Mac上.NET6连接Docker中SQL Server的Kerberos认证失败问题
问题:Docker运行SQL Server镜像时,
dotnet ef database update触发Kerberos认证失败 环境信息
- M1芯片MacBook Pro,系统为Ventura OS 13.3.1
- 正在进行.NET6教程学习,通过Docker运行SQL Server镜像,已成功用Azure Data Studio连接数据库
- 采用代码优先方式创建数据库,已完成模型创建并通过dotnet CLI添加迁移
执行dotnet ef database update时的错误信息
Cannot authenticate using Kerberos. Ensure Kerberos has been initialized on the client with 'kinit' and a Service Principal Name has been registered for the SQL Server to allow Kerberos authentication. ErrorCode=InternalError, Exception=Interop+NetSecurityNative+GssApiException: GSSAPI operation failed with error - An unsupported mechanism was requested (unknown mech-code 0 for mech unknown). at System.Net.Security.NegotiateStreamPal.GssInitSecurityContext(SafeGssContextHandle& context, SafeGssCredHandle credential, Boolean isNtlm, SafeGssNameHandle targetName, GssFlags inFlags, Byte[] buffer, Byte[]& outputBuffer, UInt32& outFlags, Int32& isNtlmUsed) at System.Net.Security.NegotiateStreamPal.EstablishSecurityContext(SafeFreeNegoCredentials credential, SafeDeleteContext& context, String targetName, ContextFlagsPal inFlags, SecurityBuffer inputBuffer, SecurityBuffer outputBuffer, ContextFlagsPal& outFlags) at Microsoft.Data.SqlClient.SNI.SNIProxy.GenSspiClientContext(SspiClientContextStatus sspiClientContextStatus, Byte[] receivedBuff, Byte[]& sendBuff, Byte[][] serverName) at Microsoft.Data.SqlClient.SNI.TdsParserStateObjectManaged.GenerateSspiClientContext(Byte[] receivedBuff, UInt32 receivedLength, Byte[]& sendBuff, UInt32& sendLength, Byte[][] _sniSpnBuffer) at Microsoft.Data.SqlClient.TdsParser.SNISSPIData(Byte[] receivedBuff, UInt32 receivedLength, Byte[]& sendBuff, UInt32& sendLength)
已尝试的操作及结果
- 多次执行
kinit命令,均无法连接KDC:
sbaqla@Saras-MacBook-Pro ~ % kinit sbaqla@ATTLOCAL.NET's password: kinit: krb5_get_init_creds: unable to reach any KDC in realm ATTLOCAL.NET, tried 0 KDCs
- 尝试使用电脑密码、Docker账户关联的Windows密码、空密码执行
kinit,均无效 - 通过「实用工具->钥匙串访问->票据查看器」修改Kerberos密码,提示密码错误
- 下载Kerberos Ticket Autorenewal应用添加凭据,返回错误:
The operation couldn't be completed. (org.h5l.GSS error 851968 - unable to reach any KDC in realm ATTLOCAL.NET, tried 0 KDCs)
当前krb5.conf文件内容
[libdefaults] default_realm = ATTLOCAL.NET [realms] ATTLOCAL.NET = { kdc = dc-33.attlocal.net }
内容的提问来源于stack exchange,提问作者Sara Baqla
相关产品推荐
相关产品推荐

