Wiki / Connection Parameters / GSSAPI and Kerberos
krbsrvname
Kerberos service name to use when authenticating with GSSAPI. This must match the service name specified in the server configuration for Kerberos authentication to succeed. (See also Section 20.6 .) The default value is normally postgres , but that …
Reading PostgreSQL 18.6.
Description
Kerberos service name to use when authenticating with GSSAPI. This must match the service name specified in the server configuration for Kerberos authentication to succeed. (See also Section 20.6 .) The default value is normally postgres , but that can be changed when building PostgreSQL via the --with-krb-srvnam option of configure . In most environments, this parameter never needs to be changed. Some Kerberos implementations might require a different service name, such as Microsoft Active Directory which requires the service name to be in upper case ( POSTGRES ).
- Client library
- libpq 18.6
- Manual definition
- Documented
- Source environment fallback
- PGKRBSRVNAME
- Compiled fallback expression
- PG_KRB_SRVNAM
Usage
krbsrvnameDefault resolution and service-file precedence
The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.
Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\postgresql\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .
Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.
Environment variable evidence
PGKRBSRVNAME behaves the same as the krbsrvname connection parameter.
Environment fallback
| Variable | Documented behavior |
|---|---|
| PGKRBSRVNAME | PGKRBSRVNAME behaves the same as the krbsrvname connection parameter. |
Manual definition
krbsrvname-
Kerberos service name to use when authenticating with GSSAPI. This must match the service name specified in the server configuration for Kerberos authentication to succeed. (See also Section 20.6.) The default value is normally
postgres, but that can be changed when building PostgreSQL via the--with-krb-srvnamoption of configure. In most environments, this parameter never needs to be changed. Some Kerberos implementations might require a different service name, such as Microsoft Active Directory which requires the service name to be in upper case (POSTGRES).
Related entries
Documentation and source
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
Source build
- Version
- 18.6
- Build
- https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
- Source fingerprint
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
Compare versions
PostgreSQL 10 → 11: changed.
--- PostgreSQL 10
+++ PostgreSQL 11
@@ -1,7 +1,7 @@
{
"compiled_default_expression": "PG_KRB_SRVNAM",
"default_evidence": [],
- "definition": "Kerberos service name to use when authenticating with GSSAPI. This must match the service name specified in the server configuration for Kerberos authentication to succeed. (See also Section 20.3.3 .)",
+ "definition": "Kerberos service name to use when authenticating with GSSAPI. This must match the service name specified in the server configuration for Kerberos authentication to succeed. (See also Section 20.6 .)",
"documented": true,
"environment": "PGKRBSRVNAME",
"keyword": "krbsrvname"
Compares recorded interfaces and attributes. Source fingerprints and build metadata are excluded; an absent sample is not proof of the introduction or removal release.
Related entries
Export JSON · Back to Connection Parameters · Recorded in PostgreSQL 10 through 20; the first sample is not necessarily its introduction.