在 Azure DevOps Server 上搭配 Git LFS 使用 Kerberos 驗證

Azure DevOps Server |Azure DevOps Server 2022

如果你有 Azure DevOps Server 搭配 Windows 認證,且需要 Git LFS 才能與 Kerberos 相容,請使用這篇文章。

此指引僅適用於 Azure DevOps Server。 Azure DevOps Services 使用不同的認證流程。

在繼續之前,請確認你的環境是否符合以下假設:

  • 你用的是 Azure DevOps Server,不是 Azure DevOps Services。
  • 你的 Azure DevOps Server 部署使用 Windows 認證。
  • 你使用 Git LFS 搭配連線到 Azure DevOps Server 的存放庫。

備註

Git LFS 版本運作方式

Git LFS 從 Git LFS 2.10.0 起支援 Kerberos 認證。

早期的 Git LFS 版本支援 NTLM 認證。 然而,NTLM 支援自 Git LFS 3.0.0 起被移除。

如果你連接到使用 Windows 認證的 Azure DevOps Server 實例,Git LFS 3.0.0 及更新版本在該情境下需要 Kerberos 認證。

更換客戶前需要確認的事項

在升級或排除 Git LFS 故障前,請確認你的環境能成功使用 Kerberos:

  • 請確認你的 Azure DevOps Server 環境是否已設定為 Windows 認證。
  • 確認用戶端連線是否協商使用 Kerberos,而不是回退到其他驗證機制。
  • 在標準化 Kerberos 之前,先檢視你的環境限制。 例如,工作群組及其他非領域情境可能需要分開規劃。

Important

升級到 Git LFS 2.10.0 或更新版本以使用 Kerberos 認證。 如果你的 Azure DevOps Server 實例使用 Windows 認證,且你使用的是 Git LFS 3.0.0 或更新版本,請使用 Kerberos 認證。