Kerberos Authentication

This section explains how to use Kerberos authentication with the SQL Developer Extension for VS Code on Windows, supporting two Kerberos credential sources:

VS Code Extension Settings

To open the settings, click the Extensions icon in the Activity Bar on the left side, locate Oracle SQL Developer Extension for VS Code, click Manage, and then select Settings. In the Settings window, select Database Connections from the left pane. Description of kerberos_settings.png follows

Description of the illustration kerberos_settings.png

Choosing the Kerberos Mode (MSLSA/MIT)

The Kerberos mode is controlled by two settings that are mutually exclusive. After changing either setting, you must restart the extension for changes to take effect.

Creating or Editing Connections for Kerberos

To configure a Kerberos connection, ensure the connection definition indicates Kerberos is enabled by setting the following Advanced property. This property is required for both MSLSA and MIT Kerberos connections.

oracle.net.authentication_services = (KERBEROS5)

The extension uses the presence of KERBEROS5 to treat the connection as Kerberos-based. For Kerberos connections, the username and password fields can be left empty because authentication is performed using existing Kerberos credentials. This applies to Custom JDBC, TNS, and Wallet connection types.

MIT Kerberos (File-Based) Connection

When using MIT Kerberos-style (file-based) authentication, two additional configuration items are required beyond what is typically needed for an MSLSA Kerberos connection:

This property is used in addition to enabling Kerberos through oracle.net.authentication_services = (KERBEROS5). Together, these settings ensure the connection uses the file-based Kerberos configuration and ticket cache rather than Windows LSA credentials.

SQLCL Support

All Kerberos functionality supported by the VS Code extension is also supported when launching and using SQLcl, so Kerberos-authenticated sessions work seamlessly without requiring users to re-enter connection details. The solution supports opening SQLcl by:

For MSLSA on Windows, the external scenario introduces an additional -mslsa flag to start SQLcl in native Kerberos mode. For example:

sql -nolog -mslsa
connect -name <connection_name>

For MIT Kerberos, SQLcl continues to work using the configured file-based Kerberos settings. In all cases (except for the optional -mslsa flag on Windows), SQLcl should rely on the already-stored connection definition and require no extra parameters.