RHEL9上Tomcat应用JDBC Kerberos认证连接MSSQL失败求助
基于JDK8的Tomcat应用通过JDBC Kerberos认证连接MSSQL失败
应用启动时持续报错:
ERROR - failed to connect to DB, reason is probably not the database absence. cause: Cannot login with Kerberos principal not_used, check your credentials. Kerberos Login failed: Integrated authentication failed. ClientConnectionId
已做配置
JVM参数(setenv.sh)
export CATALINA_OPTS="$CATALINA_OPTS -Djava.security.auth.login.config=/opt/tomcat/bin/jaas.conf -Djava.security.krb5.conf=/etc/krb5.conf -Djava.security.debug=all"
JAAS配置(jaas.conf)
SqlJaasConf { com.sun.security.auth.module.Krb5LoginModule required useKeyTab=true keyTab="/etc/krb5.keytab" principal="DBUser@TEST.CORP" doNotPrompt=true storeKey=true useTicketCache=false; };
krb5.conf配置
[logging] default = FILE:/var/log/krb5libs.log kdc = FILE:/var/log/krb5kdc.log admin_server = FILE:/var/log/kadmind.log [libdefaults] default_realm = TEST.CORP dns_lookup_realm = false dns_lookup_kdc = false ticket_lifetime = 30d renew_lifetime = 30d rdns = false forwardable = true udp_preference_limit = 0 rdns = false default_tkt_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 rc4-hmac default_tgs_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 rc4-hmac permitted_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 rc4-hmac [realms] TEST.CORP = { kdc = 172.31.82.203 admin_server = 172.31.82.203 } [domain_realm] .test.corp = TEST.CORP test.corp = TEST.CORP
已确认的Kerberos票据
Ticket cache: KCM:0 Default principal: DBUser@TEST.CORP Valid starting Expires Service principal 09/02/2024 21:54:56 10/02/2024 21:54:56 krbtgt/TEST.CORP@TEST.CORP renew until 10/02/2024 21:54:56
Windows AD注册的SPN
C:\Users\Administrator>setspn -L DBUser Registered ServicePrincipalNames for CN=DBUser,CN=Users,DC=test,DC=corp: MSSQLSvc/ip-172-31-18-241.ec2.internal:1433
JDBC连接字符串
jdbc:sqlserver://172.31.23.171:1433;databaseName=master;integratedSecurity=true;authenticationScheme=JavaKerberos;ServerSpn=MSSQLSvc/ip-172-31-18-241.ec2.internal:1433;jaasLoginConfigName=SqlJaasConf;realm=TEST.CORP
已完成的排查步骤
- 执行
sqlcmd -S 172.31.23.171 -d master -G -C可成功登录MSSQL并执行SQL命令; - 用sqlline测试JDBC连接,连接串中加入域凭据时可成功连接,移除则失败。
问题
请问问题出在哪里?该如何调试?
内容的提问来源于stack exchange,提问作者Kevin
相关产品推荐
相关产品推荐

