{"kind": "auth", "major": "18", "item": {"slug": "ident", "name": "ident", "name_zh": "", "category": "Authentication and access control", "summary": "Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details.", "aliases": [], "content_hash": "24a6051c3372fa1d95cd853b527cbb4c91ef741cb1c356020f49f774bbc717b1", "versions": {"10": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 20.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "10.23", "major": "10", "channel": "historical", "revision": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "catalog_fingerprint": "691be281b476dde4374d7f805b2bacc2e75bdef40f1e9d3d42e91f97fe95cfd0"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, {"url": "/docs/10/auth-methods.html#AUTH-IDENT", "path": "auth-methods.html", "label": "PostgreSQL 10 English manual", "sha256": "856d36a3fdfe8c45a25832e49bd07e9b7480f2ff9a33e58ac7c392630149bc34"}, {"url": "/docs/10/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 10 English manual", "sha256": "04fed609a50e8fd3013ffebb83039c544d39b6c73a6c2b2e23cd7864a70b42da"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.3.5 for details."], "manual_html": "<div class=\"sect2\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h3 class=\"title\">20.3.5.\u00a0Ident Authentication</h3>\n</div>\n</div>\n</div>\n\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/10/auth-methods.html#AUTH-PEER\" title=\"20.3.6.\u00a0Peer Authentication\">Section\u00a020.3.6</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <span class=\"productname\">ident</span>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/10/auth-username-maps.html\" title=\"20.2.\u00a0User Name Maps\">Section\u00a020.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in RFC 1413. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/10/auth-methods.html#AUTH-IDENT", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "11": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 20.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "11.22", "major": "11", "channel": "historical", "revision": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "catalog_fingerprint": "8f21f4444b7f68923f4762af0eb7937fa2907026e91249483e79050de012c901"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, {"url": "/docs/11/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 11 English manual", "sha256": "f4df12f21842e8e354e9b512fdbf555ad1f8a14652c8c2f270a345069d4c29ab"}, {"url": "/docs/11/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 11 English manual", "sha256": "5477c61a002171f5b4c462052d91231c405f39d89d825faf71e52fbae358eef7"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.8.\u00a0Ident Authentication</h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/11/auth-peer.html\" title=\"20.9.\u00a0Peer Authentication\">Section\u00a020.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <span class=\"productname\">ident</span>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/11/auth-username-maps.html\" title=\"20.2.\u00a0User Name Maps\">Section\u00a020.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in RFC 1413. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/11/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "12": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 20.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "12.22", "major": "12", "channel": "historical", "revision": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "catalog_fingerprint": "9f857f4ee4875f9c7de6bfc9df4b757dec8b3a0bb88eadb519c7bd267bd56149"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, {"url": "/docs/12/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 12 English manual", "sha256": "bf028cefbb1d89baa53b1f2a5337d7169562b29d991c8ab5a724f28663eff85d"}, {"url": "/docs/12/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 12 English manual", "sha256": "07e8cddcb38076c86dab95b72c4380a7a325f22401b5b7f9af5dd4931876f2cb"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.8.\u00a0Ident Authentication</h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/12/auth-peer.html\" title=\"20.9.\u00a0Peer Authentication\">Section\u00a020.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <span class=\"productname\">ident</span>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/12/auth-username-maps.html\" title=\"20.2.\u00a0User Name Maps\">Section\u00a020.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in RFC 1413. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/12/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "13": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 20.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "13.23", "major": "13", "channel": "historical", "revision": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "catalog_fingerprint": "c7015c845255c9d721c547c8ab9ef37825d332588c9691d982e6906b7d571002"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, {"url": "/docs/13/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 13 English manual", "sha256": "53b77f1850ff6f6c676aad23c6b2211b8bde6c2ff21753ef3f10486e09ad677f"}, {"url": "/docs/13/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 13 English manual", "sha256": "3cc6ce851945cba450e6b26ecf9cae1efd3c03fb7b55e17876f4d9ea418a7c2e"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.8.\u00a0Ident Authentication</h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/13/auth-peer.html\" title=\"20.9.\u00a0Peer Authentication\">Section\u00a020.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <span class=\"productname\">ident</span>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/13/auth-username-maps.html\" title=\"20.2.\u00a0User Name Maps\">Section\u00a020.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in RFC 1413. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/13/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "14": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 21.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "14.24", "major": "14", "channel": "stable", "revision": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "catalog_fingerprint": "b272e6a82e4c46efda81c3a6a4cdf7de6a83dfff7f02f226a392fbe9acdd3adb"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, {"url": "/docs/14/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 14 English manual", "sha256": "229e98fe4c2c44831e366b9dbd3aef979707a8255141d8b09ec1b7b7f9d493f9"}, {"url": "/docs/14/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 14 English manual", "sha256": "c9a75f04fd4a1069ea261ba061578a75c47a4b7e0bbf88761502fd4c19ccbc3f"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 21.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.8.\u00a0Ident Authentication</h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/14/auth-peer.html\" title=\"21.9.\u00a0Peer Authentication\">Section\u00a021.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <span class=\"productname\">ident</span>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/14/auth-username-maps.html\" title=\"21.2.\u00a0User Name Maps\">Section\u00a021.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc1413\">RFC 1413</a>. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/14/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "15": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 21.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "15.19", "major": "15", "channel": "stable", "revision": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "catalog_fingerprint": "fefe3c425147a86defada190c9b0663cfe02caa1724f5dede93e46457572252d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, {"url": "/docs/15/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 15 English manual", "sha256": "928e3569188c8c05652f4b974df6d3f73f7125770d06c5afe6fcde6bc7fda817"}, {"url": "/docs/15/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 15 English manual", "sha256": "0470cd3eeb82cbc32d4b8b79e29f4427bdfd01f5bb15e6d9b7cee2f6dd2bba44"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 21.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.8.\u00a0Ident Authentication</h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/15/auth-peer.html\" title=\"21.9.\u00a0Peer Authentication\">Section\u00a021.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <code class=\"literal\">ident</code>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/15/auth-username-maps.html\" title=\"21.2.\u00a0User Name Maps\">Section\u00a021.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc1413\">RFC 1413</a>. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/15/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "16": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 21.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "16.15", "major": "16", "channel": "stable", "revision": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "catalog_fingerprint": "fa133458dc8f52e15083b4f59b7a582e2e378b608d3ac5c53054df458a374e23"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, {"url": "/docs/16/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 16 English manual", "sha256": "9a67dc789427d08d89a636315a44a1c79056447574c57a55ee992b875b67030f"}, {"url": "/docs/16/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 16 English manual", "sha256": "ccc5146375a184646d5992edbc693e12c0de4431a35141d6b56c8dd6b3c52132"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 21.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.8.\u00a0Ident Authentication </h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/16/auth-peer.html\" title=\"21.9.\u00a0Peer Authentication\">Section\u00a021.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <code class=\"literal\">ident</code>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/16/auth-username-maps.html\" title=\"21.2.\u00a0User Name Maps\">Section\u00a021.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc1413\">RFC 1413</a>. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/16/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "17": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 20.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "revision": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "catalog_fingerprint": "4bbe3ac77becd618478f66aec420a533e9017be356c5c1d51a4b17f0fd497c07"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "/docs/17/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 17 English manual", "sha256": "d9c733e47428f82317c7a703aa7136484f0a37ee600fc328a9ba1944dc9a051c"}, {"url": "/docs/17/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 17 English manual", "sha256": "00c7a7c25d46aa1b2f24cd744cd4990ca4218cfafed2a4cab8c1dc1092090bba"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.8.\u00a0Ident Authentication </h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/17/auth-peer.html\" title=\"20.9.\u00a0Peer Authentication\">Section\u00a020.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <code class=\"literal\">ident</code>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/17/auth-username-maps.html\" title=\"20.2.\u00a0User Name Maps\">Section\u00a020.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc1413\">RFC 1413</a>. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/17/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "18": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 20.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 18 English manual", "sha256": "14dd74aab7c9cfa7b89f8873f997df364d665097bb9be19146de6d2ea45eec7c"}, {"url": "/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.8.\u00a0Ident Authentication </h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/18/auth-peer.html\" title=\"20.9.\u00a0Peer Authentication\">Section\u00a020.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <code class=\"literal\">ident</code>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0User Name Maps\">Section\u00a020.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc1413\">RFC 1413</a>. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/18/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "19": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 20.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "revision": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "catalog_fingerprint": "62fbf1a3689dbe8bf7e6b3372cfe6fbf867581427b3858a94c8419b77a4d2d1d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "/docs/19/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 19 English manual", "sha256": "5fbf17eb2c3e8d5662e8f67e0bcfb04c90a52f288795709c67586bc96f1f9cdd"}, {"url": "/docs/19/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 19 English manual", "sha256": "d05e9155d5388148c2c680ff208b62c6b3b0b1c30f302ada5ab4befec36c19b7"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.8.\u00a0Ident Authentication </h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/19/auth-peer.html\" title=\"20.9.\u00a0Peer Authentication\">Section\u00a020.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <code class=\"literal\">ident</code>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/19/auth-username-maps.html\" title=\"20.2.\u00a0User Name Maps\">Section\u00a020.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc1413\">RFC 1413</a>. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/19/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "20": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 20.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "revision": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "catalog_fingerprint": "398fbb9f262264053c02fbf79f88be0a6770c1473faa6ecd5931d6ec41b8258b", "source_snapshot_utc": "26-Sep-2026 20:22"}, "sources": [{"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "/docs/devel/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 20 English manual", "sha256": "cafd634ef2c71e1eaf3c469621a5b0c0882f35360264c71707f0d6e908910ce2"}, {"url": "/docs/devel/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 20 English manual", "sha256": "cf2069461da3eec62f6fb4e3df8e46fd69ff4b3a2ad059eec355cee256d7996e"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.8.\u00a0Ident Authentication </h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/devel/auth-peer.html\" title=\"20.9.\u00a0Peer Authentication\">Section\u00a020.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <code class=\"literal\">ident</code>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/devel/auth-username-maps.html\" title=\"20.2.\u00a0User Name Maps\">Section\u00a020.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc1413\">RFC 1413</a>. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/devel/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}}}, "snapshot": {"facts": [{"label": "Method", "value": "ident"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "map", "description": "Allows for mapping between system and database user names. See Section 20.2 for details."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/auth-ident.html", "path": "auth-ident.html", "label": "PostgreSQL 18 English manual", "sha256": "14dd74aab7c9cfa7b89f8873f997df364d665097bb9be19146de6d2ea45eec7c"}, {"url": "/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9"}], "sections": [], "signature": "", "attributes": {"method": "ident", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-IDENT\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.8.\u00a0Ident Authentication </h2>\n</div>\n</div>\n</div>\n<p>The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When ident is specified for a local (non-TCP/IP) connection, peer authentication (see <a class=\"xref\" href=\"/docs/18/auth-peer.html\" title=\"20.9.\u00a0Peer Authentication\">Section\u00a020.9</a>) will be used instead.</p>\n</div>\n<p>The following configuration options are supported for <code class=\"literal\">ident</code>:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p>Allows for mapping between system and database user names. See <a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0User Name Maps\">Section\u00a020.2</a> for details.</p>\n</dd>\n</dl>\n</div>\n<p>The <span class=\"quote\">\u201c<span class=\"quote\">Identification Protocol</span>\u201d</span> is described in <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc1413\">RFC 1413</a>. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like <span class=\"quote\">\u201c<span class=\"quote\">What user initiated the connection that goes out of your port <em class=\"replaceable\"><code>X</code></em> and connects to my port <em class=\"replaceable\"><code>Y</code></em>?</span>\u201d</span>. Since <span class=\"productname\">PostgreSQL</span> knows both <em class=\"replaceable\"><code>X</code></em> and <em class=\"replaceable\"><code>Y</code></em> when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.</p>\n<p>The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:</p>\n<div class=\"blockquote\">\n<table class=\"blockquote\">\n<tbody><tr>\n<td>\u00a0</td>\n<td>\n<p>The Identification Protocol is not intended as an authorization or access control protocol.</p>\n</td>\n<td>\u00a0</td>\n</tr>\n<tr>\n<td>\u00a0</td>\n<td colspan=\"2\">--<span class=\"attribution\">RFC 1413</span></td>\n</tr>\n</tbody></table>\n</div>\n<p>Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option <span class=\"emphasis\"><em>must not</em></span> be used when using the ident server with <span class=\"productname\">PostgreSQL</span>, since <span class=\"productname\">PostgreSQL</span> does not have any way to decrypt the returned string to determine the actual user name.</p>\n</div>", "manual_path": "/docs/18/auth-ident.html", "comparison_data": {"method": "ident", "documented_option_names": ["map"]}, "comparison_hash": "1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0"}, "comparison": {"left": "17", "right": "18", "status": "unchanged", "diff": ""}}