Gss Failure - Dotnet 5 and Windows Auth in Docker

Viewed 845

I'm struggling for few days with Windows Authentication in dotnet 5 project and can't get it working in the Docker environment. When running locally on Windows system, it works properly. I found other topics, which might be a duplicate, but they are related to .net core 3.1, not to dotnet 5.

Result of executing a method in a controller, that requires windows auth: Result

I followed official documentation: https://docs.microsoft.com/en-us/aspnet/core/security/authentication/windowsauth?view=aspnetcore-5.0&tabs=visual-studio#kestrel

Let me explain, what I did so far. Firstly in dotnet project:

  • services.AddAuthentication(NegotiateDefaults.AuthenticationScheme).AddNegotiate();
  • Just in case I added an additional simple controller without [Authorize] attribute and it of course works OK in the Docker. Actually makes no sense, but it just made me sure, that it is working.

Besides the dotnet code

  • I generated krb5.conf file for my company domain and copied that in the docker image. It is working OK, because I'm able to use kinit in the shell and sucessfully login. Unfortunately, I can't share this file here. I'm seeing valid ticket when executing klist

klist

  • Generated username.keytab file with ktutil
ktutil 
ktutil: add_entry -password -p myUserName@MY.COMPANY.LOCAL -k 1 -e RC4-HMAC
# ktutil prompts for a password
ktutil: write_kt myUserName.keytab
ktuilt: exit
  • The docker file
FROM company-custom-docker-image-with-dotnet-5 AS build
WORKDIR /app

COPY . ./
RUN dotnet publish -c Release -o out

FROM company-custom-docker-image-with-dotnet-runtime-5 
WORKDIR /app
COPY --from=build /app/out .
COPY krb5.conf /etc/krb5.conf
COPY username.keytab .
COPY run.sh .

ENTRYPOINT ["/app/run.sh"]

And run.sh is simple:

echo "Starting kinit"
kinit username -k -t username.keytab
dotnet MyApi.dll

The error after running a method in a controller with [Authorize] attribute is:

Interop+NetSecurityNative+GssApiException: GSSAPI operation failed with error - Unspecified GSS failure. Minor code may provide more information (Keytab FILE:/etc/krb5.keytab is nonexistent or empty).

After renaming myUserName.keytab and moving to /etc/krb5.keytab I receive other error:

Interop+NetSecurityNative+GssApiException: GSSAPI operation failed with error - An unsupported mechanism was requested.

There's a thing, which I don't understand and I should do.

The Microsoft.AspNetCore.Authentication.Negotiate component performs User Mode authentication. Service Principal Names (SPNs) must be added to the user account running the service, not the machine account. Execute setspn -S HTTP/myservername.mydomain.com myuser in an administrative command shell.

I don't know what exactly I have to put as a myservername. Could you please guide me, how it can be done?

Thank you for any help and hint.

0 Answers
Related