasServerAnchor method reports whether an anchor has been named.

void setInitiatorPath(String path)​

The setInitiatorPath method names the te_gss_initiator executable.

Unset, the system property INITIATOR_SYS_PROPERTY, then the environment variable INITIATOR_ENV, then INITIATOR_NAME on PATH.

Parameters

ParameterDescription
paththe executable.

void setKrb5Config(String path)​

The setKrb5Config method names the Kerberos profile the initiator reads (KRB5_CONFIG in its environment).

It must declare client_aware_channel_bindings = true, or the key server refuses the exchange as unbound. Unset, the initiator inherits this process's environment.

Parameters

ParameterDescription
paththe krb5.conf file.

void setSecret(Object objSec)​

The setSecret method takes another GSSAPIAuthenticationContext's settings.

A Kerberos login carries no secret of its own. Deprecateduse the named setters.

Parameters

ParameterDescription
objSeca GSSAPIAuthenticationContext.

Exceptions

ExceptionDescription
TEAgentExceptionWRONG_SECRET for anything else.

GSSAPIAuthenticationContext getInstance()​

The getInstance method is a factory method that gets an instance of the GSSAPIAuthenticationContext class.

Returns: Returns a new GSSAPIAuthenticationContext object.