Add Kerberos sso docs#1607
Open
DavIvek wants to merge 5 commits intomemgraph-3-10from
Open
Conversation
Documents the new built-in kerberos.py auth module from memgraph#3916: prerequisites, server-side env-var configuration (core + LDAP-mode-only), role-mapping for principal and ldap modes, a Docker end-to-end example, a Neo4j Python driver client snippet, and a troubleshooting list.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
- Match Neo4j's pattern: snippet only shows the connect call via kerberos_auth(); ticket acquisition is the user's problem. The single-leg / no-mutual-auth requirement moves to a Callout with concrete python-gssapi and Java pointers. - LDAP_AUTH=gssapi description now spells out SASL/GSSAPI binding via the service keytab. - pip install ldap3 (matches the module's own error message).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release note
Documents the new built-in Kerberos SSO auth module. Covers prerequisites (KDC, NTP, FQDN/PTR, SPN, keytab), server-side environment variables (core + LDAP-mode role mapping), enabling via
--auth-module-mappings=kerberos, role mapping for both principal and ldap modes, a Docker end-to-end example, a Python driver client snippet, and a troubleshooting list.Related product PRs
PRs from product repo this doc page is related to:
memgraph/memgraph#3916
Checklist:
bugfixorfeaturelabel, based on the product PR type you're documenting