tech.pisoft.teagent.GSSAPIAuthenticationContext
The GSSAPIAuthenticationContext class is a Kerberos login: the Key Service's channel-bound GSS-API module, GSSAPIAuthentication (ks AM10, ADR 0106), driven as ADR 0166 records it.
The Kerberos half runs in te_gss_initiator, the native initiator the Java and TypeScript agents share (pinned MIT krb5, channel-binding aware): this agent keeps its own TLS connection, reads its own RFC 9266 exporter (TEAgentConnection#getChannelBinding()), hands the helper the binding and each of the key server's tokens on stdin, and relays each token the helper answers with as one AUTH_UPDATE. Mutual authentication and integrity are requested and confirmed by the helper before it reports the context established. JGSS is not used: its Kerberos provider cannot declare channel-binding awareness, which the key server requires.
The key server's anchor is REQUIRED: the presented chain is verified against it before any token is sent, and a context naming none is refused by name. Open the login with TEAgentSSLAuthenticConnection#open(String, int, AuthenticationContext), which also verifies the key server at the handshake.
The credential is a Kerberos ticket the caller already holds: a credential cache named by setCredentialCache(String), the default cache when none is named, or the ticket-granting ticket in a JAAS Subject (setSubject(Subject)), which is written for the length of the login only to a private, owner-only cache file and removed after it. No password crosses this API.
Since: 8.1
© Pi Soft, 2018-2026 · Tricryption Engine 8.1
Inheritance
Static Public Attributes
| Type | Name | Description |
|---|---|---|
| final String | INITIATOR_SYS_PROPERTY | System property naming the te_gss_initiator executable when setInitiatorPath(String) was not called. |
| final String | INITIATOR_ENV | Environment variable naming the te_gss_initiator executable when neither the setter nor the system property names one. |
| final String | INITIATOR_NAME | The executable's name, resolved on PATH when nothing else names it. |
Public Member Functions
| Member | Description |
|---|---|
GSSAPIAuthenticationContext() | The GSSAPIAuthenticationContext constructor is the default class constructor. |
void setServicePrincipal(String principal) | The setServicePrincipal method names the key server's Kerberos service (its acceptor name, e.g. |
String getServicePrincipal() | The getServicePrincipal method returns the service principal set, or null. |
void setCredentialCache(String ccache) | The setCredentialCache method names the Kerberos credential cache the ticket is read from (FILE:/path, KCM:, ...). |
String getCredentialCache() | The getCredentialCache method returns the cache name set, or null. |
void setSubject(Subject subject) | The setSubject method takes the credential from a JAAS Subject that holds a Kerberos ticket-granting ticket (a javax.security.auth.kerberos.KerberosTicket among its private credentials, as Krb5LoginModule leaves it). |
Subject getSubject() | The getSubject method returns the Subject set, or null. |
void setServerAnchor(InputStream anchor) | The setServerAnchor method names the certificate(s) the key server's chain must verify against (PEM or DER, one or more; a certificate that is not self-signed pins it). |
void setServerAnchorFile(String path) | The setServerAnchorFile method reads the key server's anchor from a file (PEM or DER). |
boolean hasServerAnchor() | The hasServerAnchor method reports whether an anchor has been named. |
void setInitiatorPath(String path) | The setInitiatorPath method names the te_gss_initiator executable. |
void setKrb5Config(String path) | The setKrb5Config method names the Kerberos profile the initiator reads (KRB5_CONFIG in its environment). |
void setSecret(Object objSec) | The setSecret method takes another GSSAPIAuthenticationContext's settings. |
Static Public Member Functions
| Member | Description |
|---|---|
GSSAPIAuthenticationContext getInstance() | The getInstance method is a factory method that gets an instance of the GSSAPIAuthenticationContext class. |
Member Function Documentation
GSSAPIAuthenticationContext()
The GSSAPIAuthenticationContext constructor is the default class constructor.
void setServicePrincipal(String principal)
The setServicePrincipal method names the key server's Kerberos service (its acceptor name, e.g.
ks/host.example@REALM). A ticket for any other service is refused by the key server.
Parameters
| Parameter | Description |
|---|---|
principal | the service principal; required. |
String getServicePrincipal()
The getServicePrincipal method returns the service principal set, or null.
void setCredentialCache(String ccache)
The setCredentialCache method names the Kerberos credential cache the ticket is read from (FILE:/path, KCM:, ...).
Unset, and with no Subject, the initiator reads the default cache. Setting it clears a Subject set earlier.
Parameters
| Parameter | Description |
|---|---|
ccache | the cache name; null for the default. |
String getCredentialCache()
The getCredentialCache method returns the cache name set, or null.
void setSubject(Subject subject)
The setSubject method takes the credential from a JAAS Subject that holds a Kerberos ticket-granting ticket (a javax.security.auth.kerberos.KerberosTicket among its private credentials, as Krb5LoginModule leaves it).
Setting it clears a credential cache set earlier.
Parameters
| Parameter | Description |
|---|---|
subject | the Subject; null to clear. |
Subject getSubject()
The getSubject method returns the Subject set, or null.
void setServerAnchor(InputStream anchor)
The setServerAnchor method names the certificate(s) the key server's chain must verify against (PEM or DER, one or more; a certificate that is not self-signed pins it).
Required.
Parameters
| Parameter | Description |
|---|---|
anchor | a stream holding the anchor certificate(s). |
Exceptions
| Exception | Description |
|---|---|
TEAgentException | naming why the stream holds no usable certificate. |
void setServerAnchorFile(String path)
The setServerAnchorFile method reads the key server's anchor from a file (PEM or DER).
Parameters
| Parameter | Description |
|---|---|
path | the anchor file. |
Exceptions
| Exception | Description |
|---|---|
TEAgentException | when the file cannot be read or holds no certificate. |
boolean hasServerAnchor()
The hasServerAnchor method reports whether an anchor has been named.
void setInitiatorPath(String path)
The setInitiatorPath method names the te_gss_initiator executable.
Unset, the system property INITIATOR_SYS_PROPERTY, then the environment variable INITIATOR_ENV, then INITIATOR_NAME on PATH.
Parameters
| Parameter | Description |
|---|---|
path | the executable. |
void setKrb5Config(String path)
The setKrb5Config method names the Kerberos profile the initiator reads (KRB5_CONFIG in its environment).
It must declare client_aware_channel_bindings = true, or the key server refuses the exchange as unbound. Unset, the initiator inherits this process's environment.
Parameters
| Parameter | Description |
|---|---|
path | the krb5.conf file. |
void setSecret(Object objSec)
The setSecret method takes another GSSAPIAuthenticationContext's settings.
A Kerberos login carries no secret of its own. Deprecateduse the named setters.
Parameters
| Parameter | Description |
|---|---|
objSec | a GSSAPIAuthenticationContext. |
Exceptions
| Exception | Description |
|---|---|
TEAgentException | WRONG_SECRET for anything else. |
GSSAPIAuthenticationContext getInstance()
The getInstance method is a factory method that gets an instance of the GSSAPIAuthenticationContext class.
Returns: Returns a new GSSAPIAuthenticationContext object.