For the complete documentation index, see llms.txt. This page is also available as Markdown.

Authentication with gssapi

Instructions for installing and configuring the gssapi plugin to validate user credentials against services like Kerberos or NTLM.

Overview

The gssapi authentication plugin validates user credentials against a GSSAPI-based authentication service, like Kerberos or NTLM.

Install Package

The gssapi authentication plugin requires an additional package to be installed on Linux. On CentOS, RHEL, and Rocky Linux:

$ sudo yum install MariaDB-gssapi-server

On Debian and Ubuntu:

$ sudo apt install mariadb-plugin-gssapi-server

On SLES:

$ sudo zypper install MariaDB-gssapi-server

Configure

The gssapi authentication plugin requires some system variables to be configured, including:

  • gssapi_keytab_path

  • gssapi_principal_name

For example:

[mariadb]
...
gssapi_keytab_path=KEYTAB_PATH
gssapi_principal_name=PRINCIPAL_NAME

Install Plugin

The gssapi authentication plugin must be installed before it can be used.

To install with the INSTALL SONAME statement:

To install in a configuration file with the plugin_load_add option:

Create User

To create a user account that uses the gssapi authentication plugin, specify the plugin in the CREATE USER statement:

An optional realm can be specified:

This page is: Copyright © 2026 MariaDB. All rights reserved.

spinner

Last updated

Was this helpful?