Class NegotiateProxyAuthGenerator

java.lang.Object
software.amazon.awssdk.http.nio.netty.internal.NegotiateProxyAuthGenerator
All Implemented Interfaces:
ProxyAuthGenerator

@SdkInternalApi public class NegotiateProxyAuthGenerator extends Object implements ProxyAuthGenerator
Auth generator for Kerberos. This does not login/authentication to Kerberos. It expects the ticket cache to be present and simply reads that to generate the token.
  • Constructor Details

    • NegotiateProxyAuthGenerator

      public NegotiateProxyAuthGenerator(Configuration config, Executor executor)
      Parameters:
      config - The JAAS configuration to log in with, or null to use the default ticket-cache-only configuration.
      executor - Executor to run the blocking Kerberos work on. Must not be a Netty event loop; see generateAuthParams(URI). Its lifecycle is owned by the caller.
  • Method Details

    • scheme

      public ProxyAuthScheme scheme()
      Description copied from interface: ProxyAuthGenerator
      The name of the auth scheme this generator supports.
      Specified by:
      scheme in interface ProxyAuthGenerator
    • generateAuthParams

      public CompletableFuture<String> generateAuthParams(URI proxyEndpoint)
      Description copied from interface: ProxyAuthGenerator
      Generate the auth params for this request.

      This is asynchronous because generating the params may block - Kerberos, for example, may need to read the ticket cache from disk and contact the KDC. Implementations that block MUST complete the returned future from a thread other than the caller's; the caller is a Netty event loop thread, and blocking it would stall every other channel assigned to that loop.

      Specified by:
      generateAuthParams in interface ProxyAuthGenerator