{"kind": "auth", "major": "18", "item": {"slug": "ldap", "name": "ldap", "name_zh": "", "category": "Authentication and access control", "summary": "Authenticate using an LDAP server. See Section 20.10 for details.", "aliases": [], "content_hash": "ae824155a303611e373ba06485a3b0be060ce3d086a7d1e822b3206d1013ea1a", "versions": {"10": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. Note that this only encrypts the traffic to the LDAP server \u2014 the connection to the client will still be unencrypted unless SSL is used."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap:// host [: port ]/ basedn [?[ attribute ][?[ scope ]]] scope must be one of base , one , sub , typically the latter. Only one attribute is used, and some other components of standard LDAP URLs such as filters and extensions are not supported. For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. To use encrypted LDAP connections, the ldaptls option has to be used in addition to ldapurl . The ldaps URL scheme (direct SSL connection) is not supported. LDAP URLs are currently only supported with OpenLDAP, not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "10.23", "major": "10", "channel": "historical", "revision": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "catalog_fingerprint": "691be281b476dde4374d7f805b2bacc2e75bdef40f1e9d3d42e91f97fe95cfd0"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, {"url": "/docs/10/auth-methods.html#AUTH-LDAP", "path": "auth-methods.html", "label": "PostgreSQL 10 English manual", "sha256": "856d36a3fdfe8c45a25832e49bd07e9b7480f2ff9a33e58ac7c392630149bc34"}, {"url": "/docs/10/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 10 English manual", "sha256": "04fed609a50e8fd3013ffebb83039c544d39b6c73a6c2b2e23cd7864a70b42da"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 20.3.7 for details."], "manual_html": "<div class=\"sect2\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h3 class=\"title\">20.3.7.\u00a0LDAP Authentication</h3>\n</div>\n</div>\n</div>\n\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server disconnects and re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two separate connections to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. Note that this only encrypts the traffic to the LDAP server \u2014 the connection to the client will still be unencrypted unless SSL is used.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is</p>\n<pre class=\"synopsis\">ldap://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the latter. Only one attribute is used, and some other components of standard LDAP URLs such as filters and extensions are not supported.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>To use encrypted LDAP connections, the <code class=\"literal\">ldaptls</code> option has to be used in addition to <code class=\"literal\">ldapurl</code>. The <code class=\"literal\">ldaps</code> URL scheme (direct SSL connection) is not supported.</p>\n<p>LDAP URLs are currently only supported with OpenLDAP, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second connection succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/10/auth-methods.html#AUTH-LDAP", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapsearchattribute", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "2f2abb5d29b5bd848efcd20de05fe7fdbe01af244252da0a6b5e8de2ef2933fa"}, "11": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513. See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP, not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "11.22", "major": "11", "channel": "historical", "revision": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "catalog_fingerprint": "8f21f4444b7f68923f4762af0eb7937fa2907026e91249483e79050de012c901"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, {"url": "/docs/11/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 11 English manual", "sha256": "203b80156660ac4546cd1769ab2acc110aa9abf472688031309458a9798dd37a"}, {"url": "/docs/11/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 11 English manual", "sha256": "5477c61a002171f5b4c462052d91231c405f39d89d825faf71e52fbae358eef7"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 20.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.10.\u00a0LDAP Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server disconnects and re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two separate connections to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per RFC 4513. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with OpenLDAP, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second connection succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/11/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}, "12": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513. See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "12.22", "major": "12", "channel": "historical", "revision": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "catalog_fingerprint": "9f857f4ee4875f9c7de6bfc9df4b757dec8b3a0bb88eadb519c7bd267bd56149"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, {"url": "/docs/12/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 12 English manual", "sha256": "0fec6a76b2a86802531890638fe16dcb3f3ae4a4db04693296c29e67e5ddc908"}, {"url": "/docs/12/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 12 English manual", "sha256": "07e8cddcb38076c86dab95b72c4380a7a325f22401b5b7f9af5dd4931876f2cb"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 20.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.10.\u00a0LDAP Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server disconnects and re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two separate connections to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per RFC 4513. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with <span class=\"productname\">OpenLDAP</span>, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>If <span class=\"productname\">PostgreSQL</span> was compiled with <span class=\"productname\">OpenLDAP</span> as the LDAP client library, the <code class=\"literal\">ldapserver</code> setting may be omitted. In that case, a list of host names and ports is looked up via RFC 2782 DNS SRV records. The name <code class=\"literal\">_ldap._tcp.DOMAIN</code> is looked up, where <code class=\"literal\">DOMAIN</code> is extracted from <code class=\"literal\">ldapbasedn</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second connection succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p>Here is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name <code class=\"literal\">example.net</code>:</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/12/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}, "13": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513. See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "13.23", "major": "13", "channel": "historical", "revision": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "catalog_fingerprint": "c7015c845255c9d721c547c8ab9ef37825d332588c9691d982e6906b7d571002"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, {"url": "/docs/13/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 13 English manual", "sha256": "2190e53484a909337f45b923753b310a993d15b4a763b83113945d2192cd8351"}, {"url": "/docs/13/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 13 English manual", "sha256": "3cc6ce851945cba450e6b26ecf9cae1efd3c03fb7b55e17876f4d9ea418a7c2e"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 20.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.10.\u00a0LDAP Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server disconnects and re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two separate connections to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per RFC 4513. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with <span class=\"productname\">OpenLDAP</span>, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>If <span class=\"productname\">PostgreSQL</span> was compiled with <span class=\"productname\">OpenLDAP</span> as the LDAP client library, the <code class=\"literal\">ldapserver</code> setting may be omitted. In that case, a list of host names and ports is looked up via RFC 2782 DNS SRV records. The name <code class=\"literal\">_ldap._tcp.DOMAIN</code> is looked up, where <code class=\"literal\">DOMAIN</code> is extracted from <code class=\"literal\">ldapbasedn</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second connection succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p>Here is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name <code class=\"literal\">example.net</code>:</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/13/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}, "14": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "14.24", "major": "14", "channel": "stable", "revision": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "catalog_fingerprint": "b272e6a82e4c46efda81c3a6a4cdf7de6a83dfff7f02f226a392fbe9acdd3adb"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, {"url": "/docs/14/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 14 English manual", "sha256": "1e6edf4663135d54237da0efbc09280f32eae13c2c0e75ef29931356f244f440"}, {"url": "/docs/14/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 14 English manual", "sha256": "c9a75f04fd4a1069ea261ba061578a75c47a4b7e0bbf88761502fd4c19ccbc3f"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 21.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.10.\u00a0LDAP Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server disconnects and re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two separate connections to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4513\">RFC 4513</a>. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\">RFC 4516</a> LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with <span class=\"productname\">OpenLDAP</span>, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>If <span class=\"productname\">PostgreSQL</span> was compiled with <span class=\"productname\">OpenLDAP</span> as the LDAP client library, the <code class=\"literal\">ldapserver</code> setting may be omitted. In that case, a list of host names and ports is looked up via <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\">RFC 2782</a> DNS SRV records. The name <code class=\"literal\">_ldap._tcp.DOMAIN</code> is looked up, where <code class=\"literal\">DOMAIN</code> is extracted from <code class=\"literal\">ldapbasedn</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second connection succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p>Here is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name <code class=\"literal\">example.net</code>:</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/14/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}, "15": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "15.19", "major": "15", "channel": "stable", "revision": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "catalog_fingerprint": "fefe3c425147a86defada190c9b0663cfe02caa1724f5dede93e46457572252d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, {"url": "/docs/15/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 15 English manual", "sha256": "f355c23a666075dc2968875e229ebead4f0d113db4944f61a5ade70f5f496e9f"}, {"url": "/docs/15/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 15 English manual", "sha256": "0470cd3eeb82cbc32d4b8b79e29f4427bdfd01f5bb15e6d9b7cee2f6dd2bba44"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 21.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.10.\u00a0LDAP Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server disconnects and re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two separate connections to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4513\">RFC 4513</a>. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\">RFC 4516</a> LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with <span class=\"productname\">OpenLDAP</span>, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>If <span class=\"productname\">PostgreSQL</span> was compiled with <span class=\"productname\">OpenLDAP</span> as the LDAP client library, the <code class=\"literal\">ldapserver</code> setting may be omitted. In that case, a list of host names and ports is looked up via <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\">RFC 2782</a> DNS SRV records. The name <code class=\"literal\">_ldap._tcp.DOMAIN</code> is looked up, where <code class=\"literal\">DOMAIN</code> is extracted from <code class=\"literal\">ldapbasedn</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second connection succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p>Here is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name <code class=\"literal\">example.net</code>:</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/15/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}, "16": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "16.15", "major": "16", "channel": "stable", "revision": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "catalog_fingerprint": "fa133458dc8f52e15083b4f59b7a582e2e378b608d3ac5c53054df458a374e23"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, {"url": "/docs/16/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 16 English manual", "sha256": "dd667e5c2ce6cb14df859d3da34720144c888a8f3b8d443d789343e538c5e94a"}, {"url": "/docs/16/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 16 English manual", "sha256": "ccc5146375a184646d5992edbc693e12c0de4431a35141d6b56c8dd6b3c52132"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 21.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.10.\u00a0LDAP Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server disconnects and re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two separate connections to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4513\">RFC 4513</a>. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\">RFC 4516</a> LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with <span class=\"productname\">OpenLDAP</span>, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>If <span class=\"productname\">PostgreSQL</span> was compiled with <span class=\"productname\">OpenLDAP</span> as the LDAP client library, the <code class=\"literal\">ldapserver</code> setting may be omitted. In that case, a list of host names and ports is looked up via <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\">RFC 2782</a> DNS SRV records. The name <code class=\"literal\">_ldap._tcp.DOMAIN</code> is looked up, where <code class=\"literal\">DOMAIN</code> is extracted from <code class=\"literal\">ldapbasedn</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second connection succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p>Here is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name <code class=\"literal\">example.net</code>:</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/16/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}, "17": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "revision": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "catalog_fingerprint": "4bbe3ac77becd618478f66aec420a533e9017be356c5c1d51a4b17f0fd497c07"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "/docs/17/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 17 English manual", "sha256": "1d4c4c0be025c634cba458a751de54b97831a71c8380adc23d7c02c75c855a59"}, {"url": "/docs/17/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 17 English manual", "sha256": "00c7a7c25d46aa1b2f24cd744cd4990ca4218cfafed2a4cab8c1dc1092090bba"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 20.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.10.\u00a0LDAP Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two additional requests to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4513\">RFC 4513</a>. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\">RFC 4516</a> LDAP URL. This is an alternative way to write some of the other LDAP options in a more compact and standard form. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with <span class=\"productname\">OpenLDAP</span>, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>If <span class=\"productname\">PostgreSQL</span> was compiled with <span class=\"productname\">OpenLDAP</span> as the LDAP client library, the <code class=\"literal\">ldapserver</code> setting may be omitted. In that case, a list of host names and ports is looked up via <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\">RFC 2782</a> DNS SRV records. The name <code class=\"literal\">_ldap._tcp.DOMAIN</code> is looked up, where <code class=\"literal\">DOMAIN</code> is extracted from <code class=\"literal\">ldapbasedn</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second bind succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p>Here is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name <code class=\"literal\">example.net</code>:</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/17/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}, "18": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 18 English manual", "sha256": "8f02f50758b63b0d9a9011b2c3c1ee12e8caa3830408f5ea5d97e0e81ee52628"}, {"url": "/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 20.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.10.\u00a0LDAP Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two additional requests to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4513\">RFC 4513</a>. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n</dl>\n</div>\n<p>The following option may be used as an alternative way to write some of the above LDAP options in a more compact and standard form:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\">RFC 4516</a> LDAP URL. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with <span class=\"productname\">OpenLDAP</span>, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind. To use <code class=\"literal\">ldapurl</code> in simple bind mode, the URL must not contain a <code class=\"literal\">basedn</code> or query elements.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>If <span class=\"productname\">PostgreSQL</span> was compiled with <span class=\"productname\">OpenLDAP</span> as the LDAP client library, the <code class=\"literal\">ldapserver</code> setting may be omitted. In that case, a list of host names and ports is looked up via <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\">RFC 2782</a> DNS SRV records. The name <code class=\"literal\">_ldap._tcp.DOMAIN</code> is looked up, where <code class=\"literal\">DOMAIN</code> is extracted from <code class=\"literal\">ldapbasedn</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is a different simple-bind configuration, which uses the LDAPS scheme and a custom port number, written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldaps://ldap.example.net:49151\" ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>This is slightly more compact than specifying <code class=\"literal\">ldapserver</code>, <code class=\"literal\">ldapscheme</code>, and <code class=\"literal\">ldapport</code> separately.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second bind succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p>Here is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name <code class=\"literal\">example.net</code>:</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/18/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}, "19": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "revision": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "catalog_fingerprint": "62fbf1a3689dbe8bf7e6b3372cfe6fbf867581427b3858a94c8419b77a4d2d1d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "/docs/19/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 19 English manual", "sha256": "e7f0c5ec2b27f9479614d22f87ffeca99e87ae03e00f0f7ffcb78e2e9df84b3d"}, {"url": "/docs/19/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 19 English manual", "sha256": "d05e9155d5388148c2c680ff208b62c6b3b0b1c30f302ada5ab4befec36c19b7"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 20.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.10.\u00a0LDAP Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two additional requests to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4513\">RFC 4513</a>. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n</dl>\n</div>\n<p>The following option may be used as an alternative way to write some of the above LDAP options in a more compact and standard form:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\">RFC 4516</a> LDAP URL. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with <span class=\"productname\">OpenLDAP</span>, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind. To use <code class=\"literal\">ldapurl</code> in simple bind mode, the URL must not contain a <code class=\"literal\">basedn</code> or query elements.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>If <span class=\"productname\">PostgreSQL</span> was compiled with <span class=\"productname\">OpenLDAP</span> as the LDAP client library, the <code class=\"literal\">ldapserver</code> setting may be omitted. In that case, a list of host names and ports is looked up via <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\">RFC 2782</a> DNS SRV records. The name <code class=\"literal\">_ldap._tcp.DOMAIN</code> is looked up, where <code class=\"literal\">DOMAIN</code> is extracted from <code class=\"literal\">ldapbasedn</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is a different simple-bind configuration, which uses the LDAPS scheme and a custom port number, written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldaps://ldap.example.net:49151\" ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>This is slightly more compact than specifying <code class=\"literal\">ldapserver</code>, <code class=\"literal\">ldapscheme</code>, and <code class=\"literal\">ldapport</code> separately.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second bind succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p>Here is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name <code class=\"literal\">example.net</code>:</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/19/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}, "20": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "revision": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "catalog_fingerprint": "398fbb9f262264053c02fbf79f88be0a6770c1473faa6ecd5931d6ec41b8258b", "source_snapshot_utc": "26-Sep-2026 20:22"}, "sources": [{"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "/docs/devel/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 20 English manual", "sha256": "456fc2af52e32b229e6251f4107c0a1bc9e4c991485386042a521112407eb56e"}, {"url": "/docs/devel/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 20 English manual", "sha256": "cf2069461da3eec62f6fb4e3df8e46fd69ff4b3a2ad059eec355cee256d7996e"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 20.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.10.\u00a0LDAP Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two additional requests to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4513\">RFC 4513</a>. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n</dl>\n</div>\n<p>The following option may be used as an alternative way to write some of the above LDAP options in a more compact and standard form:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\">RFC 4516</a> LDAP URL. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with <span class=\"productname\">OpenLDAP</span>, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind. To use <code class=\"literal\">ldapurl</code> in simple bind mode, the URL must not contain a <code class=\"literal\">basedn</code> or query elements.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>If <span class=\"productname\">PostgreSQL</span> was compiled with <span class=\"productname\">OpenLDAP</span> as the LDAP client library, the <code class=\"literal\">ldapserver</code> setting may be omitted. In that case, a list of host names and ports is looked up via <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\">RFC 2782</a> DNS SRV records. The name <code class=\"literal\">_ldap._tcp.DOMAIN</code> is looked up, where <code class=\"literal\">DOMAIN</code> is extracted from <code class=\"literal\">ldapbasedn</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is a different simple-bind configuration, which uses the LDAPS scheme and a custom port number, written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldaps://ldap.example.net:49151\" ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>This is slightly more compact than specifying <code class=\"literal\">ldapserver</code>, <code class=\"literal\">ldapscheme</code>, and <code class=\"literal\">ldapport</code> separately.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second bind succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p>Here is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name <code class=\"literal\">example.net</code>:</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/devel/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}}}, "snapshot": {"facts": [{"label": "Method", "value": "ldap"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "ldapserver", "description": "Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces."}, {"name": "ldapport", "description": "Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used."}, {"name": "ldapscheme", "description": "Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative."}, {"name": "ldaptls", "description": "Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative."}, {"name": "ldapprefix", "description": "String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapsuffix", "description": "String to append to the user name when forming the DN to bind as, when doing simple bind authentication."}, {"name": "ldapbasedn", "description": "Root DN to begin the search for the user in, when doing search+bind authentication."}, {"name": "ldapbinddn", "description": "DN of user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapbindpasswd", "description": "Password for user to bind to the directory with to perform the search when doing search+bind authentication."}, {"name": "ldapsearchattribute", "description": "Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used."}, {"name": "ldapsearchfilter", "description": "The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute ."}, {"name": "ldapurl", "description": "An RFC 4516 LDAP URL. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/auth-ldap.html", "path": "auth-ldap.html", "label": "PostgreSQL 18 English manual", "sha256": "8f02f50758b63b0d9a9011b2c3c1ee12e8caa3830408f5ea5d97e0e81ee52628"}, {"url": "/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9"}], "sections": [], "signature": "", "attributes": {"method": "ldap", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using an LDAP server. See Section 20.10 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-LDAP\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.10.\u00a0LDAP Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.</p>\n<p>LDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as <em class=\"replaceable\"><code>prefix</code></em> <em class=\"replaceable\"><code>username</code></em> <em class=\"replaceable\"><code>suffix</code></em>. Typically, the <em class=\"replaceable\"><code>prefix</code></em> parameter is used to specify <code class=\"literal\">cn=</code>, or <em class=\"replaceable\"><code>DOMAIN</code></em><code class=\"literal\">\\</code> in an Active Directory environment. <em class=\"replaceable\"><code>suffix</code></em> is used to specify the remaining part of the DN in a non-Active Directory environment.</p>\n<p>In the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with <em class=\"replaceable\"><code>ldapbinddn</code></em> and <em class=\"replaceable\"><code>ldapbindpasswd</code></em>, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at <em class=\"replaceable\"><code>ldapbasedn</code></em>, and will try to do an exact match of the attribute specified in <em class=\"replaceable\"><code>ldapsearchattribute</code></em>. Once the user has been found in this search, the server re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache <code class=\"literal\">mod_authnz_ldap</code> and <code class=\"literal\">pam_ldap</code>. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two additional requests to the LDAP server to be made.</p>\n<p>The following configuration options are used in both modes:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapserver</code></span></dt>\n<dd>\n<p>Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapport</code></span></dt>\n<dd>\n<p>Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapscheme</code></span></dt>\n<dd>\n<p>Set to <code class=\"literal\">ldaps</code> to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the <code class=\"literal\">ldaptls</code> option for an alternative.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldaptls</code></span></dt>\n<dd>\n<p>Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the <code class=\"literal\">StartTLS</code> operation per <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4513\">RFC 4513</a>. See also the <code class=\"literal\">ldapscheme</code> option for an alternative.</p>\n</dd>\n</dl>\n</div>\n<p>Note that using <code class=\"literal\">ldapscheme</code> or <code class=\"literal\">ldaptls</code> only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.</p>\n<p>The following options are used in simple bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapprefix</code></span></dt>\n<dd>\n<p>String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsuffix</code></span></dt>\n<dd>\n<p>String to append to the user name when forming the DN to bind as, when doing simple bind authentication.</p>\n</dd>\n</dl>\n</div>\n<p>The following options are used in search+bind mode only:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapbasedn</code></span></dt>\n<dd>\n<p>Root DN to begin the search for the user in, when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbinddn</code></span></dt>\n<dd>\n<p>DN of user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapbindpasswd</code></span></dt>\n<dd>\n<p>Password for user to bind to the directory with to perform the search when doing search+bind authentication.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchattribute</code></span></dt>\n<dd>\n<p>Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the <code class=\"literal\">uid</code> attribute will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">ldapsearchfilter</code></span></dt>\n<dd>\n<p>The search filter to use when doing search+bind authentication. Occurrences of <code class=\"literal\">$username</code> will be replaced with the user name. This allows for more flexible search filters than <code class=\"literal\">ldapsearchattribute</code>.</p>\n</dd>\n</dl>\n</div>\n<p>The following option may be used as an alternative way to write some of the above LDAP options in a more compact and standard form:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">ldapurl</code></span></dt>\n<dd>\n<p>An <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\">RFC 4516</a> LDAP URL. The format is</p>\n<pre class=\"synopsis\">ldap[s]://<em class=\"replaceable\"><code>host</code></em>[:<em class=\"replaceable\"><code>port</code></em>]/<em class=\"replaceable\"><code>basedn</code></em>[?[<em class=\"replaceable\"><code>attribute</code></em>][?[<em class=\"replaceable\"><code>scope</code></em>][?[<em class=\"replaceable\"><code>filter</code></em>]]]]\n</pre>\n<p><em class=\"replaceable\"><code>scope</code></em> must be one of <code class=\"literal\">base</code>, <code class=\"literal\">one</code>, <code class=\"literal\">sub</code>, typically the last. (The default is <code class=\"literal\">base</code>, which is normally not useful in this application.) <em class=\"replaceable\"><code>attribute</code></em> can nominate a single attribute, in which case it is used as a value for <code class=\"literal\">ldapsearchattribute</code>. If <em class=\"replaceable\"><code>attribute</code></em> is empty then <em class=\"replaceable\"><code>filter</code></em> can be used as a value for <code class=\"literal\">ldapsearchfilter</code>.</p>\n<p>The URL scheme <code class=\"literal\">ldaps</code> chooses the LDAPS method for making LDAP connections over SSL, equivalent to using <code class=\"literal\">ldapscheme=ldaps</code>. To use encrypted LDAP connections using the <code class=\"literal\">StartTLS</code> operation, use the normal URL scheme <code class=\"literal\">ldap</code> and specify the <code class=\"literal\">ldaptls</code> option in addition to <code class=\"literal\">ldapurl</code>.</p>\n<p>For non-anonymous binds, <code class=\"literal\">ldapbinddn</code> and <code class=\"literal\">ldapbindpasswd</code> must be specified as separate options.</p>\n<p>LDAP URLs are currently only supported with <span class=\"productname\">OpenLDAP</span>, not on Windows.</p>\n</dd>\n</dl>\n</div>\n<p>It is an error to mix configuration options for simple bind with options for search+bind. To use <code class=\"literal\">ldapurl</code> in simple bind mode, the URL must not contain a <code class=\"literal\">basedn</code> or query elements.</p>\n<p>When using search+bind mode, the search can be performed using a single attribute specified with <code class=\"literal\">ldapsearchattribute</code>, or using a custom search filter specified with <code class=\"literal\">ldapsearchfilter</code>. Specifying <code class=\"literal\">ldapsearchattribute=foo</code> is equivalent to specifying <code class=\"literal\">ldapsearchfilter=\"(foo=$username)\"</code>. If neither option is specified the default is <code class=\"literal\">ldapsearchattribute=uid</code>.</p>\n<p>If <span class=\"productname\">PostgreSQL</span> was compiled with <span class=\"productname\">OpenLDAP</span> as the LDAP client library, the <code class=\"literal\">ldapserver</code> setting may be omitted. In that case, a list of host names and ports is looked up via <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\">RFC 2782</a> DNS SRV records. The name <code class=\"literal\">_ldap._tcp.DOMAIN</code> is looked up, where <code class=\"literal\">DOMAIN</code> is extracted from <code class=\"literal\">ldapbasedn</code>.</p>\n<p>Here is an example for a simple-bind LDAP configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind to the LDAP server using the DN <code class=\"literal\">cn=someuser, dc=example, dc=net</code> and the password provided by the client. If that connection succeeds, the database access is granted.</p>\n<p>Here is a different simple-bind configuration, which uses the LDAPS scheme and a custom port number, written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldaps://ldap.example.net:49151\" ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n</pre>\n<p>This is slightly more compact than specifying <code class=\"literal\">ldapserver</code>, <code class=\"literal\">ldapscheme</code>, and <code class=\"literal\">ldapport</code> separately.</p>\n<p>Here is an example for a search+bind configuration:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n</pre>\n<p>When a connection to the database server as database user <code class=\"literal\">someuser</code> is requested, PostgreSQL will attempt to bind anonymously (since <code class=\"literal\">ldapbinddn</code> was not specified) to the LDAP server, perform a search for <code class=\"literal\">(uid=someuser)</code> under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second bind succeeds, the database access is granted.</p>\n<p>Here is the same search+bind configuration written as a URL:</p>\n<pre class=\"programlisting\">host ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n</pre>\n<p>Some other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.</p>\n<p>Here is an example for a search+bind configuration that uses <code class=\"literal\">ldapsearchfilter</code> instead of <code class=\"literal\">ldapsearchattribute</code> to allow authentication by user ID or email address:</p>\n<pre class=\"programlisting\">host ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n</pre>\n<p>Here is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name <code class=\"literal\">example.net</code>:</p>\n<pre class=\"programlisting\">host ... ldap ldapbasedn=\"dc=example,dc=net\"\n</pre>\n<div class=\"tip\">\n<h3 class=\"title\">Tip</h3>\n<p>Since LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.</p>\n</div>\n</div>", "manual_path": "/docs/18/auth-ldap.html", "comparison_data": {"method": "ldap", "documented_option_names": ["ldapbasedn", "ldapbinddn", "ldapbindpasswd", "ldapport", "ldapprefix", "ldapscheme", "ldapsearchattribute", "ldapsearchfilter", "ldapserver", "ldapsuffix", "ldaptls", "ldapurl"]}, "comparison_hash": "d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88"}, "comparison": {"left": "17", "right": "18", "status": "unchanged", "diff": ""}}