MySQL Workbench

5.3.4.2 LDAP Sasl/Kerberos

The LDAP Sasl/Kerberos connection method is supported as an LDAP authentication method for MySQL servers and MySQL Workbench on Linux only. Using the GSSAPI security abstraction interface, a connection of this type authenticates to Kerberos to obtain service credentials, then uses those credentials in turn to enable secure access to other services. A GSSAPI library and Kerberos services must be available to MySQL Server (see The GSSAPI/Kerberos Authentication Method).

Tip

If the Linux environment hosting MySQL Workbench has access to LDAP through Microsoft Active directory, then Kerberos is enabled by default.

MySQL Workbench provides the authentication_ldap_sasl_client client-side plugin to support this connection method. It is compatible with the authentication_ldap_sasl server-side plugin, which must be installed on the MySQL server hosting the connection (see Installing LDAP Pluggable Authentication). Also, the authentication_ldap_sasl_auth_method_name system variable must be set to use the GSSAPI method. For additional variables that can (or should) be configured when using the server-side plugin, see Configure the Server-Side SASL LDAP Authentication Plugin for GSSAPI/Kerberos.

Connection values for the LDAP Sasl/Kerberos connection method include:

Parameters Tab

SSL Tab

The SSL options for this connection method are the same as Standard TCP/IP (see SSL Tab).

Advanced Tab

The advanced options for this connection method are similar to Standard TCP/IP (see Advanced Tab), but also include the following options: