Wiki / Connection Parameters / Authentication
channel_binding
This option controls the client's use of channel binding. A setting of require means that the connection must employ channel binding, prefer means that the client will choose channel binding if available, and disable prevents the use of channel bind…
Reading PostgreSQL 18.6.
Description
This option controls the client's use of channel binding. A setting of require means that the connection must employ channel binding, prefer means that the client will choose channel binding if available, and disable prevents the use of channel binding. The default is prefer if PostgreSQL is compiled with SSL support; otherwise the default is disable .
- Client library
- libpq 18.6
- Manual definition
- Documented
- Source environment fallback
- PGCHANNELBINDING
- Compiled fallback expression
- DefaultChannelBinding
Usage
channel_bindingDefault resolution and service-file precedence
The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.
Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\postgresql\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .
Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.
Environment variable evidence
PGCHANNELBINDING behaves the same as the channel_binding connection parameter.
Environment fallback
| Variable | Documented behavior |
|---|---|
| PGCHANNELBINDING | PGCHANNELBINDING behaves the same as the channel_binding connection parameter. |
Manual definition
channel_binding-
This option controls the client's use of channel binding. A setting of
requiremeans that the connection must employ channel binding,prefermeans that the client will choose channel binding if available, anddisableprevents the use of channel binding. The default ispreferif PostgreSQL is compiled with SSL support; otherwise the default isdisable.Channel binding is a method for the server to authenticate itself to the client. It is only supported over SSL connections with PostgreSQL 11 or later servers using the
SCRAMauthentication method.
Related entries
Documentation and source
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
Source build
- Version
- 18.6
- Build
- https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
- Source fingerprint
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
Compare versions
PostgreSQL 12 → 13: added.
--- PostgreSQL 12
+++ PostgreSQL 13
@@ -1 +1,10 @@
-Not recorded in this version
+{
+ "compiled_default_expression": "DefaultChannelBinding",
+ "default_evidence": [
+ "This option controls the client's use of channel binding. A setting of require means that the connection must employ channel binding, prefer means that the client will choose channel binding if available, and disable prevents the use of channel binding. The default is prefer if PostgreSQL is compiled with SSL support; otherwise the default is disable ."
+ ],
+ "definition": "This option controls the client's use of channel binding. A setting of require means that the connection must employ channel binding, prefer means that the client will choose channel binding if available, and disable prevents the use of channel binding. The default is prefer if PostgreSQL is compiled with SSL support; otherwise the default is disable . Channel binding is a method for the server to authenticate itself to the client. It is only supported over SSL connections with PostgreSQL 11 or later servers using the SCRAM authentication method.",
+ "documented": true,
+ "environment": "PGCHANNELBINDING",
+ "keyword": "channel_binding"
+}
Compares recorded interfaces and attributes. Source fingerprints and build metadata are excluded; an absent sample is not proof of the introduction or removal release.
Related entries
Export JSON · Back to Connection Parameters · Recorded in PostgreSQL 13 through 20; the first sample is not necessarily its introduction.