{"Entry":{"collection":"auth","key":"cert","name":"cert","aliases":[],"metadata":{"aliases":[],"category":"Authentication and access control","content_hash":"297f2685302419b982caafa87769863b919a7a6ae98bc789cda92d789a257042","imported_at":"2026-09-30T00:40:33.271308+08:00","name":"cert","name_zh":"","slug":"cert","summary":"Authenticate using SSL client certificates. See Section 20.11 for details."}},"Definition":{"Collection":"auth","Key":"cert","SourceDatabase":"center","Version":"18","SourceTable":"authentication_method","SourceKey":"cert","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","Facts":{"aliases":[],"attributes":{"configuration":"pg_hba.conf","inventory":"User-visible source authentication method","method":"cert"},"comparison_data":{"documented_option_names":["map"],"method":"cert"},"comparison_hash":"40542fff8f26666c5c9e9d161e6288daf51bf13f0e269760dbc632420d0e4b94","description":["Authenticate using SSL client certificates. See Section 20.12 for details."],"facts":[{"label":"Method","value":"cert"},{"label":"Configuration","value":"pg_hba.conf"},{"label":"Inventory","value":"User-visible source authentication method"}],"manual_html":"\u003cdiv class=\"sect1\" id=\"AUTH-CERT\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e20.12. Certificate Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThis authentication method uses SSL client certificates to perform authentication. It is therefore only available for SSL connections; see \u003ca class=\"xref\" href=\"/docs/18/ssl-tcp.html#SSL-OPENSSL-CONFIG\" title=\"18.9.2. OpenSSL Configuration\"\u003eSection 18.9.2\u003c/a\u003e for SSL configuration instructions. When using this authentication method, the server will require that the client provide a valid, trusted certificate. No password prompt will be sent to the client. The \u003ccode class=\"literal\"\u003ecn\u003c/code\u003e (Common Name) attribute of the certificate will be compared to the requested database user name, and if they match the login will be allowed. User name mapping can be used to allow \u003ccode class=\"literal\"\u003ecn\u003c/code\u003e to be different from the database user name.\u003c/p\u003e\n\u003cp\u003eThe following configuration options are supported for SSL certificate authentication:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003emap\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAllows for mapping between system and database user names. See \u003ca class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2. User Name Maps\"\u003eSection 20.2\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eIt is redundant to use the \u003ccode class=\"literal\"\u003eclientcert\u003c/code\u003e option with \u003ccode class=\"literal\"\u003ecert\u003c/code\u003e authentication because \u003ccode class=\"literal\"\u003ecert\u003c/code\u003e authentication is effectively \u003ccode class=\"literal\"\u003etrust\u003c/code\u003e authentication with \u003ccode class=\"literal\"\u003eclientcert=verify-full\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e","manual_path":"/docs/18/auth-cert.html","related":[],"release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sections":[],"signature":"","sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"auth-cert.html","sha256":"b43c008f505f9b377b2712eef6c9f98a10a3074642ca173f46e44316305c02ad","url":"/docs/18/auth-cert.html"},{"label":"PostgreSQL 18 English manual","path":"auth-pg-hba-conf.html","sha256":"6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9","url":"/docs/18/auth-pg-hba-conf.html"}],"tables":[{"columns":[{"key":"name","label":"Option or term"},{"key":"description","label":"Meaning"}],"key":"method-options","rows":[{"description":"Allows for mapping between system and database user names. See Section 20.2 for details.","name":"map"}],"title":"Documented method options and alternatives"}]},"ManualEvidence":{"manual_path":"/docs/18/auth-cert.html","release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"auth-cert.html","sha256":"b43c008f505f9b377b2712eef6c9f98a10a3074642ca173f46e44316305c02ad","url":"/docs/18/auth-cert.html"},{"label":"PostgreSQL 18 English manual","path":"auth-pg-hba-conf.html","sha256":"6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9","url":"/docs/18/auth-pg-hba-conf.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"auth","Key":"cert","SourceDatabase":"center","Version":"18","Locale":"en","Title":"cert","Summary":"Authenticate using SSL client certificates. See Section 20.12 for details.","BodyHTML":"\u003cdiv id=\"AUTH-CERT\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2\u003e20.12. Certificate Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThis authentication method uses SSL client certificates to perform authentication. It is therefore only available for SSL connections; see \u003ca href=\"/docs/18/ssl-tcp.html#SSL-OPENSSL-CONFIG\" rel=\"nofollow\"\u003eSection 18.9.2\u003c/a\u003e for SSL configuration instructions. When using this authentication method, the server will require that the client provide a valid, trusted certificate. No password prompt will be sent to the client. The \u003ccode\u003ecn\u003c/code\u003e (Common Name) attribute of the certificate will be compared to the requested database user name, and if they match the login will be allowed. User name mapping can be used to allow \u003ccode\u003ecn\u003c/code\u003e to be different from the database user name.\u003c/p\u003e\n\u003cp\u003eThe following configuration options are supported for SSL certificate authentication:\u003c/p\u003e\n\u003cdiv\u003e\n\u003cdl\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003emap\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAllows for mapping between system and database user names. See \u003ca href=\"/docs/18/auth-username-maps.html\" rel=\"nofollow\"\u003eSection 20.2\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eIt is redundant to use the \u003ccode\u003eclientcert\u003c/code\u003e option with \u003ccode\u003ecert\u003c/code\u003e authentication because \u003ccode\u003ecert\u003c/code\u003e authentication is effectively \u003ccode\u003etrust\u003c/code\u003e authentication with \u003ccode\u003eclientcert=verify-full\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","ContentHash":"b6ce73929cd44e9c93837be428cde75114ca075182217a2d21e79516cfdd5c5f","Payload":{"description":["Authenticate using SSL client certificates. See Section 20.12 for details."],"manual_html":"\u003cdiv class=\"sect1\" id=\"AUTH-CERT\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e20.12. Certificate Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThis authentication method uses SSL client certificates to perform authentication. It is therefore only available for SSL connections; see \u003ca class=\"xref\" href=\"/docs/18/ssl-tcp.html#SSL-OPENSSL-CONFIG\" title=\"18.9.2. OpenSSL Configuration\"\u003eSection 18.9.2\u003c/a\u003e for SSL configuration instructions. When using this authentication method, the server will require that the client provide a valid, trusted certificate. No password prompt will be sent to the client. The \u003ccode class=\"literal\"\u003ecn\u003c/code\u003e (Common Name) attribute of the certificate will be compared to the requested database user name, and if they match the login will be allowed. User name mapping can be used to allow \u003ccode class=\"literal\"\u003ecn\u003c/code\u003e to be different from the database user name.\u003c/p\u003e\n\u003cp\u003eThe following configuration options are supported for SSL certificate authentication:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003emap\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAllows for mapping between system and database user names. See \u003ca class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2. User Name Maps\"\u003eSection 20.2\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eIt is redundant to use the \u003ccode class=\"literal\"\u003eclientcert\u003c/code\u003e option with \u003ccode class=\"literal\"\u003ecert\u003c/code\u003e authentication because \u003ccode class=\"literal\"\u003ecert\u003c/code\u003e authentication is effectively \u003ccode class=\"literal\"\u003etrust\u003c/code\u003e authentication with \u003ccode class=\"literal\"\u003eclientcert=verify-full\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e","related":[],"sections":[],"tables":[{"columns":[{"key":"name","label":"Option or term"},{"key":"description","label":"Meaning"}],"key":"method-options","rows":[{"description":"Allows for mapping between system and database user names. See Section 20.2 for details.","name":"map"}],"title":"Documented method options and alternatives"}]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
