Wiki / Authentication Methods / Authentication and access control
pam
Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details.
Reading PostgreSQL 18.6.
Description
Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details.
- Method
- pam
- Configuration
- pg_hba.conf
- Inventory
- User-visible source authentication method
Documented method options and alternatives
| Option or term | Meaning |
|---|---|
| pamservice | PAM service name. |
| pam_use_hostname | Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.) |
Manual definition
20.13. PAM Authentication
This authentication method operates similarly to password except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is postgresql. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the Linux-PAM Page.
The following configuration options are supported for PAM:
pamservice-
PAM service name.
pam_use_hostname-
Determines whether the remote IP address or the host name is provided to PAM modules through the
PAM_RHOSTitem. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)
Note
If PAM is set up to read /etc/shadow, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.
Documentation and source
Source build
- Version
- 18.6
- Build
- https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
- Source fingerprint
555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f
Compare versions
PostgreSQL 17 → 18: unchanged.
Compares recorded interfaces and attributes. Source fingerprints and build metadata are excluded; an absent sample is not proof of the introduction or removal release.
Related entries
Export JSON · Back to Authentication Methods · Recorded in PostgreSQL 10 through 20; the first sample is not necessarily its introduction.