{"kind": "auth", "major": "18", "item": {"slug": "pam", "name": "pam", "name_zh": "", "category": "Authentication and access control", "summary": "Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details.", "aliases": [], "content_hash": "fc4ee79fad90c2894ddaa032799b7c487c9aa9c6c4cc6468635da2ba85f2f652", "versions": {"10": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "10.23", "major": "10", "channel": "historical", "revision": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "catalog_fingerprint": "691be281b476dde4374d7f805b2bacc2e75bdef40f1e9d3d42e91f97fe95cfd0"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, {"url": "/docs/10/auth-methods.html#AUTH-PAM", "path": "auth-methods.html", "label": "PostgreSQL 10 English manual", "sha256": "856d36a3fdfe8c45a25832e49bd07e9b7480f2ff9a33e58ac7c392630149bc34"}, {"url": "/docs/10/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 10 English manual", "sha256": "04fed609a50e8fd3013ffebb83039c544d39b6c73a6c2b2e23cd7864a70b42da"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.3.10 for details."], "manual_html": "<div class=\"sect2\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h3 class=\"title\">20.3.10.\u00a0PAM Authentication</h3>\n</div>\n</div>\n</div>\n\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"http://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/10/auth-methods.html#AUTH-PAM", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "11": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "11.22", "major": "11", "channel": "historical", "revision": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "catalog_fingerprint": "8f21f4444b7f68923f4762af0eb7937fa2907026e91249483e79050de012c901"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, {"url": "/docs/11/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 11 English manual", "sha256": "4699f3844bb3b6beddec19f7307959c823d564edab59e0aa73310253e5286cd7"}, {"url": "/docs/11/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 11 English manual", "sha256": "5477c61a002171f5b4c462052d91231c405f39d89d825faf71e52fbae358eef7"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.13.\u00a0PAM Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/11/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "12": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "12.22", "major": "12", "channel": "historical", "revision": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "catalog_fingerprint": "9f857f4ee4875f9c7de6bfc9df4b757dec8b3a0bb88eadb519c7bd267bd56149"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, {"url": "/docs/12/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 12 English manual", "sha256": "06e22525f31c4224e6bf457c65950426ce0d5d986673cacb379bd5aacabfec78"}, {"url": "/docs/12/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 12 English manual", "sha256": "07e8cddcb38076c86dab95b72c4380a7a325f22401b5b7f9af5dd4931876f2cb"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.13.\u00a0PAM Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/12/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "13": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "13.23", "major": "13", "channel": "historical", "revision": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "catalog_fingerprint": "c7015c845255c9d721c547c8ab9ef37825d332588c9691d982e6906b7d571002"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, {"url": "/docs/13/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 13 English manual", "sha256": "cefb868a1bdbe727e7811134f967c483ef24c1a45f0ef678fafca981659f4ccd"}, {"url": "/docs/13/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 13 English manual", "sha256": "3cc6ce851945cba450e6b26ecf9cae1efd3c03fb7b55e17876f4d9ea418a7c2e"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.13.\u00a0PAM Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/13/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "14": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "14.24", "major": "14", "channel": "stable", "revision": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "catalog_fingerprint": "b272e6a82e4c46efda81c3a6a4cdf7de6a83dfff7f02f226a392fbe9acdd3adb"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, {"url": "/docs/14/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 14 English manual", "sha256": "7049c58318701dc26567e24d487d9399d6b7190edd824e20efda5ba18eac70cf"}, {"url": "/docs/14/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 14 English manual", "sha256": "c9a75f04fd4a1069ea261ba061578a75c47a4b7e0bbf88761502fd4c19ccbc3f"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 21.13 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.13.\u00a0PAM Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/14/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "15": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "15.19", "major": "15", "channel": "stable", "revision": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "catalog_fingerprint": "fefe3c425147a86defada190c9b0663cfe02caa1724f5dede93e46457572252d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, {"url": "/docs/15/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 15 English manual", "sha256": "39ab36fb316e8a1750ffb77e8bb895fe45ea2ee889cc745d21e8b1b97de6ada9"}, {"url": "/docs/15/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 15 English manual", "sha256": "0470cd3eeb82cbc32d4b8b79e29f4427bdfd01f5bb15e6d9b7cee2f6dd2bba44"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 21.13 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.13.\u00a0PAM Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/15/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "16": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "16.15", "major": "16", "channel": "stable", "revision": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "catalog_fingerprint": "fa133458dc8f52e15083b4f59b7a582e2e378b608d3ac5c53054df458a374e23"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, {"url": "/docs/16/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 16 English manual", "sha256": "bbde6bf1671253771d9749d75590d9291beba57eab51c56a98ae77f3649964a9"}, {"url": "/docs/16/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 16 English manual", "sha256": "ccc5146375a184646d5992edbc693e12c0de4431a35141d6b56c8dd6b3c52132"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 21.13 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.13.\u00a0PAM Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/16/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "17": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "revision": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "catalog_fingerprint": "4bbe3ac77becd618478f66aec420a533e9017be356c5c1d51a4b17f0fd497c07"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "/docs/17/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 17 English manual", "sha256": "8c47f249a956294a371ea0ed80b4826dcc39cd0d326e0ab516ec6c5008bb1f16"}, {"url": "/docs/17/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 17 English manual", "sha256": "00c7a7c25d46aa1b2f24cd744cd4990ca4218cfafed2a4cab8c1dc1092090bba"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.13.\u00a0PAM Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/17/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "18": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 18 English manual", "sha256": "e3d0a0d5ecb652f5534d7f62574b323d77436acd258b10a17a359873c1edf8d8"}, {"url": "/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.13.\u00a0PAM Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/18/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "19": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "revision": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "catalog_fingerprint": "62fbf1a3689dbe8bf7e6b3372cfe6fbf867581427b3858a94c8419b77a4d2d1d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "/docs/19/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 19 English manual", "sha256": "0b7b7f6fad787ed02a3ff88dbe02e3a0ad6ca6bb0082a40bcb23d32ed165d84f"}, {"url": "/docs/19/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 19 English manual", "sha256": "d05e9155d5388148c2c680ff208b62c6b3b0b1c30f302ada5ab4befec36c19b7"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.12 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.12.\u00a0PAM Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/19/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "20": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "revision": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "catalog_fingerprint": "398fbb9f262264053c02fbf79f88be0a6770c1473faa6ecd5931d6ec41b8258b", "source_snapshot_utc": "26-Sep-2026 20:22"}, "sources": [{"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "/docs/devel/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 20 English manual", "sha256": "353faa962be969ab84b21f18363e636308553bcbec7f512959fc34aa0260c6da"}, {"url": "/docs/devel/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 20 English manual", "sha256": "cf2069461da3eec62f6fb4e3df8e46fd69ff4b3a2ad059eec355cee256d7996e"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.12 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.12.\u00a0PAM Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/devel/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}}}, "snapshot": {"facts": [{"label": "Method", "value": "pam"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "pamservice", "description": "PAM service name."}, {"name": "pam_use_hostname", "description": "Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)"}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/auth-pam.html", "path": "auth-pam.html", "label": "PostgreSQL 18 English manual", "sha256": "e3d0a0d5ecb652f5534d7f62574b323d77436acd258b10a17a359873c1edf8d8"}, {"url": "/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9"}], "sections": [], "signature": "", "attributes": {"method": "pam", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-PAM\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.13.\u00a0PAM Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is <code class=\"literal\">postgresql</code>. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the <a class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"><span class=\"productname\">Linux-PAM</span> Page</a>.</p>\n<p>The following configuration options are supported for PAM:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">pamservice</code></span></dt>\n<dd>\n<p>PAM service name.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">pam_use_hostname</code></span></dt>\n<dd>\n<p>Determines whether the remote IP address or the host name is provided to PAM modules through the <code class=\"symbol\">PAM_RHOST</code> item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>If PAM is set up to read <code class=\"filename\">/etc/shadow</code>, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.</p>\n</div>\n</div>", "manual_path": "/docs/18/auth-pam.html", "comparison_data": {"method": "pam", "documented_option_names": ["pam_use_hostname", "pamservice"]}, "comparison_hash": "e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741"}, "comparison": {"left": "17", "right": "18", "status": "unchanged", "diff": ""}}