Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions src/Npgsql/Internal/NpgsqlConnector.cs
Original file line number Diff line number Diff line change
Expand Up @@ -249,6 +249,10 @@ internal bool PostgresCancellationPerformed

static readonly SslApplicationProtocol _alpnProtocol = new("postgresql");

// By default, consider that we do have kerberos library installed
// It'll be set to false the first time we hit TypeInitializationException
static bool hasKerberosLibrary = true;

#pragma warning disable CA1859
// We're casting to IDisposable to not explicitly reference X509Certificate2 for NativeAOT
// TODO: probably pointless now, needs to be rechecked
Expand Down Expand Up @@ -603,6 +607,15 @@ await OpenCore(

internal async ValueTask<GssEncryptionResult> GSSEncrypt(bool async, bool isRequired, CancellationToken cancellationToken)
{
// There's no kerberos library installed, so no point in going further
if (!hasKerberosLibrary)
{
if (isRequired)
throw new NpgsqlException("Unable to load native library to negotiate GSS encryption");

return GssEncryptionResult.GetCredentialFailure;
}

ConnectionLogger.LogTrace("Negotiating GSS encryption");

var targetName = $"{KerberosServiceName}/{Host}";
Expand Down Expand Up @@ -632,6 +645,9 @@ internal async ValueTask<GssEncryptionResult> GSSEncrypt(bool async, bool isRequ
}
catch (TypeInitializationException)
{
// No kerberos library, make sure others do not even attempt to request it
hasKerberosLibrary = false;

// On UNIX .NET throws TypeInitializationException if it's unable to load the native library
if (isRequired)
throw new NpgsqlException("Unable to load native library to negotiate GSS encryption");
Expand Down
Loading