{"Entry":{"collection":"auth","key":"ident","name":"ident","aliases":[],"metadata":{"aliases":[],"category":"Authentication and access control","content_hash":"24a6051c3372fa1d95cd853b527cbb4c91ef741cb1c356020f49f774bbc717b1","imported_at":"2026-09-30T00:40:33.290455+08:00","name":"ident","name_zh":"","slug":"ident","summary":"Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."}},"Definition":{"Collection":"auth","Key":"ident","SourceDatabase":"center","Version":"18","SourceTable":"authentication_method","SourceKey":"ident","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","Facts":{"aliases":[],"attributes":{"configuration":"pg_hba.conf","inventory":"User-visible source authentication method","method":"ident"},"comparison_data":{"documented_option_names":["map"],"method":"ident"},"comparison_hash":"1e75b0772a935e648eb3675daa207e7e3b87b3ee5ae88c48a8eb96b82f094fc0","description":["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."],"facts":[{"label":"Method","value":"ident"},{"label":"Configuration","value":"pg_hba.conf"},{"label":"Inventory","value":"User-visible source authentication method"}],"manual_html":"\u003cdiv class=\"sect1\" id=\"AUTH-IDENT\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e20.8. Ident Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThe ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.\u003c/p\u003e\n\u003cdiv class=\"note\"\u003e\n\u003ch3 class=\"title\"\u003eNote\u003c/h3\u003e\n\u003cp\u003eWhen ident is specified for a local (non-TCP/IP) connection, peer authentication (see \u003ca class=\"xref\" href=\"/docs/18/auth-peer.html\" title=\"20.9. Peer Authentication\"\u003eSection 20.9\u003c/a\u003e) will be used instead.\u003c/p\u003e\n\u003c/div\u003e\n\u003cp\u003eThe following configuration options are supported for \u003ccode class=\"literal\"\u003eident\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003emap\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAllows for mapping between system and database user names. See \u003ca class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2. User Name Maps\"\u003eSection 20.2\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eThe \u003cspan class=\"quote\"\u003e“\u003cspan class=\"quote\"\u003eIdentification Protocol\u003c/span\u003e”\u003c/span\u003e is described in \u003ca class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc1413\"\u003eRFC 1413\u003c/a\u003e. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like \u003cspan class=\"quote\"\u003e“\u003cspan class=\"quote\"\u003eWhat user initiated the connection that goes out of your port \u003cem class=\"replaceable\"\u003e\u003ccode\u003eX\u003c/code\u003e\u003c/em\u003e and connects to my port \u003cem class=\"replaceable\"\u003e\u003ccode\u003eY\u003c/code\u003e\u003c/em\u003e?\u003c/span\u003e”\u003c/span\u003e. Since \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e knows both \u003cem class=\"replaceable\"\u003e\u003ccode\u003eX\u003c/code\u003e\u003c/em\u003e and \u003cem class=\"replaceable\"\u003e\u003ccode\u003eY\u003c/code\u003e\u003c/em\u003e when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.\u003c/p\u003e\n\u003cp\u003eThe drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:\u003c/p\u003e\n\u003cdiv class=\"blockquote\"\u003e\n\u003ctable class=\"blockquote\"\u003e\n\u003ctbody\u003e\u003ctr\u003e\n\u003ctd\u003e \u003c/td\u003e\n\u003ctd\u003e\n\u003cp\u003eThe Identification Protocol is not intended as an authorization or access control protocol.\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd\u003e \u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e \u003c/td\u003e\n\u003ctd colspan=\"2\"\u003e--\u003cspan class=\"attribution\"\u003eRFC 1413\u003c/span\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\u003c/table\u003e\n\u003c/div\u003e\n\u003cp\u003eSome ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option \u003cspan class=\"emphasis\"\u003e\u003cem\u003emust not\u003c/em\u003e\u003c/span\u003e be used when using the ident server with \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e, since \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e does not have any way to decrypt the returned string to determine the actual user name.\u003c/p\u003e\n\u003c/div\u003e","manual_path":"/docs/18/auth-ident.html","related":[],"release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sections":[],"signature":"","sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"auth-ident.html","sha256":"14dd74aab7c9cfa7b89f8873f997df364d665097bb9be19146de6d2ea45eec7c","url":"/docs/18/auth-ident.html"},{"label":"PostgreSQL 18 English manual","path":"auth-pg-hba-conf.html","sha256":"6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9","url":"/docs/18/auth-pg-hba-conf.html"}],"tables":[{"columns":[{"key":"name","label":"Option or term"},{"key":"description","label":"Meaning"}],"key":"method-options","rows":[{"description":"Allows for mapping between system and database user names. See Section 20.2 for details.","name":"map"}],"title":"Documented method options and alternatives"}]},"ManualEvidence":{"manual_path":"/docs/18/auth-ident.html","release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"auth-ident.html","sha256":"14dd74aab7c9cfa7b89f8873f997df364d665097bb9be19146de6d2ea45eec7c","url":"/docs/18/auth-ident.html"},{"label":"PostgreSQL 18 English manual","path":"auth-pg-hba-conf.html","sha256":"6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9","url":"/docs/18/auth-pg-hba-conf.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"auth","Key":"ident","SourceDatabase":"center","Version":"18","Locale":"en","Title":"ident","Summary":"Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details.","BodyHTML":"\u003cdiv id=\"AUTH-IDENT\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2\u003e20.8. Ident Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThe ident authentication method works by obtaining the client\u0026#39;s operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.\u003c/p\u003e\n\u003cdiv\u003e\n\u003ch3\u003eNote\u003c/h3\u003e\n\u003cp\u003eWhen ident is specified for a local (non-TCP/IP) connection, peer authentication (see \u003ca href=\"/docs/18/auth-peer.html\" rel=\"nofollow\"\u003eSection 20.9\u003c/a\u003e) will be used instead.\u003c/p\u003e\n\u003c/div\u003e\n\u003cp\u003eThe following configuration options are supported for \u003ccode\u003eident\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv\u003e\n\u003cdl\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003emap\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAllows for mapping between system and database user names. See \u003ca href=\"/docs/18/auth-username-maps.html\" rel=\"nofollow\"\u003eSection 20.2\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eThe \u003cspan\u003e“\u003cspan\u003eIdentification Protocol\u003c/span\u003e”\u003c/span\u003e is described in \u003ca href=\"https://datatracker.ietf.org/doc/html/rfc1413\" rel=\"nofollow\"\u003eRFC 1413\u003c/a\u003e. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like \u003cspan\u003e“\u003cspan\u003eWhat user initiated the connection that goes out of your port \u003cem\u003e\u003ccode\u003eX\u003c/code\u003e\u003c/em\u003e and connects to my port \u003cem\u003e\u003ccode\u003eY\u003c/code\u003e\u003c/em\u003e?\u003c/span\u003e”\u003c/span\u003e. Since \u003cspan\u003ePostgreSQL\u003c/span\u003e knows both \u003cem\u003e\u003ccode\u003eX\u003c/code\u003e\u003c/em\u003e and \u003cem\u003e\u003ccode\u003eY\u003c/code\u003e\u003c/em\u003e when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.\u003c/p\u003e\n\u003cp\u003eThe drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:\u003c/p\u003e\n\u003cdiv\u003e\n\u003ctable\u003e\n\u003ctbody\u003e\u003ctr\u003e\n\u003ctd\u003e \u003c/td\u003e\n\u003ctd\u003e\n\u003cp\u003eThe Identification Protocol is not intended as an authorization or access control protocol.\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd\u003e \u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e \u003c/td\u003e\n\u003ctd colspan=\"2\"\u003e--\u003cspan\u003eRFC 1413\u003c/span\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\u003c/table\u003e\n\u003c/div\u003e\n\u003cp\u003eSome ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine\u0026#39;s administrator knows. This option \u003cspan\u003e\u003cem\u003emust not\u003c/em\u003e\u003c/span\u003e be used when using the ident server with \u003cspan\u003ePostgreSQL\u003c/span\u003e, since \u003cspan\u003ePostgreSQL\u003c/span\u003e does not have any way to decrypt the returned string to determine the actual user name.\u003c/p\u003e\n\u003c/div\u003e","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","ContentHash":"2c80bfee17b14ef41ab04ce673d6d3c3ebee1470004e79ba462f5936ec7d70ac","Payload":{"description":["Obtain the operating system user name of the client by contacting the ident server on the client and check if it matches the requested database user name. Ident authentication can only be used on TCP/IP connections. When specified for local connections, peer authentication will be used instead. See Section 20.8 for details."],"manual_html":"\u003cdiv class=\"sect1\" id=\"AUTH-IDENT\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e20.8. Ident Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThe ident authentication method works by obtaining the client's operating system user name from an ident server and using it as the allowed database user name (with an optional user name mapping). This is only supported on TCP/IP connections.\u003c/p\u003e\n\u003cdiv class=\"note\"\u003e\n\u003ch3 class=\"title\"\u003eNote\u003c/h3\u003e\n\u003cp\u003eWhen ident is specified for a local (non-TCP/IP) connection, peer authentication (see \u003ca class=\"xref\" href=\"/docs/18/auth-peer.html\" title=\"20.9. Peer Authentication\"\u003eSection 20.9\u003c/a\u003e) will be used instead.\u003c/p\u003e\n\u003c/div\u003e\n\u003cp\u003eThe following configuration options are supported for \u003ccode class=\"literal\"\u003eident\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003emap\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAllows for mapping between system and database user names. See \u003ca class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2. User Name Maps\"\u003eSection 20.2\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eThe \u003cspan class=\"quote\"\u003e“\u003cspan class=\"quote\"\u003eIdentification Protocol\u003c/span\u003e”\u003c/span\u003e is described in \u003ca class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc1413\"\u003eRFC 1413\u003c/a\u003e. Virtually every Unix-like operating system ships with an ident server that listens on TCP port 113 by default. The basic functionality of an ident server is to answer questions like \u003cspan class=\"quote\"\u003e“\u003cspan class=\"quote\"\u003eWhat user initiated the connection that goes out of your port \u003cem class=\"replaceable\"\u003e\u003ccode\u003eX\u003c/code\u003e\u003c/em\u003e and connects to my port \u003cem class=\"replaceable\"\u003e\u003ccode\u003eY\u003c/code\u003e\u003c/em\u003e?\u003c/span\u003e”\u003c/span\u003e. Since \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e knows both \u003cem class=\"replaceable\"\u003e\u003ccode\u003eX\u003c/code\u003e\u003c/em\u003e and \u003cem class=\"replaceable\"\u003e\u003ccode\u003eY\u003c/code\u003e\u003c/em\u003e when a physical connection is established, it can interrogate the ident server on the host of the connecting client and can theoretically determine the operating system user for any given connection.\u003c/p\u003e\n\u003cp\u003eThe drawback of this procedure is that it depends on the integrity of the client: if the client machine is untrusted or compromised, an attacker could run just about any program on port 113 and return any user name they choose. This authentication method is therefore only appropriate for closed networks where each client machine is under tight control and where the database and system administrators operate in close contact. In other words, you must trust the machine running the ident server. Heed the warning:\u003c/p\u003e\n\u003cdiv class=\"blockquote\"\u003e\n\u003ctable class=\"blockquote\"\u003e\n\u003ctbody\u003e\u003ctr\u003e\n\u003ctd\u003e \u003c/td\u003e\n\u003ctd\u003e\n\u003cp\u003eThe Identification Protocol is not intended as an authorization or access control protocol.\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd\u003e \u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e \u003c/td\u003e\n\u003ctd colspan=\"2\"\u003e--\u003cspan class=\"attribution\"\u003eRFC 1413\u003c/span\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\u003c/table\u003e\n\u003c/div\u003e\n\u003cp\u003eSome ident servers have a nonstandard option that causes the returned user name to be encrypted, using a key that only the originating machine's administrator knows. This option \u003cspan class=\"emphasis\"\u003e\u003cem\u003emust not\u003c/em\u003e\u003c/span\u003e be used when using the ident server with \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e, since \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e does not have any way to decrypt the returned string to determine the actual user name.\u003c/p\u003e\n\u003c/div\u003e","related":[],"sections":[],"tables":[{"columns":[{"key":"name","label":"Option or term"},{"key":"description","label":"Meaning"}],"key":"method-options","rows":[{"description":"Allows for mapping between system and database user names. See Section 20.2 for details.","name":"map"}],"title":"Documented method options and alternatives"}]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
