ident
Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details.
当前阅读 PG 18·选择有来源记录的版本
此版本暂无所选语言的定义,以下显示原始英文内容。
- Method
- ident
- Configuration
- pg_hba.conf
- Inventory
- User-visible source authentication method
- aliases
- 未知
- manual path
- /docs/18/auth-ident.html
- signature
- 未知
版本定义 PG 18
20.8. Ident Authentication
The ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.
Note
When ident is specified for a local (non-TCP/IP) connection, peer authentication (see Section 20.9) will be used instead.
The following configuration options are supported for ident:
map-
Allows for mapping between system and database user names. See Section 20.2 for details.
The “Identification Protocol” is described in RFC 1413. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like “What user initiated the connection that goes out of your port X and connects to my port Y?”. Since PostgreSQL knows both X and Y when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.
The drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:
|
The Identification Protocol is not intended as an authorization or access control protocol. |
||
| --RFC 1413 | ||
Some ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option must not be used when using the ident server with PostgreSQL, since PostgreSQL does not have any way to decrypt the returned string to determine the actual user name.
Documented method options and alternatives
| Option or term | Meaning |
|---|---|
| map | Allows for mapping between system and database user names. See Section 20.2 for details. |
比较版本
完整来源事实
attributes
{"configuration":"pg_hba.conf","inventory":"User-visible source authentication method","method":"ident"}来源引用
- Matching PostgreSQL source archive
- PostgreSQL 18 English manual
- PostgreSQL 18 English manual
- 固定 PostgreSQL 源码归档
定义来源
center · PostgreSQL 18 · 555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f
正文语言: en · 555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f