Skip to content

KerberosAuthentication default MUTUAL_REQUIRED always fails against Trino (no mutual token on success) #643

Description

@aminghadersohi

trino.auth.KerberosAuthentication defaults to mutual_authentication=MUTUAL_REQUIRED. When a Trino coordinator accepts a SPNEGO request, its 200 response has no WWW-Authenticate header, so it carries no mutual-authentication token. With the default, requests-kerberos rejects every successful response:

requests_kerberos.exceptions.MutualAuthenticationError: Unable to authenticate <Response [200]>
trino.exceptions.TrinoConnectionError: failed to execute: Unable to authenticate <Response [200]>

Reproduced with trino 0.339.0, requests-kerberos 0.15.0 and pyspnego 0.12.2 against Trino 483. The coordinator was configured with http-server.authentication.type=KERBEROS over HTTPS, and the client had a valid TGT:

import trino
from trino.auth import KerberosAuthentication

conn = trino.dbapi.connect(
    host="trino.example", port=8443, user="alice", http_scheme="https",
    auth=KerberosAuthentication(service_name="HTTP"),
)
conn.cursor().execute("SELECT 1")   # MutualAuthenticationError on the 200 response

The same connection works with mutual_authentication=KerberosAuthentication.MUTUAL_OPTIONAL. With that setting, a mutual token is still verified whenever the server sends one. The HTTPS connection authenticates the server either way.

Suggestion: default to MUTUAL_OPTIONAL, or at least document that Trino does not return a mutual-authentication token, so the current default cannot succeed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions