This repository was archived by the owner on Jan 23, 2023. It is now read-only.
Fix SqlClient Kerberos on Linux#36513
Merged
davidsh merged 1 commit intodotnet:masterfrom Apr 1, 2019
Merged
Conversation
This PR is a follow-up to PR dotnet#36329. In that previous PR, I changed to use the GSS_C_NT_HOSTBASED_SERVICE format for the SPN. That requires using a '@' separator character instead of a "/". I had assumed since System.Data.SqlClient was including the source files from Common for SafeDeleteNegoContext.cs that it would have the corresponding change to use the proper separator character. However, it appears that the file was only included to get the project building. It was using a separate file to calculate the SPN. The customer requiring these fixes reported that Kerberos was working properly now for HttpClient and NegotiateStream. But SqlClient was still broken. This PR completes the fix so that SqlClient will work properly with Kerberos especially in multiple domain/realm environments. This fix was manually tested in the enterprise scenario test lab.
Contributor
Author
|
/azp run corefx-outerloop-windows |
Contributor
Author
|
/azp run corefx-outerloop-linux |
|
Azure Pipelines successfully started running 1 pipeline(s). |
1 similar comment
|
Azure Pipelines successfully started running 1 pipeline(s). |
stephentoub
approved these changes
Apr 1, 2019
saurabh500
approved these changes
Apr 1, 2019
picenka21
pushed a commit
to picenka21/runtime
that referenced
this pull request
Feb 18, 2022
This PR is a follow-up to PR dotnet/corefx#36329. In that previous PR, I changed to use the GSS_C_NT_HOSTBASED_SERVICE format for the SPN. That requires using a '@' separator character instead of a "/". I had assumed since System.Data.SqlClient was including the source files from Common for SafeDeleteNegoContext.cs that it would have the corresponding change to use the proper separator character. However, it appears that the file was only included to get the project building. It was using a separate file to calculate the SPN. The customer requiring these fixes reported that Kerberos was working properly now for HttpClient and NegotiateStream. But SqlClient was still broken. This PR completes the fix so that SqlClient will work properly with Kerberos especially in multiple domain/realm environments. This fix was manually tested in the enterprise scenario test lab. Commit migrated from dotnet/corefx@78c4c8b
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR is a follow-up to PR #36329. In that previous PR, I changed to use the
GSS_C_NT_HOSTBASED_SERVICE format for the SPN. That requires using a '@' separator
character instead of a "/". I had assumed since System.Data.SqlClient was including
the source files from Common for SafeDeleteNegoContext.cs that it would have the
corresponding change to use the proper separator character. However, it appears that
the file was only included to get the project building. It was using a separate file
to calculate the SPN.
The customer requiring these fixes reported that Kerberos was working properly now
for HttpClient and NegotiateStream. But SqlClient was still broken.
This PR completes the fix so that SqlClient will work properly with Kerberos especially
in multiple domain/realm environments. This fix was manually tested in the enterprise
scenario test lab.