Kerberos Authentication
This section explains how to use Kerberos authentication with the SQL Developer Extension for VS Code, supporting two Kerberos credential sources:
-
MSLSA (Windows LSA): This is Windows’ native Kerberos credential store, where tickets are kept in memory by the Local Security Authority (LSA).
-
MIT Kerberos: This method uses a file-based Kerberos configuration and credential cache.
Use one Kerberos credential source at a time. The Security: Windows Local Security Authority setting determines whether the extension uses MSLSA credentials. To use MIT Kerberos, configure the appropriate Security: Kerberos Configuration Path and Security: Kerberos Credential Cache Path settings for your environment.
VS Code Extension Settings
To configure Kerberos settings, open the SQL Developer for VS Code extension settings and search for Kerberos. The settings are available under Database Connections.

Description of the illustration kerberos_settings.png
Choosing the Kerberos Mode (MSLSA/MIT)
The Kerberos mode is controlled by the following settings. After changing any of these settings, you must restart the extension for changes to take effect.
-
Security: Windows Local Security Authority
This setting enables MSLSA-based Kerberos authentication on Windows. When the Use the Windows Local Security Authority for Kerberos authentication checkbox is selected, the extension uses the Windows Local Security Authority (LSA) credential store to obtain the Kerberos ticket needed to perform the authentication.
-
Security: Kerberos Configuration Path
This setting specifies the location of the Kerberos configuration file (for example, krb5.conf) used for MIT Kerberos authentication. When a valid path is provided, the extension uses it to get the Kerberos configuration needed to create the connection.
-
Security: Kerberos Credential Cache Path
This setting specifies the location of the Kerberos credential cache file used for MIT Kerberos authentication. When a valid path is provided, the extension uses the cached Kerberos ticket to perform authentication and sets the
oracle.net.kerberos5_cc_nameconnection property accordingly.
Note: Windows LSA and MIT Kerberos cannot be active at the same time. Restart the extension after changing the Kerberos security settings.
Using Kerberos Authentication for a Connection
Kerberos authentication is available for Basic, Custom JDBC, TNS, and Cloud Wallet connection types. When creating or editing a supported connection, select Kerberos from the Authentication Type list. For information about creating or editing a database connection, see Creating a Connection.
When Kerberos is selected, SQL Developer for VS Code automatically configures the required Kerberos authentication service. For MIT Kerberos connections only, if oracle.net.kerberos5_mutual_authentication is not already configured, the extension automatically sets it to true.
Kerberos Connection Properties
The normal Kerberos workflow does not usually require users to add Oracle Net Kerberos properties manually in Advanced properties.
-
Authentication services When Kerberos is selected as Authentication Type, SQL Developer for VS Code automatically configures
oracle.net.authentication_services=(KERBEROS5). -
Credential cache For MIT Kerberos, the value specified in Kerberos Credential Cache Path is used automatically for
oracle.net.kerberos5_cc_name. -
Mutual authentication For MIT Kerberos, SQL Developer for VS Code automatically sets
oracle.net.kerberos5_mutual_authentication=truewhen no value has already been configured.
Note: If you explicitly specify oracle.net.kerberos5_mutual_authentication or oracle.net.kerberos5_cc_name in Advanced properties, the value that you specify takes precedence over the automatically configured value.
SQLCL Support
All Kerberos functionality supported by the VS Code extension is also supported when launching and using SQLcl, so Kerberos-authenticated sessions work seamlessly without requiring users to re-enter connection details. The solution supports opening SQLcl by:
-
Right-clicking a saved connection and selecting Open SQLcl
-
Connecting from an in-IDE SQLcl terminal using
connect -name <connection_name> -
Connecting from an external OS terminal using the SQLcl executable with a named connection:
sql -nolog connect -name <connection_name>
For MSLSA on Windows, the external scenario introduces an additional -mslsa flag to start SQLcl in native Kerberos mode. For example:
sql -nolog -mslsa
connect -name <connection_name>
For MIT Kerberos, SQLcl continues to work using the configured file-based Kerberos settings. In all cases (except for the optional -mslsa flag on Windows), SQLcl should rely on the already-stored connection definition and require no extra parameters.