trino.auth.KerberosAuthentication defaults to mutual_authentication=MUTUAL_REQUIRED. When a Trino coordinator accepts a SPNEGO request, its 200 response has no WWW-Authenticate header, so it carries no mutual-authentication token. With the default, requests-kerberos rejects every successful response:
requests_kerberos.exceptions.MutualAuthenticationError: Unable to authenticate <Response [200]>
trino.exceptions.TrinoConnectionError: failed to execute: Unable to authenticate <Response [200]>
Reproduced with trino 0.339.0, requests-kerberos 0.15.0 and pyspnego 0.12.2 against Trino 483. The coordinator was configured with http-server.authentication.type=KERBEROS over HTTPS, and the client had a valid TGT:
import trino
from trino.auth import KerberosAuthentication
conn = trino.dbapi.connect(
host="trino.example", port=8443, user="alice", http_scheme="https",
auth=KerberosAuthentication(service_name="HTTP"),
)
conn.cursor().execute("SELECT 1") # MutualAuthenticationError on the 200 response
The same connection works with mutual_authentication=KerberosAuthentication.MUTUAL_OPTIONAL. With that setting, a mutual token is still verified whenever the server sends one. The HTTPS connection authenticates the server either way.
Suggestion: default to MUTUAL_OPTIONAL, or at least document that Trino does not return a mutual-authentication token, so the current default cannot succeed.
trino.auth.KerberosAuthenticationdefaults tomutual_authentication=MUTUAL_REQUIRED. When a Trino coordinator accepts a SPNEGO request, its200response has noWWW-Authenticateheader, so it carries no mutual-authentication token. With the default, requests-kerberos rejects every successful response:Reproduced with trino 0.339.0, requests-kerberos 0.15.0 and pyspnego 0.12.2 against Trino 483. The coordinator was configured with
http-server.authentication.type=KERBEROSover HTTPS, and the client had a valid TGT:The same connection works with
mutual_authentication=KerberosAuthentication.MUTUAL_OPTIONAL. With that setting, a mutual token is still verified whenever the server sends one. The HTTPS connection authenticates the server either way.Suggestion: default to
MUTUAL_OPTIONAL, or at least document that Trino does not return a mutual-authentication token, so the current default cannot succeed.