Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: add BuildSpnFunc to GSSAPIConfig for allow custom spn #2807

Merged
merged 1 commit into from Feb 22, 2024
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
12 changes: 10 additions & 2 deletions gssapi_kerberos.go
Expand Up @@ -39,6 +39,7 @@ type GSSAPIConfig struct {
Password string
Realm string
DisablePAFXFAST bool
BuildSpn BuildSpnFunc
}

type GSSAPIKerberosAuth struct {
Expand All @@ -57,6 +58,8 @@ type KerberosClient interface {
Destroy()
}

type BuildSpnFunc func(serviceName, host string) string

// writePackage appends length in big endian before the payload, and sends it to kafka
func (krbAuth *GSSAPIKerberosAuth) writePackage(broker *Broker, payload []byte) (int, error) {
length := uint64(len(payload))
Expand Down Expand Up @@ -211,10 +214,15 @@ func (krbAuth *GSSAPIKerberosAuth) Authorize(broker *Broker) error {
return err
}
// Construct SPN using serviceName and host
// SPN format: <SERVICE>/<FQDN>
// default SPN format: <SERVICE>/<FQDN>

host := strings.SplitN(broker.addr, ":", 2)[0] // Strip port part
spn := fmt.Sprintf("%s/%s", broker.conf.Net.SASL.GSSAPI.ServiceName, host)
var spn string
if krbAuth.Config.BuildSpn != nil {
spn = krbAuth.Config.BuildSpn(broker.conf.Net.SASL.GSSAPI.ServiceName, host)
} else {
spn = fmt.Sprintf("%s/%s", broker.conf.Net.SASL.GSSAPI.ServiceName, host)
}

ticket, encKey, err := kerberosClient.GetServiceTicket(spn)
if err != nil {
Expand Down