jackc/pgx · error
kerberos error: no GSSAPI provider registered, see…
Error message
kerberos error: no GSSAPI provider registered, see https://github.com/otan/gopgkrb5
What it means
gssAuth guard: the server requested GSSAPI/Kerberos authentication, but pgx ships no built-in GSS provider and none has been registered via RegisterGSSProvider. The missing registration (absent init side effect of a provider package such as github.com/otan/gopgkrb5) is the faulty input.
Solutions
- Import a GSS provider, e.g. github.com/otan/gopgkrb5, and call pgconn.RegisterGSSProvider in init
- Or switch the server's pg_hba.conf to a non-GSS authentication method
Defensive patterns
Strategy: fallback
When it happens
Trigger: Thrown at pgconn/krb5.go:38 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04).
Data as JSON: /api/errors/cd0efb4334db74fe.
Report an issue: GitHub.
Appendix: source
Thrown at pgconn/krb5.go:38
// import "github.com/otan/gopgkrb5"
//
// func init() {
// pgconn.RegisterGSSProvider(func() (pgconn.GSS, error) { return gopgkrb5.NewGSS() })
// }
func RegisterGSSProvider(newGSSArg NewGSSFunc) {
newGSS = newGSSArg
}
// GSS provides GSSAPI authentication (e.g., Kerberos).
type GSS interface {
GetInitToken(host, service string) ([]byte, error)
GetInitTokenFromSPN(spn string) ([]byte, error)
Continue(inToken []byte) (done bool, outToken []byte, err error)
}
func (c *PgConn) gssAuth() error {
if newGSS == nil {
return errors.New("kerberos error: no GSSAPI provider registered, see https://github.com/otan/gopgkrb5")
}
cli, err := newGSS()
if err != nil {
return err
}
var nextData []byte
if c.config.KerberosSpn != "" {
// Use the supplied SPN if provided.
nextData, err = cli.GetInitTokenFromSPN(c.config.KerberosSpn)
} else {
// Allow the kerberos service name to be overridden
service := "postgres"
if c.config.KerberosSrvName != "" {
service = c.config.KerberosSrvName
}
nextData, err = cli.GetInitToken(c.config.Host, service)
}View on GitHub (pinned to ec1a0befd2)