jackc/pgx · error

expected AuthenticationGSSContinue message but received…

Error message

expected AuthenticationGSSContinue message but received unexpected message %T

What it means

During GSSAPI authentication the client expected an AuthenticationGSSContinue message but received a different backend message type. The GSS exchange is out of sequence and authentication fails.

Solutions

  1. Inspect the %T value to identify the unexpected message
  2. Verify the server's GSSAPI/Kerberos configuration
  3. Ensure the Kerberos client credentials are valid (kinit)
  4. Check for protocol interference from proxies
Defensive patterns

Strategy: type-guard

When it happens

Trigger: Thrown at pgconn/krb5.go:99 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/64468ab5781058b2. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/krb5.go:99

		}
	}
	return nil
}

func (c *PgConn) rxGSSContinue() (*pgproto3.AuthenticationGSSContinue, error) {
	msg, err := c.receiveMessage()
	if err != nil {
		return nil, err
	}

	switch m := msg.(type) {
	case *pgproto3.AuthenticationGSSContinue:
		return m, nil
	case *pgproto3.ErrorResponse:
		return nil, ErrorResponseToPgError(m)
	}

	return nil, fmt.Errorf("expected AuthenticationGSSContinue message but received unexpected message %T", msg)
}

View on GitHub (pinned to ec1a0befd2)