↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

SCRAM-SHA-256 Authentication

Recorded source states and original language descriptions. Missing version evidence stays unknown.

The source snapshot records transitions for PostgreSQL 8.1–18. The historical matrix records independent cells for 7.4–18. Neither records support for PostgreSQL 19 or 20; newer versions remain unknown. These source claims are distinct from runtime measurements.

Security

Description

As described in RFC 7677, SCRAM-SHA-256 authentication provides challenge-response scheme, that prevents password sniffing on untrusted connections. It is more secure than the md5 method, but might not be supported by older clients.

SCRAM-SHA-256 authentication can be enabled in the host-based authentication configuration file.

Selected version: PostgreSQL 18

Yes

20191817161514131211109.69.59.49.39.29.19.08.48.38.28.18.07.4
UnknownUnknownYesYesYesYesYesYesYesYesYesNoNoNoNoNoNoNoNoNoNoNoUnknownUnknown

Compare versions

Original documentation links

Recorded legacy identifiers: 295

Complete source facts and provenance

yaml · center · 1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd

{
  "Key": "scram-sha-256-authentication",
  "SourceKind": "yaml",
  "SourceDatabase": "center",
  "SourceTable": "featurematrix.yaml",
  "SourceKey": "SCRAM-SHA-256 Authentication",
  "SourceHash": "1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd",
  "Name": "SCRAM-SHA-256 Authentication",
  "NameLocale": "en",
  "GroupKey": "security",
  "GroupName": "Security",
  "GroupLocale": "en",
  "Ordinal": 23,
  "GroupOrder": 14,
  "Facts": {
    "feature": {
      "description": "As described in RFC 7677, SCRAM-SHA-256 authentication provides challenge-response scheme, that prevents password sniffing on untrusted connections. It is more secure than the md5 method, but might not be supported by older clients.\r\n\r\nSCRAM-SHA-256 authentication can be enabled in the host-based authentication configuration file.",
      "name": "SCRAM-SHA-256 Authentication",
      "versions": {
        "10": "Yes"
      }
    },
    "group": "Security",
    "versions": {
      "max": 18,
      "min": 8.1
    }
  },
  "Cells": [
    {
      "Version": "10",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "10",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "11",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "10",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "12",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "10",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "13",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "10",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "14",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "10",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "15",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "10",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "16",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "10",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "17",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "10",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "18",
      "State": "yes",
      "EvidenceKind": "yaml-transition",
      "TransitionVersion": "10",
      "Supported": true,
      "Original": "Yes"
    },
    {
      "Version": "8.1",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "8.2",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "8.3",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "8.4",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.0",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.1",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.2",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.3",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.4",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.5",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    },
    {
      "Version": "9.6",
      "State": "no",
      "EvidenceKind": "yaml-default-no",
      "TransitionVersion": "",
      "Supported": false,
      "Original": "No"
    }
  ],
  "Texts": [
    {
      "Locale": "en",
      "Title": "SCRAM-SHA-256 Authentication",
      "BodyHTML": "\u003cp\u003eAs described in RFC 7677, SCRAM-SHA-256 authentication provides challenge-response scheme, that prevents password sniffing on untrusted connections. It is more secure than the md5 method, but might not be supported by older clients.\u003c/p\u003e\n\u003cp\u003eSCRAM-SHA-256 authentication can be enabled in the host-based authentication configuration file.\u003c/p\u003e\n",
      "SourceHash": "1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd",
      "ContentHash": "738a5d152234156b2fcb9359a419e673cb5a5a8b139ce67078649577529c74fc",
      "Payload": {
        "description": "As described in RFC 7677, SCRAM-SHA-256 authentication provides challenge-response scheme, that prevents password sniffing on untrusted connections. It is more secure than the md5 method, but might not be supported by older clients.\r\n\r\nSCRAM-SHA-256 authentication can be enabled in the host-based authentication configuration file.",
        "name": "SCRAM-SHA-256 Authentication",
        "versions": {
          "10": "Yes"
        }
      }
    },
    {
      "Locale": "zh-Hans",
      "Title": "SCRAM-SHA-256 身份验证",
      "BodyHTML": "\u003cp\u003e如 RFC 7677 所述,SCRAM-SHA-256 身份验证提供了质询-响应方案,可防止在不可信连接上的密码嗅探。它比 md5 方法更安全,但可能不被较旧的客户端支持。\u003c/p\u003e\n\u003cp\u003eSCRAM-SHA-256 身份验证可以在基于主机的身份验证配置文件中启用。\u003c/p\u003e\n",
      "SourceHash": "071091951021357a5f492adb04caed6febf4d315ac2626ca027a48dd8ec01d50",
      "ContentHash": "5c94e26dbe9e1b9914449dfe8def8d714b9a1766fc8383de4f86ba3468aa7f13",
      "Payload": {
        "description": "如 RFC 7677 所述,SCRAM-SHA-256 身份验证提供了质询-响应方案,可防止在不可信连接上的密码嗅探。它比 md5 方法更安全,但可能不被较旧的客户端支持。\n\nSCRAM-SHA-256 身份验证可以在基于主机的身份验证配置文件中启用。",
        "name": "SCRAM-SHA-256 身份验证"
      }
    }
  ],
  "GroupTitles": {
    "en": "Security",
    "zh-Hans": "安全"
  },
  "LegacyIDs": [
    "295"
  ]
}

Complete source data JSON