{"kind": "auth", "major": "18", "item": {"slug": "radius", "name": "radius", "name_zh": "", "category": "Authentication and access control", "summary": "Authenticate using a RADIUS server. See Section 20.11 for details.", "aliases": [], "content_hash": "5cc4b8389a7a6af91c11f643a942a97c92f95656c2a88a4443b205854c0b3bbb", "versions": {"10": {"facts": [{"label": "Method", "value": "radius"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "radiusservers", "description": "The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required."}, {"name": "radiussecrets", "description": "The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required. Note The encryption vector used will only be cryptographically strong if PostgreSQL is built with support for OpenSSL . In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary."}, {"name": "radiusports", "description": "The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port ( 1812 ) will be used."}, {"name": "radiusidentifiers", "description": "The strings to be used as NAS Identifier in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default postgresql will be used."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "10.23", "major": "10", "channel": "historical", "revision": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "catalog_fingerprint": "691be281b476dde4374d7f805b2bacc2e75bdef40f1e9d3d42e91f97fe95cfd0"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, {"url": "/docs/10/auth-methods.html#AUTH-RADIUS", "path": "auth-methods.html", "label": "PostgreSQL 10 English manual", "sha256": "856d36a3fdfe8c45a25832e49bd07e9b7480f2ff9a33e58ac7c392630149bc34"}, {"url": "/docs/10/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 10 English manual", "sha256": "04fed609a50e8fd3013ffebb83039c544d39b6c73a6c2b2e23cd7864a70b42da"}], "sections": [], "signature": "", "attributes": {"method": "radius", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using a RADIUS server. See Section 20.3.8 for details."], "manual_html": "<div class=\"sect2\" id=\"AUTH-RADIUS\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h3 class=\"title\">20.3.8.\u00a0RADIUS Authentication</h3>\n</div>\n</div>\n</div>\n\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses RADIUS as the password verification method. RADIUS is used only to validate the user name/password pairs. Therefore the user must already exist in the database before RADIUS can be used for authentication.</p>\n<p>When using RADIUS authentication, an Access Request message will be sent to the configured RADIUS server. This request will be of type <code class=\"literal\">Authenticate Only</code>, and include parameters for <code class=\"literal\">user name</code>, <code class=\"literal\">password</code> (encrypted) and <code class=\"literal\">NAS Identifier</code>. The request will be encrypted using a secret shared with the server. The RADIUS server will respond to this request with either <code class=\"literal\">Access Accept</code> or <code class=\"literal\">Access Reject</code>. There is no support for RADIUS accounting.</p>\n<p>Multiple RADIUS servers can be specified, in which case they will be tried sequentially. If a negative response is received from a server, the authentication will fail. If no response is received, the next server in the list will be tried. To specify multiple servers, separate the server names with commas and surround the list with double quotes. If multiple servers are specified, the other RADIUS options can also be given as comma-separated lists, to provide individual values for each server. They can also be specified as a single value, in which case that value will apply to all servers.</p>\n<p>The following configuration options are supported for RADIUS:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">radiusservers</code></span></dt>\n<dd>\n<p>The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiussecrets</code></span></dt>\n<dd>\n<p>The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>The encryption vector used will only be cryptographically strong if <span class=\"productname\">PostgreSQL</span> is built with support for <span class=\"productname\">OpenSSL</span>. In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary.</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusports</code></span></dt>\n<dd>\n<p>The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port (<code class=\"literal\">1812</code>) will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusidentifiers</code></span></dt>\n<dd>\n<p>The strings to be used as <code class=\"literal\">NAS Identifier</code> in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default <code class=\"literal\">postgresql</code> will be used.</p>\n</dd>\n</dl>\n</div>\n<p>If it is necessary to have a comma or whitespace in a RADIUS parameter value, that can be done by putting double quotes around the value, but it is tedious because two layers of double-quoting are now required. An example of putting whitespace into RADIUS secret strings is:</p>\n<pre class=\"programlisting\">host ... radius radiusservers=\"server1,server2\" radiussecrets=\"\"\"secret one\"\",\"\"secret two\"\"\"\n</pre></div>", "manual_path": "/docs/10/auth-methods.html#AUTH-RADIUS", "comparison_data": {"method": "radius", "documented_option_names": ["radiusidentifiers", "radiusports", "radiussecrets", "radiusservers"]}, "comparison_hash": "084932634de939bfac07ac9c692a7d4dd0c6593c73dd494f2f0ccbad15d6f1a4"}, "11": {"facts": [{"label": "Method", "value": "radius"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "radiusservers", "description": "The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required."}, {"name": "radiussecrets", "description": "The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required. Note The encryption vector used will only be cryptographically strong if PostgreSQL is built with support for OpenSSL . In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary."}, {"name": "radiusports", "description": "The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port ( 1812 ) will be used."}, {"name": "radiusidentifiers", "description": "The strings to be used as NAS Identifier in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default postgresql will be used."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "11.22", "major": "11", "channel": "historical", "revision": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "catalog_fingerprint": "8f21f4444b7f68923f4762af0eb7937fa2907026e91249483e79050de012c901"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, {"url": "/docs/11/auth-radius.html", "path": "auth-radius.html", "label": "PostgreSQL 11 English manual", "sha256": "69a32a9d89ec8d7e57227f97390cd5c9042c3bc0ef4ee3e73d0892d3ffad7e37"}, {"url": "/docs/11/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 11 English manual", "sha256": "5477c61a002171f5b4c462052d91231c405f39d89d825faf71e52fbae358eef7"}], "sections": [], "signature": "", "attributes": {"method": "radius", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using a RADIUS server. See Section 20.11 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-RADIUS\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.11.\u00a0RADIUS Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses RADIUS as the password verification method. RADIUS is used only to validate the user name/password pairs. Therefore the user must already exist in the database before RADIUS can be used for authentication.</p>\n<p>When using RADIUS authentication, an Access Request message will be sent to the configured RADIUS server. This request will be of type <code class=\"literal\">Authenticate Only</code>, and include parameters for <code class=\"literal\">user name</code>, <code class=\"literal\">password</code> (encrypted) and <code class=\"literal\">NAS Identifier</code>. The request will be encrypted using a secret shared with the server. The RADIUS server will respond to this request with either <code class=\"literal\">Access Accept</code> or <code class=\"literal\">Access Reject</code>. There is no support for RADIUS accounting.</p>\n<p>Multiple RADIUS servers can be specified, in which case they will be tried sequentially. If a negative response is received from a server, the authentication will fail. If no response is received, the next server in the list will be tried. To specify multiple servers, separate the server names with commas and surround the list with double quotes. If multiple servers are specified, the other RADIUS options can also be given as comma-separated lists, to provide individual values for each server. They can also be specified as a single value, in which case that value will apply to all servers.</p>\n<p>The following configuration options are supported for RADIUS:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">radiusservers</code></span></dt>\n<dd>\n<p>The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiussecrets</code></span></dt>\n<dd>\n<p>The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>The encryption vector used will only be cryptographically strong if <span class=\"productname\">PostgreSQL</span> is built with support for <span class=\"productname\">OpenSSL</span>. In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary.</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusports</code></span></dt>\n<dd>\n<p>The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port (<code class=\"literal\">1812</code>) will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusidentifiers</code></span></dt>\n<dd>\n<p>The strings to be used as <code class=\"literal\">NAS Identifier</code> in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default <code class=\"literal\">postgresql</code> will be used.</p>\n</dd>\n</dl>\n</div>\n<p>If it is necessary to have a comma or whitespace in a RADIUS parameter value, that can be done by putting double quotes around the value, but it is tedious because two layers of double-quoting are now required. An example of putting whitespace into RADIUS secret strings is:</p>\n<pre class=\"programlisting\">host ... radius radiusservers=\"server1,server2\" radiussecrets=\"\"\"secret one\"\",\"\"secret two\"\"\"\n</pre>\n</div>", "manual_path": "/docs/11/auth-radius.html", "comparison_data": {"method": "radius", "documented_option_names": ["radiusidentifiers", "radiusports", "radiussecrets", "radiusservers"]}, "comparison_hash": "084932634de939bfac07ac9c692a7d4dd0c6593c73dd494f2f0ccbad15d6f1a4"}, "12": {"facts": [{"label": "Method", "value": "radius"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "radiusservers", "description": "The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required."}, {"name": "radiussecrets", "description": "The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required. Note The encryption vector used will only be cryptographically strong if PostgreSQL is built with support for OpenSSL . In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary."}, {"name": "radiusports", "description": "The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port ( 1812 ) will be used."}, {"name": "radiusidentifiers", "description": "The strings to be used as NAS Identifier in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default postgresql will be used."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "12.22", "major": "12", "channel": "historical", "revision": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "catalog_fingerprint": "9f857f4ee4875f9c7de6bfc9df4b757dec8b3a0bb88eadb519c7bd267bd56149"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, {"url": "/docs/12/auth-radius.html", "path": "auth-radius.html", "label": "PostgreSQL 12 English manual", "sha256": "129f40ba492bdcb60f299d868dd5daa754ad966369c3f0d07ae1bbd9946b71c8"}, {"url": "/docs/12/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 12 English manual", "sha256": "07e8cddcb38076c86dab95b72c4380a7a325f22401b5b7f9af5dd4931876f2cb"}], "sections": [], "signature": "", "attributes": {"method": "radius", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using a RADIUS server. See Section 20.11 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-RADIUS\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.11.\u00a0RADIUS Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses RADIUS as the password verification method. RADIUS is used only to validate the user name/password pairs. Therefore the user must already exist in the database before RADIUS can be used for authentication.</p>\n<p>When using RADIUS authentication, an Access Request message will be sent to the configured RADIUS server. This request will be of type <code class=\"literal\">Authenticate Only</code>, and include parameters for <code class=\"literal\">user name</code>, <code class=\"literal\">password</code> (encrypted) and <code class=\"literal\">NAS Identifier</code>. The request will be encrypted using a secret shared with the server. The RADIUS server will respond to this request with either <code class=\"literal\">Access Accept</code> or <code class=\"literal\">Access Reject</code>. There is no support for RADIUS accounting.</p>\n<p>Multiple RADIUS servers can be specified, in which case they will be tried sequentially. If a negative response is received from a server, the authentication will fail. If no response is received, the next server in the list will be tried. To specify multiple servers, separate the server names with commas and surround the list with double quotes. If multiple servers are specified, the other RADIUS options can also be given as comma-separated lists, to provide individual values for each server. They can also be specified as a single value, in which case that value will apply to all servers.</p>\n<p>The following configuration options are supported for RADIUS:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">radiusservers</code></span></dt>\n<dd>\n<p>The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiussecrets</code></span></dt>\n<dd>\n<p>The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>The encryption vector used will only be cryptographically strong if <span class=\"productname\">PostgreSQL</span> is built with support for <span class=\"productname\">OpenSSL</span>. In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary.</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusports</code></span></dt>\n<dd>\n<p>The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port (<code class=\"literal\">1812</code>) will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusidentifiers</code></span></dt>\n<dd>\n<p>The strings to be used as <code class=\"literal\">NAS Identifier</code> in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default <code class=\"literal\">postgresql</code> will be used.</p>\n</dd>\n</dl>\n</div>\n<p>If it is necessary to have a comma or whitespace in a RADIUS parameter value, that can be done by putting double quotes around the value, but it is tedious because two layers of double-quoting are now required. An example of putting whitespace into RADIUS secret strings is:</p>\n<pre class=\"programlisting\">host ... radius radiusservers=\"server1,server2\" radiussecrets=\"\"\"secret one\"\",\"\"secret two\"\"\"\n</pre>\n</div>", "manual_path": "/docs/12/auth-radius.html", "comparison_data": {"method": "radius", "documented_option_names": ["radiusidentifiers", "radiusports", "radiussecrets", "radiusservers"]}, "comparison_hash": "084932634de939bfac07ac9c692a7d4dd0c6593c73dd494f2f0ccbad15d6f1a4"}, "13": {"facts": [{"label": "Method", "value": "radius"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "radiusservers", "description": "The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required."}, {"name": "radiussecrets", "description": "The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required. Note The encryption vector used will only be cryptographically strong if PostgreSQL is built with support for OpenSSL . In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary."}, {"name": "radiusports", "description": "The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port ( 1812 ) will be used."}, {"name": "radiusidentifiers", "description": "The strings to be used as NAS Identifier in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default postgresql will be used."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "13.23", "major": "13", "channel": "historical", "revision": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "catalog_fingerprint": "c7015c845255c9d721c547c8ab9ef37825d332588c9691d982e6906b7d571002"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, {"url": "/docs/13/auth-radius.html", "path": "auth-radius.html", "label": "PostgreSQL 13 English manual", "sha256": "8b856325e93363b1b1c81543292410374f7082bb87c6a0a2819a9bd730597f44"}, {"url": "/docs/13/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 13 English manual", "sha256": "3cc6ce851945cba450e6b26ecf9cae1efd3c03fb7b55e17876f4d9ea418a7c2e"}], "sections": [], "signature": "", "attributes": {"method": "radius", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using a RADIUS server. See Section 20.11 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-RADIUS\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.11.\u00a0RADIUS Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses RADIUS as the password verification method. RADIUS is used only to validate the user name/password pairs. Therefore the user must already exist in the database before RADIUS can be used for authentication.</p>\n<p>When using RADIUS authentication, an Access Request message will be sent to the configured RADIUS server. This request will be of type <code class=\"literal\">Authenticate Only</code>, and include parameters for <code class=\"literal\">user name</code>, <code class=\"literal\">password</code> (encrypted) and <code class=\"literal\">NAS Identifier</code>. The request will be encrypted using a secret shared with the server. The RADIUS server will respond to this request with either <code class=\"literal\">Access Accept</code> or <code class=\"literal\">Access Reject</code>. There is no support for RADIUS accounting.</p>\n<p>Multiple RADIUS servers can be specified, in which case they will be tried sequentially. If a negative response is received from a server, the authentication will fail. If no response is received, the next server in the list will be tried. To specify multiple servers, separate the server names with commas and surround the list with double quotes. If multiple servers are specified, the other RADIUS options can also be given as comma-separated lists, to provide individual values for each server. They can also be specified as a single value, in which case that value will apply to all servers.</p>\n<p>The following configuration options are supported for RADIUS:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">radiusservers</code></span></dt>\n<dd>\n<p>The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiussecrets</code></span></dt>\n<dd>\n<p>The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>The encryption vector used will only be cryptographically strong if <span class=\"productname\">PostgreSQL</span> is built with support for <span class=\"productname\">OpenSSL</span>. In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary.</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusports</code></span></dt>\n<dd>\n<p>The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port (<code class=\"literal\">1812</code>) will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusidentifiers</code></span></dt>\n<dd>\n<p>The strings to be used as <code class=\"literal\">NAS Identifier</code> in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default <code class=\"literal\">postgresql</code> will be used.</p>\n</dd>\n</dl>\n</div>\n<p>If it is necessary to have a comma or whitespace in a RADIUS parameter value, that can be done by putting double quotes around the value, but it is tedious because two layers of double-quoting are now required. An example of putting whitespace into RADIUS secret strings is:</p>\n<pre class=\"programlisting\">host ... radius radiusservers=\"server1,server2\" radiussecrets=\"\"\"secret one\"\",\"\"secret two\"\"\"\n</pre>\n</div>", "manual_path": "/docs/13/auth-radius.html", "comparison_data": {"method": "radius", "documented_option_names": ["radiusidentifiers", "radiusports", "radiussecrets", "radiusservers"]}, "comparison_hash": "084932634de939bfac07ac9c692a7d4dd0c6593c73dd494f2f0ccbad15d6f1a4"}, "14": {"facts": [{"label": "Method", "value": "radius"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "radiusservers", "description": "The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required."}, {"name": "radiussecrets", "description": "The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required. Note The encryption vector used will only be cryptographically strong if PostgreSQL is built with support for OpenSSL . In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary."}, {"name": "radiusports", "description": "The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port ( 1812 ) will be used."}, {"name": "radiusidentifiers", "description": "The strings to be used as NAS Identifier in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default postgresql will be used."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "14.24", "major": "14", "channel": "stable", "revision": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "catalog_fingerprint": "b272e6a82e4c46efda81c3a6a4cdf7de6a83dfff7f02f226a392fbe9acdd3adb"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, {"url": "/docs/14/auth-radius.html", "path": "auth-radius.html", "label": "PostgreSQL 14 English manual", "sha256": "fb3d3e931756b65ca94923f872168ac0a24c8535d9248ab33fab95e8d5d91956"}, {"url": "/docs/14/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 14 English manual", "sha256": "c9a75f04fd4a1069ea261ba061578a75c47a4b7e0bbf88761502fd4c19ccbc3f"}], "sections": [], "signature": "", "attributes": {"method": "radius", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using a RADIUS server. See Section 21.11 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-RADIUS\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.11.\u00a0RADIUS Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses RADIUS as the password verification method. RADIUS is used only to validate the user name/password pairs. Therefore the user must already exist in the database before RADIUS can be used for authentication.</p>\n<p>When using RADIUS authentication, an Access Request message will be sent to the configured RADIUS server. This request will be of type <code class=\"literal\">Authenticate Only</code>, and include parameters for <code class=\"literal\">user name</code>, <code class=\"literal\">password</code> (encrypted) and <code class=\"literal\">NAS Identifier</code>. The request will be encrypted using a secret shared with the server. The RADIUS server will respond to this request with either <code class=\"literal\">Access Accept</code> or <code class=\"literal\">Access Reject</code>. There is no support for RADIUS accounting.</p>\n<p>Multiple RADIUS servers can be specified, in which case they will be tried sequentially. If a negative response is received from a server, the authentication will fail. If no response is received, the next server in the list will be tried. To specify multiple servers, separate the server names with commas and surround the list with double quotes. If multiple servers are specified, the other RADIUS options can also be given as comma-separated lists, to provide individual values for each server. They can also be specified as a single value, in which case that value will apply to all servers.</p>\n<p>The following configuration options are supported for RADIUS:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">radiusservers</code></span></dt>\n<dd>\n<p>The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiussecrets</code></span></dt>\n<dd>\n<p>The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>The encryption vector used will only be cryptographically strong if <span class=\"productname\">PostgreSQL</span> is built with support for <span class=\"productname\">OpenSSL</span>. In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary.</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusports</code></span></dt>\n<dd>\n<p>The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port (<code class=\"literal\">1812</code>) will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusidentifiers</code></span></dt>\n<dd>\n<p>The strings to be used as <code class=\"literal\">NAS Identifier</code> in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default <code class=\"literal\">postgresql</code> will be used.</p>\n</dd>\n</dl>\n</div>\n<p>If it is necessary to have a comma or whitespace in a RADIUS parameter value, that can be done by putting double quotes around the value, but it is tedious because two layers of double-quoting are now required. An example of putting whitespace into RADIUS secret strings is:</p>\n<pre class=\"programlisting\">host ... radius radiusservers=\"server1,server2\" radiussecrets=\"\"\"secret one\"\",\"\"secret two\"\"\"\n</pre>\n</div>", "manual_path": "/docs/14/auth-radius.html", "comparison_data": {"method": "radius", "documented_option_names": ["radiusidentifiers", "radiusports", "radiussecrets", "radiusservers"]}, "comparison_hash": "084932634de939bfac07ac9c692a7d4dd0c6593c73dd494f2f0ccbad15d6f1a4"}, "15": {"facts": [{"label": "Method", "value": "radius"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "radiusservers", "description": "The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required."}, {"name": "radiussecrets", "description": "The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required. Note The encryption vector used will only be cryptographically strong if PostgreSQL is built with support for OpenSSL . In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary."}, {"name": "radiusports", "description": "The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port ( 1812 ) will be used."}, {"name": "radiusidentifiers", "description": "The strings to be used as NAS Identifier in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default postgresql will be used."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "15.19", "major": "15", "channel": "stable", "revision": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "catalog_fingerprint": "fefe3c425147a86defada190c9b0663cfe02caa1724f5dede93e46457572252d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, {"url": "/docs/15/auth-radius.html", "path": "auth-radius.html", "label": "PostgreSQL 15 English manual", "sha256": "abfe27c3edfe3ce469aafba0b559f030982ac2c58e0b0e7217f5294b25c446f4"}, {"url": "/docs/15/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 15 English manual", "sha256": "0470cd3eeb82cbc32d4b8b79e29f4427bdfd01f5bb15e6d9b7cee2f6dd2bba44"}], "sections": [], "signature": "", "attributes": {"method": "radius", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using a RADIUS server. See Section 21.11 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-RADIUS\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.11.\u00a0RADIUS Authentication</h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses RADIUS as the password verification method. RADIUS is used only to validate the user name/password pairs. Therefore the user must already exist in the database before RADIUS can be used for authentication.</p>\n<p>When using RADIUS authentication, an Access Request message will be sent to the configured RADIUS server. This request will be of type <code class=\"literal\">Authenticate Only</code>, and include parameters for <code class=\"literal\">user name</code>, <code class=\"literal\">password</code> (encrypted) and <code class=\"literal\">NAS Identifier</code>. The request will be encrypted using a secret shared with the server. The RADIUS server will respond to this request with either <code class=\"literal\">Access Accept</code> or <code class=\"literal\">Access Reject</code>. There is no support for RADIUS accounting.</p>\n<p>Multiple RADIUS servers can be specified, in which case they will be tried sequentially. If a negative response is received from a server, the authentication will fail. If no response is received, the next server in the list will be tried. To specify multiple servers, separate the server names with commas and surround the list with double quotes. If multiple servers are specified, the other RADIUS options can also be given as comma-separated lists, to provide individual values for each server. They can also be specified as a single value, in which case that value will apply to all servers.</p>\n<p>The following configuration options are supported for RADIUS:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">radiusservers</code></span></dt>\n<dd>\n<p>The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiussecrets</code></span></dt>\n<dd>\n<p>The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>The encryption vector used will only be cryptographically strong if <span class=\"productname\">PostgreSQL</span> is built with support for <span class=\"productname\">OpenSSL</span>. In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary.</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusports</code></span></dt>\n<dd>\n<p>The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port (<code class=\"literal\">1812</code>) will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusidentifiers</code></span></dt>\n<dd>\n<p>The strings to be used as <code class=\"literal\">NAS Identifier</code> in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default <code class=\"literal\">postgresql</code> will be used.</p>\n</dd>\n</dl>\n</div>\n<p>If it is necessary to have a comma or whitespace in a RADIUS parameter value, that can be done by putting double quotes around the value, but it is tedious because two layers of double-quoting are now required. An example of putting whitespace into RADIUS secret strings is:</p>\n<pre class=\"programlisting\">host ... radius radiusservers=\"server1,server2\" radiussecrets=\"\"\"secret one\"\",\"\"secret two\"\"\"\n</pre>\n</div>", "manual_path": "/docs/15/auth-radius.html", "comparison_data": {"method": "radius", "documented_option_names": ["radiusidentifiers", "radiusports", "radiussecrets", "radiusservers"]}, "comparison_hash": "084932634de939bfac07ac9c692a7d4dd0c6593c73dd494f2f0ccbad15d6f1a4"}, "16": {"facts": [{"label": "Method", "value": "radius"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "radiusservers", "description": "The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required."}, {"name": "radiussecrets", "description": "The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required. Note The encryption vector used will only be cryptographically strong if PostgreSQL is built with support for OpenSSL . In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary."}, {"name": "radiusports", "description": "The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port ( 1812 ) will be used."}, {"name": "radiusidentifiers", "description": "The strings to be used as NAS Identifier in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default postgresql will be used."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "16.15", "major": "16", "channel": "stable", "revision": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "catalog_fingerprint": "fa133458dc8f52e15083b4f59b7a582e2e378b608d3ac5c53054df458a374e23"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, {"url": "/docs/16/auth-radius.html", "path": "auth-radius.html", "label": "PostgreSQL 16 English manual", "sha256": "4a5d4067352e0634a51d0e2fedab371ea4fcbedf4f3406270ff9bc5565db4204"}, {"url": "/docs/16/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 16 English manual", "sha256": "ccc5146375a184646d5992edbc693e12c0de4431a35141d6b56c8dd6b3c52132"}], "sections": [], "signature": "", "attributes": {"method": "radius", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using a RADIUS server. See Section 21.11 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-RADIUS\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">21.11.\u00a0RADIUS Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses RADIUS as the password verification method. RADIUS is used only to validate the user name/password pairs. Therefore the user must already exist in the database before RADIUS can be used for authentication.</p>\n<p>When using RADIUS authentication, an Access Request message will be sent to the configured RADIUS server. This request will be of type <code class=\"literal\">Authenticate Only</code>, and include parameters for <code class=\"literal\">user name</code>, <code class=\"literal\">password</code> (encrypted) and <code class=\"literal\">NAS Identifier</code>. The request will be encrypted using a secret shared with the server. The RADIUS server will respond to this request with either <code class=\"literal\">Access Accept</code> or <code class=\"literal\">Access Reject</code>. There is no support for RADIUS accounting.</p>\n<p>Multiple RADIUS servers can be specified, in which case they will be tried sequentially. If a negative response is received from a server, the authentication will fail. If no response is received, the next server in the list will be tried. To specify multiple servers, separate the server names with commas and surround the list with double quotes. If multiple servers are specified, the other RADIUS options can also be given as comma-separated lists, to provide individual values for each server. They can also be specified as a single value, in which case that value will apply to all servers.</p>\n<p>The following configuration options are supported for RADIUS:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">radiusservers</code></span></dt>\n<dd>\n<p>The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiussecrets</code></span></dt>\n<dd>\n<p>The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>The encryption vector used will only be cryptographically strong if <span class=\"productname\">PostgreSQL</span> is built with support for <span class=\"productname\">OpenSSL</span>. In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary.</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusports</code></span></dt>\n<dd>\n<p>The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port (<code class=\"literal\">1812</code>) will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusidentifiers</code></span></dt>\n<dd>\n<p>The strings to be used as <code class=\"literal\">NAS Identifier</code> in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default <code class=\"literal\">postgresql</code> will be used.</p>\n</dd>\n</dl>\n</div>\n<p>If it is necessary to have a comma or whitespace in a RADIUS parameter value, that can be done by putting double quotes around the value, but it is tedious because two layers of double-quoting are now required. An example of putting whitespace into RADIUS secret strings is:</p>\n<pre class=\"programlisting\">host ... radius radiusservers=\"server1,server2\" radiussecrets=\"\"\"secret one\"\",\"\"secret two\"\"\"\n</pre>\n</div>", "manual_path": "/docs/16/auth-radius.html", "comparison_data": {"method": "radius", "documented_option_names": ["radiusidentifiers", "radiusports", "radiussecrets", "radiusservers"]}, "comparison_hash": "084932634de939bfac07ac9c692a7d4dd0c6593c73dd494f2f0ccbad15d6f1a4"}, "17": {"facts": [{"label": "Method", "value": "radius"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "radiusservers", "description": "The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required."}, {"name": "radiussecrets", "description": "The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required. Note The encryption vector used will only be cryptographically strong if PostgreSQL is built with support for OpenSSL . In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary."}, {"name": "radiusports", "description": "The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port ( 1812 ) will be used."}, {"name": "radiusidentifiers", "description": "The strings to be used as NAS Identifier in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default postgresql will be used."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "revision": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "catalog_fingerprint": "4bbe3ac77becd618478f66aec420a533e9017be356c5c1d51a4b17f0fd497c07"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "/docs/17/auth-radius.html", "path": "auth-radius.html", "label": "PostgreSQL 17 English manual", "sha256": "2c2677fa257f6ef6a49d7e2aefb77420a39cf9370f6d15529c9a13e83363d922"}, {"url": "/docs/17/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 17 English manual", "sha256": "00c7a7c25d46aa1b2f24cd744cd4990ca4218cfafed2a4cab8c1dc1092090bba"}], "sections": [], "signature": "", "attributes": {"method": "radius", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using a RADIUS server. See Section 20.11 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-RADIUS\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.11.\u00a0RADIUS Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses RADIUS as the password verification method. RADIUS is used only to validate the user name/password pairs. Therefore the user must already exist in the database before RADIUS can be used for authentication.</p>\n<p>When using RADIUS authentication, an Access Request message will be sent to the configured RADIUS server. This request will be of type <code class=\"literal\">Authenticate Only</code>, and include parameters for <code class=\"literal\">user name</code>, <code class=\"literal\">password</code> (encrypted) and <code class=\"literal\">NAS Identifier</code>. The request will be encrypted using a secret shared with the server. The RADIUS server will respond to this request with either <code class=\"literal\">Access Accept</code> or <code class=\"literal\">Access Reject</code>. There is no support for RADIUS accounting.</p>\n<p>Multiple RADIUS servers can be specified, in which case they will be tried sequentially. If a negative response is received from a server, the authentication will fail. If no response is received, the next server in the list will be tried. To specify multiple servers, separate the server names with commas and surround the list with double quotes. If multiple servers are specified, the other RADIUS options can also be given as comma-separated lists, to provide individual values for each server. They can also be specified as a single value, in which case that value will apply to all servers.</p>\n<p>The following configuration options are supported for RADIUS:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">radiusservers</code></span></dt>\n<dd>\n<p>The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiussecrets</code></span></dt>\n<dd>\n<p>The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>The encryption vector used will only be cryptographically strong if <span class=\"productname\">PostgreSQL</span> is built with support for <span class=\"productname\">OpenSSL</span>. In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary.</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusports</code></span></dt>\n<dd>\n<p>The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port (<code class=\"literal\">1812</code>) will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusidentifiers</code></span></dt>\n<dd>\n<p>The strings to be used as <code class=\"literal\">NAS Identifier</code> in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default <code class=\"literal\">postgresql</code> will be used.</p>\n</dd>\n</dl>\n</div>\n<p>If it is necessary to have a comma or whitespace in a RADIUS parameter value, that can be done by putting double quotes around the value, but it is tedious because two layers of double-quoting are now required. An example of putting whitespace into RADIUS secret strings is:</p>\n<pre class=\"programlisting\">host ... radius radiusservers=\"server1,server2\" radiussecrets=\"\"\"secret one\"\",\"\"secret two\"\"\"\n</pre>\n</div>", "manual_path": "/docs/17/auth-radius.html", "comparison_data": {"method": "radius", "documented_option_names": ["radiusidentifiers", "radiusports", "radiussecrets", "radiusservers"]}, "comparison_hash": "084932634de939bfac07ac9c692a7d4dd0c6593c73dd494f2f0ccbad15d6f1a4"}, "18": {"facts": [{"label": "Method", "value": "radius"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "radiusservers", "description": "The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required."}, {"name": "radiussecrets", "description": "The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required. Note The encryption vector used will only be cryptographically strong if PostgreSQL is built with support for OpenSSL . In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary."}, {"name": "radiusports", "description": "The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port ( 1812 ) will be used."}, {"name": "radiusidentifiers", "description": "The strings to be used as NAS Identifier in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default postgresql will be used."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/auth-radius.html", "path": "auth-radius.html", "label": "PostgreSQL 18 English manual", "sha256": "adc663bf8e300c937cc9ee1b2004b31455391ad8d8699f75abe1f643cc7ff39b"}, {"url": "/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9"}], "sections": [], "signature": "", "attributes": {"method": "radius", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using a RADIUS server. See Section 20.11 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-RADIUS\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.11.\u00a0RADIUS Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses RADIUS as the password verification method. RADIUS is used only to validate the user name/password pairs. Therefore the user must already exist in the database before RADIUS can be used for authentication.</p>\n<p>When using RADIUS authentication, an Access Request message will be sent to the configured RADIUS server. This request will be of type <code class=\"literal\">Authenticate Only</code>, and include parameters for <code class=\"literal\">user name</code>, <code class=\"literal\">password</code> (encrypted) and <code class=\"literal\">NAS Identifier</code>. The request will be encrypted using a secret shared with the server. The RADIUS server will respond to this request with either <code class=\"literal\">Access Accept</code> or <code class=\"literal\">Access Reject</code>. There is no support for RADIUS accounting.</p>\n<p>Multiple RADIUS servers can be specified, in which case they will be tried sequentially. If a negative response is received from a server, the authentication will fail. If no response is received, the next server in the list will be tried. To specify multiple servers, separate the server names with commas and surround the list with double quotes. If multiple servers are specified, the other RADIUS options can also be given as comma-separated lists, to provide individual values for each server. They can also be specified as a single value, in which case that value will apply to all servers.</p>\n<p>The following configuration options are supported for RADIUS:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">radiusservers</code></span></dt>\n<dd>\n<p>The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiussecrets</code></span></dt>\n<dd>\n<p>The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>The encryption vector used will only be cryptographically strong if <span class=\"productname\">PostgreSQL</span> is built with support for <span class=\"productname\">OpenSSL</span>. In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary.</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusports</code></span></dt>\n<dd>\n<p>The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port (<code class=\"literal\">1812</code>) will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusidentifiers</code></span></dt>\n<dd>\n<p>The strings to be used as <code class=\"literal\">NAS Identifier</code> in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default <code class=\"literal\">postgresql</code> will be used.</p>\n</dd>\n</dl>\n</div>\n<p>If it is necessary to have a comma or whitespace in a RADIUS parameter value, that can be done by putting double quotes around the value, but it is tedious because two layers of double-quoting are now required. An example of putting whitespace into RADIUS secret strings is:</p>\n<pre class=\"programlisting\">host ... radius radiusservers=\"server1,server2\" radiussecrets=\"\"\"secret one\"\",\"\"secret two\"\"\"\n</pre>\n</div>", "manual_path": "/docs/18/auth-radius.html", "comparison_data": {"method": "radius", "documented_option_names": ["radiusidentifiers", "radiusports", "radiussecrets", "radiusservers"]}, "comparison_hash": "084932634de939bfac07ac9c692a7d4dd0c6593c73dd494f2f0ccbad15d6f1a4"}}}, "snapshot": {"facts": [{"label": "Method", "value": "radius"}, {"label": "Configuration", "value": "pg_hba.conf"}, {"label": "Inventory", "value": "User-visible source authentication method"}], "tables": [{"key": "method-options", "rows": [{"name": "radiusservers", "description": "The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required."}, {"name": "radiussecrets", "description": "The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required. Note The encryption vector used will only be cryptographically strong if PostgreSQL is built with support for OpenSSL . In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary."}, {"name": "radiusports", "description": "The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port ( 1812 ) will be used."}, {"name": "radiusidentifiers", "description": "The strings to be used as NAS Identifier in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default postgresql will be used."}], "title": "Documented method options and alternatives", "columns": [{"key": "name", "label": "Option or term"}, {"key": "description", "label": "Meaning"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/auth-radius.html", "path": "auth-radius.html", "label": "PostgreSQL 18 English manual", "sha256": "adc663bf8e300c937cc9ee1b2004b31455391ad8d8699f75abe1f643cc7ff39b"}, {"url": "/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9"}], "sections": [], "signature": "", "attributes": {"method": "radius", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["Authenticate using a RADIUS server. See Section 20.11 for details."], "manual_html": "<div class=\"sect1\" id=\"AUTH-RADIUS\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\">20.11.\u00a0RADIUS Authentication </h2>\n</div>\n</div>\n</div>\n<p>This authentication method operates similarly to <code class=\"literal\">password</code> except that it uses RADIUS as the password verification method. RADIUS is used only to validate the user name/password pairs. Therefore the user must already exist in the database before RADIUS can be used for authentication.</p>\n<p>When using RADIUS authentication, an Access Request message will be sent to the configured RADIUS server. This request will be of type <code class=\"literal\">Authenticate Only</code>, and include parameters for <code class=\"literal\">user name</code>, <code class=\"literal\">password</code> (encrypted) and <code class=\"literal\">NAS Identifier</code>. The request will be encrypted using a secret shared with the server. The RADIUS server will respond to this request with either <code class=\"literal\">Access Accept</code> or <code class=\"literal\">Access Reject</code>. There is no support for RADIUS accounting.</p>\n<p>Multiple RADIUS servers can be specified, in which case they will be tried sequentially. If a negative response is received from a server, the authentication will fail. If no response is received, the next server in the list will be tried. To specify multiple servers, separate the server names with commas and surround the list with double quotes. If multiple servers are specified, the other RADIUS options can also be given as comma-separated lists, to provide individual values for each server. They can also be specified as a single value, in which case that value will apply to all servers.</p>\n<p>The following configuration options are supported for RADIUS:</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">radiusservers</code></span></dt>\n<dd>\n<p>The DNS names or IP addresses of the RADIUS servers to connect to. This parameter is required.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiussecrets</code></span></dt>\n<dd>\n<p>The shared secrets used when talking securely to the RADIUS servers. This must have exactly the same value on the PostgreSQL and RADIUS servers. It is recommended that this be a string of at least 16 characters. This parameter is required.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>The encryption vector used will only be cryptographically strong if <span class=\"productname\">PostgreSQL</span> is built with support for <span class=\"productname\">OpenSSL</span>. In other cases, the transmission to the RADIUS server should only be considered obfuscated, not secured, and external security measures should be applied if necessary.</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusports</code></span></dt>\n<dd>\n<p>The port numbers to connect to on the RADIUS servers. If no port is specified, the default RADIUS port (<code class=\"literal\">1812</code>) will be used.</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">radiusidentifiers</code></span></dt>\n<dd>\n<p>The strings to be used as <code class=\"literal\">NAS Identifier</code> in the RADIUS requests. This parameter can be used, for example, to identify which database cluster the user is attempting to connect to, which can be useful for policy matching on the RADIUS server. If no identifier is specified, the default <code class=\"literal\">postgresql</code> will be used.</p>\n</dd>\n</dl>\n</div>\n<p>If it is necessary to have a comma or whitespace in a RADIUS parameter value, that can be done by putting double quotes around the value, but it is tedious because two layers of double-quoting are now required. An example of putting whitespace into RADIUS secret strings is:</p>\n<pre class=\"programlisting\">host ... radius radiusservers=\"server1,server2\" radiussecrets=\"\"\"secret one\"\",\"\"secret two\"\"\"\n</pre>\n</div>", "manual_path": "/docs/18/auth-radius.html", "comparison_data": {"method": "radius", "documented_option_names": ["radiusidentifiers", "radiusports", "radiussecrets", "radiusservers"]}, "comparison_hash": "084932634de939bfac07ac9c692a7d4dd0c6593c73dd494f2f0ccbad15d6f1a4"}, "comparison": {"left": "18", "right": "19", "status": "removed", "diff": "--- PostgreSQL 18\n+++ PostgreSQL 19\n@@ -1,9 +1 @@\n-{\n-  \"documented_option_names\": [\n-    \"radiusidentifiers\",\n-    \"radiusports\",\n-    \"radiussecrets\",\n-    \"radiusservers\"\n-  ],\n-  \"method\": \"radius\"\n-}\n+Not recorded in this version"}}