Repository navigation
Service principal name on linux uses instance name instead of port when using SSRP #3566
Description
Activity
- added a commit that references this issue
on Apr 10, 2026 Root Cause Analysis
This is the same class of bug as #2187, which was fixed in PR #2240 but only for the
Protocol.TCPcase.The Bug
In
SniProxy.netcore.cs—GetSqlServerSPNs(), the SPN postfix (port vs instance name) is selected with:postfix = dataSource.ResolvedProtocol == DataSource.Protocol.TCP ? dataSource.ResolvedPort.ToString() : dataSource.InstanceName;
When connecting with
Data Source=server\instance(notcp:prefix),ResolvedProtocolisProtocol.None— notProtocol.TCP. The connection logic inCreateConnectionHandlecorrectly treatsProtocol.Noneas TCP (falls through toCreateTcpHandle, which resolves the port via SSRP and setsResolvedPort). ButGetSqlServerSPNsonly checked forProtocol.TCPexactly, so it took the else branch and used the instance name instead of the resolved port.The same issue applies to
Protocol.Admin(DAC connections), which also uses TCP and resolves ports via SSRP.The Fix
Inverted the condition: only Named Pipes (
Protocol.NP) should use the instance name in the SPN. All other protocols use the resolved port:postfix = dataSource.ResolvedProtocol == DataSource.Protocol.NP ? dataSource.InstanceName : dataSource.ResolvedPort.ToString();
Draft PR: #4180
- added a commit that references this issue
on Apr 10, 2026 - added a commit that references this issue
on Apr 29, 2026 - added a commit that references this issue
on May 7, 2026 - added a commit that references this issue
on Jun 10, 2026
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsDone
Describe the bug
We're connecting to an SQL server using
Data Source=<server>\<instance>; Integrated Security = truefrom linux. This first requests a port number from SSRP, and then requests a service ticket from kerberos.Seeing from packet trace we see that the SPN requested uses instance name in the port field similar to issue #2187.
This is a problem because we cannot self-register SPNs for machines using instance name instead of port number in AD, so developer machines using connection string
Data Source=.\SQLEXPRESS; Integrated Security = true(using our self-made SSRP-daemon) fails to fetch the ticket due to the incorrect principal name.If i specify port number after the instance name, the SPN requested does not reference instance name but instead uses port number so this leads me to believe there is a bug in what SPN is requested when the port is resolved through SSRP.
To reproduce
Connect to an sql server named instance without port number so that SSRP is invoked. Using packet trace we observe that the ticket requested specifies instance name.
Expected behavior
I expect the service ticket requested to specify the port number per the docs similar to the issue #2187
Further technical details
Microsoft.Data.SqlClient version: 6.1.0-preview2.25178.5 (from nuget.org)
.NET target: .NET 8.0
SQL Server version: Any
Operating system: Ubuntu 25.04