↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

Multifactor authentication via valid client SSL/TLS certificate

Recorded source states and original language descriptions. Missing version evidence stays unknown.

The source snapshot records transitions for PostgreSQL 8.1–18. The historical matrix records independent cells for 7.4–18. Neither records support for PostgreSQL 19 or 20; newer versions remain unknown. These source claims are distinct from runtime measurements.

Security

Description

If an authentication entry in the pg_hba.conf specifies the clientcert=verify-full, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.

https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES

Selected version: PostgreSQL 18

Yes

20191817161514131211109.69.59.49.39.29.19.08.48.38.28.18.07.4
UnknownUnknownYesYesYesYesYesYesYesNoNoNoNoNoNoNoNoNoNoNoNoNoUnknownUnknown

Compare versions

Original documentation links

Recorded legacy identifiers: 326

Complete source facts and provenance

yaml · center · 1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd

{
  "Key": "multifactor-authentication-via-valid-client-ssltls-certificate",
  "SourceKind": "yaml",
  "SourceDatabase": "center",
  "SourceTable": "featurematrix.yaml",
  "SourceKey": "Multifactor authentication via valid client SSL/TLS certificate",
  "SourceHash": "1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd",
  "Name": "Multifactor authentication via valid client SSL/TLS certificate",
  "NameLocale": "en",
  "GroupKey": "security",
  "GroupName": "Security",
  "GroupLocale": "en",
  "Ordinal": 14,
  "GroupOrder": 14,
  "Facts": {
    "feature": {
      "description": "If an authentication entry in the pg_hba.conf specifies the `clientcert=verify-full`, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.\r\n\r\n[https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES](https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES)",
      "name": "Multifactor authentication via valid client SSL/TLS certificate",
      "versions": {
        "12": "Yes"
      }
    },
    "group": "Security",
    "versions": {
      "max": 18,
      "min": 8.1
    }
  },
  "Cells": [
    {
      "Version": "10",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "11",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "12",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "12",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "13",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "12",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "14",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "12",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "15",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "12",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "16",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "12",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "17",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "12",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "18",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "12",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "8.1",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "8.2",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "8.3",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "8.4",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.0",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.1",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.2",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.3",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.4",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.5",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.6",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    }
  ],
  "Texts": [
    {
      "Locale": "en",
      "Title": "Multifactor authentication via valid client SSL/TLS certificate",
      "BodyHTML": "\u003cp\u003eIf an authentication entry in the pg_hba.conf specifies the \u003ccode\u003eclientcert=verify-full\u003c/code\u003e, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\" rel=\"nofollow\"\u003ehttps://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\u003c/a\u003e\u003c/p\u003e\n",
      "SourceHash": "1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd",
      "ContentHash": "6ffde594e8dc7c79f9e7b2f05aec068a3873f20243ab44060f3d69421f816cca",
      "Payload": {
        "description": "If an authentication entry in the pg_hba.conf specifies the `clientcert=verify-full`, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.\r\n\r\n[https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES](https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES)",
        "name": "Multifactor authentication via valid client SSL/TLS certificate",
        "versions": {
          "12": "Yes"
        }
      }
    },
    {
      "Locale": "zh-Hans",
      "Title": "通过有效的客户端 SSL/TLS 证书进行多因素身份验证",
      "BodyHTML": "\u003cp\u003e如果 pg_hba.conf 中的身份验证条目指定了 \u003ccode\u003eclientcert=verify-full\u003c/code\u003e,则客户端必须提供与登录名匹配的有效 SSL 证书,或者基于映射的客户端名称。\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\" rel=\"nofollow\"\u003ehttps://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\u003c/a\u003e\u003c/p\u003e\n",
      "SourceHash": "071091951021357a5f492adb04caed6febf4d315ac2626ca027a48dd8ec01d50",
      "ContentHash": "5b645361965bcc9649badea138d9cf77688a8825275c5b70b3a0d89a20f66452",
      "Payload": {
        "description": "如果 pg_hba.conf 中的身份验证条目指定了 `clientcert=verify-full`,则客户端必须提供与登录名匹配的有效 SSL 证书,或者基于映射的客户端名称。\n\n[https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES](https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES)",
        "name": "通过有效的客户端 SSL/TLS 证书进行多因素身份验证"
      }
    }
  ],
  "GroupTitles": {
    "en": "Security",
    "zh-Hans": "安全"
  },
  "LegacyIDs": [
    "326"
  ]
}

Complete source data JSON