Kerberos Authentication

This section explains how to use Kerberos authentication with the SQL Developer Extension for VS Code, supporting two Kerberos credential sources:

Use one Kerberos credential source at a time. The Security: Windows Local Security Authority setting determines whether the extension uses MSLSA credentials. To use MIT Kerberos, configure the appropriate Security: Kerberos Configuration Path and Security: Kerberos Credential Cache Path settings for your environment.

VS Code Extension Settings

To configure Kerberos settings, open the SQL Developer for VS Code extension settings and search for Kerberos. The settings are available under Database Connections. Description of kerberos_settings.png follows

Description of the illustration kerberos_settings.png

Choosing the Kerberos Mode (MSLSA/MIT)

The Kerberos mode is controlled by the following settings. After changing any of these settings, you must restart the extension for changes to take effect.

Note: Windows LSA and MIT Kerberos cannot be active at the same time. Restart the extension after changing the Kerberos security settings.

Using Kerberos Authentication for a Connection

Kerberos authentication is available for Basic, Custom JDBC, TNS, and Cloud Wallet connection types. When creating or editing a supported connection, select Kerberos from the Authentication Type list. For information about creating or editing a database connection, see Creating a Connection. When Kerberos is selected, SQL Developer for VS Code automatically configures the required Kerberos authentication service. For MIT Kerberos connections only, if oracle.net.kerberos5_mutual_authentication is not already configured, the extension automatically sets it to true.

Kerberos Connection Properties

The normal Kerberos workflow does not usually require users to add Oracle Net Kerberos properties manually in Advanced properties.

Note: If you explicitly specify oracle.net.kerberos5_mutual_authentication or oracle.net.kerberos5_cc_name in Advanced properties, the value that you specify takes precedence over the automatically configured value.

SQLCL Support

All Kerberos functionality supported by the VS Code extension is also supported when launching and using SQLcl, so Kerberos-authenticated sessions work seamlessly without requiring users to re-enter connection details. The solution supports opening SQLcl by:

For MSLSA on Windows, the external scenario introduces an additional -mslsa flag to start SQLcl in native Kerberos mode. For example:

sql -nolog -mslsa
connect -name <connection_name>

For MIT Kerberos, SQLcl continues to work using the configured file-based Kerberos settings. In all cases (except for the optional -mslsa flag on Windows), SQLcl should rely on the already-stored connection definition and require no extra parameters.