Skip to content

Initial support for Kerberos auth - #7211

Open
dagnir wants to merge 1 commit into
feature/master/netty-kerberos-proxy-authfrom
dongie/netty-kerberos-proxy-auth
Open

Initial support for Kerberos auth#7211
dagnir wants to merge 1 commit into
feature/master/netty-kerberos-proxy-authfrom
dongie/netty-kerberos-proxy-auth

Conversation

@dagnir

@dagnir dagnir commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Motivation and Context

Initial part for implementation #7033.

Modifications

This commit adds

  • A new enum ProxyAuthScheme that enumerates the proxy auth mechanisms supported by Netty
  • ProxyAuthGenerator (internal) that knows how to generate the auth params for its respective auth scheme
  • NegotiateProxyAuthGenerator for Kerberos

Testing

Screenshots (if appropriate)

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)

Checklist

  • I have read the CONTRIBUTING document
  • Local run of mvn install succeeds
  • My code follows the code style of this project
  • My change requires a change to the Javadoc documentation
  • I have updated the Javadoc documentation accordingly
  • I have added tests to cover my changes
  • All new and existing tests passed
  • I have added a changelog entry. Adding a new entry must be accomplished by running the scripts/new-change script and following the instructions. Commit the new file created by the script in .changes/next-release with your changes.
  • My change is to implement 1.11 parity feature and I have updated LaunchChangelog

License

  • I confirm that this pull request can be released under the Apache 2 license

This commit adds
 - A new enum `ProxyAuthScheme` that enumerates the proxy auth
   mechanisms supported by Netty
 - `ProxyAuthGenerator` (internal) that knows how to generate the auth
   params for its respective auth scheme
 - `NegotiateProxyAuthGenerator` for Kerberos
@dagnir
dagnir requested a review from a team as a code owner July 31, 2026 21:56
@dagnir
dagnir requested a review from joviegas July 31, 2026 22:00
*/
@SdkInternalApi
public class NegotiateProxyAuthGenerator implements ProxyAuthGenerator {
private static final String OID = "1.3.6.1.5.5.2";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit : was wondering if need to mention a little bit more detail on the OID ,something like

// SPNEGO pseudo-mechanism OID. Lets the proxy negotiate Kerberos over HTTP "Negotiate".
private static final String SPNEGO_MECHANISM_OID = "1.3.6.1.5.5.2";

* Supported auth schemes for authentication with a proxy.
*/
@SdkPublicApi
public enum ProxyAuthScheme {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit : just for my understanding .
Is there any cases this can be used by other Http clients like crt-http , if yes then should we consider moving this interfaces to a common package shared by the sdk http clients ?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I thought about moving this to SPI package but it doesn't seem like a good fit since we don't have a common proxy config interface.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants