You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mac上.NET6连接Docker中SQL Server的Kerberos认证失败问题

问题:Docker运行SQL Server镜像时,dotnet ef database update触发Kerberos认证失败

环境信息

  • M1芯片MacBook Pro,系统为Ventura OS 13.3.1
  • 正在进行.NET6教程学习,通过Docker运行SQL Server镜像,已成功用Azure Data Studio连接数据库
  • 采用代码优先方式创建数据库,已完成模型创建并通过dotnet CLI添加迁移

执行dotnet ef database update时的错误信息

Cannot authenticate using Kerberos. Ensure Kerberos has been initialized on the client with 'kinit' and a Service Principal Name has been registered for the SQL Server to allow Kerberos authentication.
ErrorCode=InternalError, Exception=Interop+NetSecurityNative+GssApiException: GSSAPI operation failed with error - An unsupported mechanism was requested (unknown mech-code 0 for mech unknown).
at System.Net.Security.NegotiateStreamPal.GssInitSecurityContext(SafeGssContextHandle& context, SafeGssCredHandle credential, Boolean isNtlm, SafeGssNameHandle targetName, GssFlags inFlags, Byte[] buffer, Byte[]& outputBuffer, UInt32& outFlags, Int32& isNtlmUsed)
at System.Net.Security.NegotiateStreamPal.EstablishSecurityContext(SafeFreeNegoCredentials credential, SafeDeleteContext& context, String targetName, ContextFlagsPal inFlags, SecurityBuffer inputBuffer, SecurityBuffer outputBuffer, ContextFlagsPal& outFlags)
 at Microsoft.Data.SqlClient.SNI.SNIProxy.GenSspiClientContext(SspiClientContextStatus sspiClientContextStatus, Byte[] receivedBuff, Byte[]& sendBuff, Byte[][] serverName)
 at Microsoft.Data.SqlClient.SNI.TdsParserStateObjectManaged.GenerateSspiClientContext(Byte[] receivedBuff, UInt32 receivedLength, Byte[]& sendBuff, UInt32& sendLength, Byte[][] _sniSpnBuffer)
 at Microsoft.Data.SqlClient.TdsParser.SNISSPIData(Byte[] receivedBuff, UInt32 receivedLength, Byte[]& sendBuff, UInt32& sendLength)

已尝试的操作及结果

  • 多次执行kinit命令,均无法连接KDC:
sbaqla@Saras-MacBook-Pro ~ % kinit
sbaqla@ATTLOCAL.NET's password: 
kinit: krb5_get_init_creds: unable to reach any KDC in realm ATTLOCAL.NET, tried 0 KDCs
  • 尝试使用电脑密码、Docker账户关联的Windows密码、空密码执行kinit,均无效
  • 通过「实用工具->钥匙串访问->票据查看器」修改Kerberos密码,提示密码错误
  • 下载Kerberos Ticket Autorenewal应用添加凭据,返回错误:
The operation couldn't be completed. (org.h5l.GSS error 851968 - unable to reach any KDC in realm ATTLOCAL.NET, tried 0 KDCs)

当前krb5.conf文件内容

[libdefaults]
  default_realm = ATTLOCAL.NET
 
[realms]
ATTLOCAL.NET = {
   kdc = dc-33.attlocal.net
}

内容的提问来源于stack exchange,提问作者Sara Baqla

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 22:03:31