Multifactor authentication via valid client SSL/TLS certificate
Recorded source states and original language descriptions. Missing version evidence stays unknown.
The source snapshot records transitions for PostgreSQL 8.1–18. The historical matrix records independent cells for 7.4–18. Neither records support for PostgreSQL 19 or 20; newer versions remain unknown. These source claims are distinct from runtime measurements.
Security
Description
If an authentication entry in the pg_hba.conf specifies the clientcert=verify-full, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.
https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES
Selected version: PostgreSQL 18
Yes
Compare versions
Original documentation links
Recorded legacy identifiers: 326
Complete source facts and provenance
yaml · center · 1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd
{
"Key": "multifactor-authentication-via-valid-client-ssltls-certificate",
"SourceKind": "yaml",
"SourceDatabase": "center",
"SourceTable": "featurematrix.yaml",
"SourceKey": "Multifactor authentication via valid client SSL/TLS certificate",
"SourceHash": "1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd",
"Name": "Multifactor authentication via valid client SSL/TLS certificate",
"NameLocale": "en",
"GroupKey": "security",
"GroupName": "Security",
"GroupLocale": "en",
"Ordinal": 14,
"GroupOrder": 14,
"Facts": {
"feature": {
"description": "If an authentication entry in the pg_hba.conf specifies the `clientcert=verify-full`, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.\r\n\r\n[https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES](https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES)",
"name": "Multifactor authentication via valid client SSL/TLS certificate",
"versions": {
"12": "Yes"
}
},
"group": "Security",
"versions": {
"max": 18,
"min": 8.1
}
},
"Cells": [
{
"Version": "10",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "11",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "12",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "13",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "14",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "15",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "16",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "17",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "18",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "8.1",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "8.2",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "8.3",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "8.4",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.0",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.1",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.2",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.3",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.4",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.5",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.6",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
}
],
"Texts": [
{
"Locale": "en",
"Title": "Multifactor authentication via valid client SSL/TLS certificate",
"BodyHTML": "\u003cp\u003eIf an authentication entry in the pg_hba.conf specifies the \u003ccode\u003eclientcert=verify-full\u003c/code\u003e, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\" rel=\"nofollow\"\u003ehttps://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\u003c/a\u003e\u003c/p\u003e\n",
"SourceHash": "1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd",
"ContentHash": "6ffde594e8dc7c79f9e7b2f05aec068a3873f20243ab44060f3d69421f816cca",
"Payload": {
"description": "If an authentication entry in the pg_hba.conf specifies the `clientcert=verify-full`, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.\r\n\r\n[https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES](https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES)",
"name": "Multifactor authentication via valid client SSL/TLS certificate",
"versions": {
"12": "Yes"
}
}
},
{
"Locale": "zh-Hans",
"Title": "通过有效的客户端 SSL/TLS 证书进行多因素身份验证",
"BodyHTML": "\u003cp\u003e如果 pg_hba.conf 中的身份验证条目指定了 \u003ccode\u003eclientcert=verify-full\u003c/code\u003e,则客户端必须提供与登录名匹配的有效 SSL 证书,或者基于映射的客户端名称。\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\" rel=\"nofollow\"\u003ehttps://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\u003c/a\u003e\u003c/p\u003e\n",
"SourceHash": "071091951021357a5f492adb04caed6febf4d315ac2626ca027a48dd8ec01d50",
"ContentHash": "5b645361965bcc9649badea138d9cf77688a8825275c5b70b3a0d89a20f66452",
"Payload": {
"description": "如果 pg_hba.conf 中的身份验证条目指定了 `clientcert=verify-full`,则客户端必须提供与登录名匹配的有效 SSL 证书,或者基于映射的客户端名称。\n\n[https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES](https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES)",
"name": "通过有效的客户端 SSL/TLS 证书进行多因素身份验证"
}
}
],
"GroupTitles": {
"en": "Security",
"zh-Hans": "安全"
},
"LegacyIDs": [
"326"
]
}