You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RHEL9上Tomcat应用JDBC Kerberos认证连接MSSQL失败求助

基于JDK8的Tomcat应用通过JDBC Kerberos认证连接MSSQL失败

应用启动时持续报错:

ERROR - failed to connect to DB, reason is probably not the database absence. cause: Cannot login with Kerberos principal not_used, check your credentials. Kerberos Login failed: Integrated authentication failed. ClientConnectionId

已做配置

JVM参数(setenv.sh)

export CATALINA_OPTS="$CATALINA_OPTS -Djava.security.auth.login.config=/opt/tomcat/bin/jaas.conf -Djava.security.krb5.conf=/etc/krb5.conf -Djava.security.debug=all"

JAAS配置(jaas.conf)

SqlJaasConf {
      com.sun.security.auth.module.Krb5LoginModule required
      useKeyTab=true
      keyTab="/etc/krb5.keytab"
      principal="DBUser@TEST.CORP"
      doNotPrompt=true
      storeKey=true
      useTicketCache=false;
    };

krb5.conf配置

[logging]
    default = FILE:/var/log/krb5libs.log
    kdc = FILE:/var/log/krb5kdc.log
    admin_server = FILE:/var/log/kadmind.log

[libdefaults]
    default_realm = TEST.CORP
    dns_lookup_realm = false
    dns_lookup_kdc = false
    ticket_lifetime = 30d
    renew_lifetime = 30d
    rdns = false
    forwardable = true
    udp_preference_limit = 0
    rdns = false
    default_tkt_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 rc4-hmac
    default_tgs_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 rc4-hmac
    permitted_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 rc4-hmac

[realms]
TEST.CORP = {
     kdc = 172.31.82.203
     admin_server = 172.31.82.203
 }

[domain_realm]
.test.corp = TEST.CORP
test.corp = TEST.CORP

已确认的Kerberos票据

Ticket cache: KCM:0
Default principal: DBUser@TEST.CORP

Valid starting       Expires              Service principal
09/02/2024 21:54:56  10/02/2024 21:54:56  krbtgt/TEST.CORP@TEST.CORP
    renew until 10/02/2024 21:54:56

Windows AD注册的SPN

C:\Users\Administrator>setspn -L DBUser
Registered ServicePrincipalNames for CN=DBUser,CN=Users,DC=test,DC=corp:
        MSSQLSvc/ip-172-31-18-241.ec2.internal:1433

JDBC连接字符串

jdbc:sqlserver://172.31.23.171:1433;databaseName=master;integratedSecurity=true;authenticationScheme=JavaKerberos;ServerSpn=MSSQLSvc/ip-172-31-18-241.ec2.internal:1433;jaasLoginConfigName=SqlJaasConf;realm=TEST.CORP

已完成的排查步骤

  • 执行sqlcmd -S 172.31.23.171 -d master -G -C可成功登录MSSQL并执行SQL命令;
  • 用sqlline测试JDBC连接,连接串中加入域凭据时可成功连接,移除则失败。

问题

请问问题出在哪里?该如何调试?


内容的提问来源于stack exchange,提问作者Kevin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 17:43:25