Visitar URL original
[Feature Request] Support transport encryption using GSSAPI · Issue #1322 · MagicStack/asyncpg · GitHub
Skip to content

[Feature Request] Support transport encryption using GSSAPI #1322

Description

@jackhill

In addition to using GSSAPI for authentication, Postgres supports using GSSAPI for channel encryption as an alternative to TLS with certs. I find this pairs well when also using GSSAPI for authentication.

Activity

  1. mayankdas2005 commented on Oct 8, 2026

    @mayankdas2005

    Hi @jackhill , I'm interested in working on this. Before I start, a few scoping questions:

    Would you accept a PR adding a gssencmode option (disable / prefer / require)?
    The main work is the GSSENCRequest handshake plus a transport wrapper that does GSS wrap/unwrap, since there's no start_tls equivalent. Does that approach fit how you'd want it structured?
    Tests would need a Kerberos KDC. Would you prefer those gated behind an optional marker/CI job, or kept out of the default suite?
    Should prefer be the default as in libpq, or should it start opt-in to avoid changing existing behavior?

    Happy to start with a design sketch if that's easier to review first.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions