Connection with Kerberos

Xshell 7 supports MIT GSSAPI Kerberos and Microsoft's SSPI Kerberos authentication. This article assumes that you have a working Kerberos server and client.
To create a new Kerberos session,

  1. Select [New] from the [File] menu.
  2. Enter a session name in [Name].
  3. Select SSH from the [Protocols] list.
  4. Enter a host name in [Host]
  5. Select [Authentication] from under [Category].
  6. Select GSSAPI from the [Method] list.
    • Note 
      If the PC running Xshell is utilizing an Xshell supported Kerberos module, Xshell can only automatically authenticate to the SSH server if GSSAPI authentication is selected.
  7. To change the GSSAPI settings, click the [Setup] button.
    • Note 
      To connect to another server using Kerberos authentication from a server using Kerberos authentication, select the 'Allow GSSAPI credential delegation' option.
  8. Click [OK] to save the GSSAPI settings.
  9. Enter the user name.
  10. Click [OK] to save the session file.
  11. Click [Connect] to connect immediately or select the session file from the Sessions Dialog Box to connect.


You have finished creating a session that will use the Kerberos module. When this session opens, it will try to use the Kerberos credential for the specified user. It has to be the same user you defined in the Network Identity Manager.