{"Entry":{"collection":"auth","key":"ldap","name":"ldap","aliases":[],"metadata":{"aliases":[],"category":"Authentication and access control","content_hash":"ae824155a303611e373ba06485a3b0be060ce3d086a7d1e822b3206d1013ea1a","imported_at":"2026-09-30T00:40:33.296867+08:00","name":"ldap","name_zh":"","slug":"ldap","summary":"Authenticate using an LDAP server. See Section 20.10 for details."}},"Definition":{"Collection":"auth","Key":"ldap","SourceDatabase":"center","Version":"18","SourceTable":"authentication_method","SourceKey":"ldap","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","Facts":{"aliases":[],"attributes":{"configuration":"pg_hba.conf","inventory":"User-visible source authentication method","method":"ldap"},"comparison_data":{"documented_option_names":["ldapbasedn","ldapbinddn","ldapbindpasswd","ldapport","ldapprefix","ldapscheme","ldapsearchattribute","ldapsearchfilter","ldapserver","ldapsuffix","ldaptls","ldapurl"],"method":"ldap"},"comparison_hash":"d40de945ae67b3ac60a284fdd442cc24a4e9d05bc7a7b18009b54e491c381b88","description":["Authenticate using an LDAP server. See Section 20.10 for details."],"facts":[{"label":"Method","value":"ldap"},{"label":"Configuration","value":"pg_hba.conf"},{"label":"Inventory","value":"User-visible source authentication method"}],"manual_html":"\u003cdiv class=\"sect1\" id=\"AUTH-LDAP\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e20.10. LDAP Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThis authentication method operates similarly to \u003ccode class=\"literal\"\u003epassword\u003c/code\u003e except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.\u003c/p\u003e\n\u003cp\u003eLDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as \u003cem class=\"replaceable\"\u003e\u003ccode\u003eprefix\u003c/code\u003e\u003c/em\u003e \u003cem class=\"replaceable\"\u003e\u003ccode\u003eusername\u003c/code\u003e\u003c/em\u003e \u003cem class=\"replaceable\"\u003e\u003ccode\u003esuffix\u003c/code\u003e\u003c/em\u003e. Typically, the \u003cem class=\"replaceable\"\u003e\u003ccode\u003eprefix\u003c/code\u003e\u003c/em\u003e parameter is used to specify \u003ccode class=\"literal\"\u003ecn=\u003c/code\u003e, or \u003cem class=\"replaceable\"\u003e\u003ccode\u003eDOMAIN\u003c/code\u003e\u003c/em\u003e\u003ccode class=\"literal\"\u003e\\\u003c/code\u003e in an Active Directory environment. \u003cem class=\"replaceable\"\u003e\u003ccode\u003esuffix\u003c/code\u003e\u003c/em\u003e is used to specify the remaining part of the DN in a non-Active Directory environment.\u003c/p\u003e\n\u003cp\u003eIn the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with \u003cem class=\"replaceable\"\u003e\u003ccode\u003eldapbinddn\u003c/code\u003e\u003c/em\u003e and \u003cem class=\"replaceable\"\u003e\u003ccode\u003eldapbindpasswd\u003c/code\u003e\u003c/em\u003e, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at \u003cem class=\"replaceable\"\u003e\u003ccode\u003eldapbasedn\u003c/code\u003e\u003c/em\u003e, and will try to do an exact match of the attribute specified in \u003cem class=\"replaceable\"\u003e\u003ccode\u003eldapsearchattribute\u003c/code\u003e\u003c/em\u003e. Once the user has been found in this search, the server re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache \u003ccode class=\"literal\"\u003emod_authnz_ldap\u003c/code\u003e and \u003ccode class=\"literal\"\u003epam_ldap\u003c/code\u003e. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two additional requests to the LDAP server to be made.\u003c/p\u003e\n\u003cp\u003eThe following configuration options are used in both modes:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapserver\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eNames or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapport\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003ePort number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapscheme\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eSet to \u003ccode class=\"literal\"\u003eldaps\u003c/code\u003e to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the \u003ccode class=\"literal\"\u003eldaptls\u003c/code\u003e option for an alternative.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldaptls\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eSet to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the \u003ccode class=\"literal\"\u003eStartTLS\u003c/code\u003e operation per \u003ca class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4513\"\u003eRFC 4513\u003c/a\u003e. See also the \u003ccode class=\"literal\"\u003eldapscheme\u003c/code\u003e option for an alternative.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eNote that using \u003ccode class=\"literal\"\u003eldapscheme\u003c/code\u003e or \u003ccode class=\"literal\"\u003eldaptls\u003c/code\u003e only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.\u003c/p\u003e\n\u003cp\u003eThe following options are used in simple bind mode only:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapprefix\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eString to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapsuffix\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eString to append to the user name when forming the DN to bind as, when doing simple bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eThe following options are used in search+bind mode only:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapbasedn\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eRoot DN to begin the search for the user in, when doing search+bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapbinddn\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eDN of user to bind to the directory with to perform the search when doing search+bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapbindpasswd\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003ePassword for user to bind to the directory with to perform the search when doing search+bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapsearchattribute\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAttribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the \u003ccode class=\"literal\"\u003euid\u003c/code\u003e attribute will be used.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapsearchfilter\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eThe search filter to use when doing search+bind authentication. Occurrences of \u003ccode class=\"literal\"\u003e$username\u003c/code\u003e will be replaced with the user name. This allows for more flexible search filters than \u003ccode class=\"literal\"\u003eldapsearchattribute\u003c/code\u003e.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eThe following option may be used as an alternative way to write some of the above LDAP options in a more compact and standard form:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapurl\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAn \u003ca class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\"\u003eRFC 4516\u003c/a\u003e LDAP URL. The format is\u003c/p\u003e\n\u003cpre class=\"synopsis\"\u003eldap[s]://\u003cem class=\"replaceable\"\u003e\u003ccode\u003ehost\u003c/code\u003e\u003c/em\u003e[:\u003cem class=\"replaceable\"\u003e\u003ccode\u003eport\u003c/code\u003e\u003c/em\u003e]/\u003cem class=\"replaceable\"\u003e\u003ccode\u003ebasedn\u003c/code\u003e\u003c/em\u003e[?[\u003cem class=\"replaceable\"\u003e\u003ccode\u003eattribute\u003c/code\u003e\u003c/em\u003e][?[\u003cem class=\"replaceable\"\u003e\u003ccode\u003escope\u003c/code\u003e\u003c/em\u003e][?[\u003cem class=\"replaceable\"\u003e\u003ccode\u003efilter\u003c/code\u003e\u003c/em\u003e]]]]\n\u003c/pre\u003e\n\u003cp\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003escope\u003c/code\u003e\u003c/em\u003e must be one of \u003ccode class=\"literal\"\u003ebase\u003c/code\u003e, \u003ccode class=\"literal\"\u003eone\u003c/code\u003e, \u003ccode class=\"literal\"\u003esub\u003c/code\u003e, typically the last. (The default is \u003ccode class=\"literal\"\u003ebase\u003c/code\u003e, which is normally not useful in this application.) \u003cem class=\"replaceable\"\u003e\u003ccode\u003eattribute\u003c/code\u003e\u003c/em\u003e can nominate a single attribute, in which case it is used as a value for \u003ccode class=\"literal\"\u003eldapsearchattribute\u003c/code\u003e. If \u003cem class=\"replaceable\"\u003e\u003ccode\u003eattribute\u003c/code\u003e\u003c/em\u003e is empty then \u003cem class=\"replaceable\"\u003e\u003ccode\u003efilter\u003c/code\u003e\u003c/em\u003e can be used as a value for \u003ccode class=\"literal\"\u003eldapsearchfilter\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThe URL scheme \u003ccode class=\"literal\"\u003eldaps\u003c/code\u003e chooses the LDAPS method for making LDAP connections over SSL, equivalent to using \u003ccode class=\"literal\"\u003eldapscheme=ldaps\u003c/code\u003e. To use encrypted LDAP connections using the \u003ccode class=\"literal\"\u003eStartTLS\u003c/code\u003e operation, use the normal URL scheme \u003ccode class=\"literal\"\u003eldap\u003c/code\u003e and specify the \u003ccode class=\"literal\"\u003eldaptls\u003c/code\u003e option in addition to \u003ccode class=\"literal\"\u003eldapurl\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eFor non-anonymous binds, \u003ccode class=\"literal\"\u003eldapbinddn\u003c/code\u003e and \u003ccode class=\"literal\"\u003eldapbindpasswd\u003c/code\u003e must be specified as separate options.\u003c/p\u003e\n\u003cp\u003eLDAP URLs are currently only supported with \u003cspan class=\"productname\"\u003eOpenLDAP\u003c/span\u003e, not on Windows.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eIt is an error to mix configuration options for simple bind with options for search+bind. To use \u003ccode class=\"literal\"\u003eldapurl\u003c/code\u003e in simple bind mode, the URL must not contain a \u003ccode class=\"literal\"\u003ebasedn\u003c/code\u003e or query elements.\u003c/p\u003e\n\u003cp\u003eWhen using search+bind mode, the search can be performed using a single attribute specified with \u003ccode class=\"literal\"\u003eldapsearchattribute\u003c/code\u003e, or using a custom search filter specified with \u003ccode class=\"literal\"\u003eldapsearchfilter\u003c/code\u003e. Specifying \u003ccode class=\"literal\"\u003eldapsearchattribute=foo\u003c/code\u003e is equivalent to specifying \u003ccode class=\"literal\"\u003eldapsearchfilter=\"(foo=$username)\"\u003c/code\u003e. If neither option is specified the default is \u003ccode class=\"literal\"\u003eldapsearchattribute=uid\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIf \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e was compiled with \u003cspan class=\"productname\"\u003eOpenLDAP\u003c/span\u003e as the LDAP client library, the \u003ccode class=\"literal\"\u003eldapserver\u003c/code\u003e setting may be omitted. In that case, a list of host names and ports is looked up via \u003ca class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\"\u003eRFC 2782\u003c/a\u003e DNS SRV records. The name \u003ccode class=\"literal\"\u003e_ldap._tcp.DOMAIN\u003c/code\u003e is looked up, where \u003ccode class=\"literal\"\u003eDOMAIN\u003c/code\u003e is extracted from \u003ccode class=\"literal\"\u003eldapbasedn\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eHere is an example for a simple-bind LDAP configuration:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n\u003c/pre\u003e\n\u003cp\u003eWhen a connection to the database server as database user \u003ccode class=\"literal\"\u003esomeuser\u003c/code\u003e is requested, PostgreSQL will attempt to bind to the LDAP server using the DN \u003ccode class=\"literal\"\u003ecn=someuser, dc=example, dc=net\u003c/code\u003e and the password provided by the client. If that connection succeeds, the database access is granted.\u003c/p\u003e\n\u003cp\u003eHere is a different simple-bind configuration, which uses the LDAPS scheme and a custom port number, written as a URL:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapurl=\"ldaps://ldap.example.net:49151\" ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n\u003c/pre\u003e\n\u003cp\u003eThis is slightly more compact than specifying \u003ccode class=\"literal\"\u003eldapserver\u003c/code\u003e, \u003ccode class=\"literal\"\u003eldapscheme\u003c/code\u003e, and \u003ccode class=\"literal\"\u003eldapport\u003c/code\u003e separately.\u003c/p\u003e\n\u003cp\u003eHere is an example for a search+bind configuration:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n\u003c/pre\u003e\n\u003cp\u003eWhen a connection to the database server as database user \u003ccode class=\"literal\"\u003esomeuser\u003c/code\u003e is requested, PostgreSQL will attempt to bind anonymously (since \u003ccode class=\"literal\"\u003eldapbinddn\u003c/code\u003e was not specified) to the LDAP server, perform a search for \u003ccode class=\"literal\"\u003e(uid=someuser)\u003c/code\u003e under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second bind succeeds, the database access is granted.\u003c/p\u003e\n\u003cp\u003eHere is the same search+bind configuration written as a URL:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n\u003c/pre\u003e\n\u003cp\u003eSome other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.\u003c/p\u003e\n\u003cp\u003eHere is an example for a search+bind configuration that uses \u003ccode class=\"literal\"\u003eldapsearchfilter\u003c/code\u003e instead of \u003ccode class=\"literal\"\u003eldapsearchattribute\u003c/code\u003e to allow authentication by user ID or email address:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n\u003c/pre\u003e\n\u003cp\u003eHere is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name \u003ccode class=\"literal\"\u003eexample.net\u003c/code\u003e:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapbasedn=\"dc=example,dc=net\"\n\u003c/pre\u003e\n\u003cdiv class=\"tip\"\u003e\n\u003ch3 class=\"title\"\u003eTip\u003c/h3\u003e\n\u003cp\u003eSince LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/div\u003e","manual_path":"/docs/18/auth-ldap.html","related":[],"release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sections":[],"signature":"","sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"auth-ldap.html","sha256":"8f02f50758b63b0d9a9011b2c3c1ee12e8caa3830408f5ea5d97e0e81ee52628","url":"/docs/18/auth-ldap.html"},{"label":"PostgreSQL 18 English manual","path":"auth-pg-hba-conf.html","sha256":"6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9","url":"/docs/18/auth-pg-hba-conf.html"}],"tables":[{"columns":[{"key":"name","label":"Option or term"},{"key":"description","label":"Meaning"}],"key":"method-options","rows":[{"description":"Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.","name":"ldapserver"},{"description":"Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.","name":"ldapport"},{"description":"Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.","name":"ldapscheme"},{"description":"Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative.","name":"ldaptls"},{"description":"String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.","name":"ldapprefix"},{"description":"String to append to the user name when forming the DN to bind as, when doing simple bind authentication.","name":"ldapsuffix"},{"description":"Root DN to begin the search for the user in, when doing search+bind authentication.","name":"ldapbasedn"},{"description":"DN of user to bind to the directory with to perform the search when doing search+bind authentication.","name":"ldapbinddn"},{"description":"Password for user to bind to the directory with to perform the search when doing search+bind authentication.","name":"ldapbindpasswd"},{"description":"Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.","name":"ldapsearchattribute"},{"description":"The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .","name":"ldapsearchfilter"},{"description":"An RFC 4516 LDAP URL. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows.","name":"ldapurl"}],"title":"Documented method options and alternatives"}]},"ManualEvidence":{"manual_path":"/docs/18/auth-ldap.html","release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"auth-ldap.html","sha256":"8f02f50758b63b0d9a9011b2c3c1ee12e8caa3830408f5ea5d97e0e81ee52628","url":"/docs/18/auth-ldap.html"},{"label":"PostgreSQL 18 English manual","path":"auth-pg-hba-conf.html","sha256":"6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9","url":"/docs/18/auth-pg-hba-conf.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"auth","Key":"ldap","SourceDatabase":"center","Version":"18","Locale":"en","Title":"ldap","Summary":"Authenticate using an LDAP server. See Section 20.10 for details.","BodyHTML":"\u003cdiv id=\"AUTH-LDAP\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2\u003e20.10. LDAP Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThis authentication method operates similarly to \u003ccode\u003epassword\u003c/code\u003e except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.\u003c/p\u003e\n\u003cp\u003eLDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as \u003cem\u003e\u003ccode\u003eprefix\u003c/code\u003e\u003c/em\u003e \u003cem\u003e\u003ccode\u003eusername\u003c/code\u003e\u003c/em\u003e \u003cem\u003e\u003ccode\u003esuffix\u003c/code\u003e\u003c/em\u003e. Typically, the \u003cem\u003e\u003ccode\u003eprefix\u003c/code\u003e\u003c/em\u003e parameter is used to specify \u003ccode\u003ecn=\u003c/code\u003e, or \u003cem\u003e\u003ccode\u003eDOMAIN\u003c/code\u003e\u003c/em\u003e\u003ccode\u003e\\\u003c/code\u003e in an Active Directory environment. \u003cem\u003e\u003ccode\u003esuffix\u003c/code\u003e\u003c/em\u003e is used to specify the remaining part of the DN in a non-Active Directory environment.\u003c/p\u003e\n\u003cp\u003eIn the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with \u003cem\u003e\u003ccode\u003eldapbinddn\u003c/code\u003e\u003c/em\u003e and \u003cem\u003e\u003ccode\u003eldapbindpasswd\u003c/code\u003e\u003c/em\u003e, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at \u003cem\u003e\u003ccode\u003eldapbasedn\u003c/code\u003e\u003c/em\u003e, and will try to do an exact match of the attribute specified in \u003cem\u003e\u003ccode\u003eldapsearchattribute\u003c/code\u003e\u003c/em\u003e. Once the user has been found in this search, the server re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache \u003ccode\u003emod_authnz_ldap\u003c/code\u003e and \u003ccode\u003epam_ldap\u003c/code\u003e. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two additional requests to the LDAP server to be made.\u003c/p\u003e\n\u003cp\u003eThe following configuration options are used in both modes:\u003c/p\u003e\n\u003cdiv\u003e\n\u003cdl\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapserver\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eNames or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapport\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003ePort number on LDAP server to connect to. If no port is specified, the LDAP library\u0026#39;s default port setting will be used.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapscheme\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eSet to \u003ccode\u003eldaps\u003c/code\u003e to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the \u003ccode\u003eldaptls\u003c/code\u003e option for an alternative.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldaptls\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eSet to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the \u003ccode\u003eStartTLS\u003c/code\u003e operation per \u003ca href=\"https://datatracker.ietf.org/doc/html/rfc4513\" rel=\"nofollow\"\u003eRFC 4513\u003c/a\u003e. See also the \u003ccode\u003eldapscheme\u003c/code\u003e option for an alternative.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eNote that using \u003ccode\u003eldapscheme\u003c/code\u003e or \u003ccode\u003eldaptls\u003c/code\u003e only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.\u003c/p\u003e\n\u003cp\u003eThe following options are used in simple bind mode only:\u003c/p\u003e\n\u003cdiv\u003e\n\u003cdl\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapprefix\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eString to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapsuffix\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eString to append to the user name when forming the DN to bind as, when doing simple bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eThe following options are used in search+bind mode only:\u003c/p\u003e\n\u003cdiv\u003e\n\u003cdl\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapbasedn\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eRoot DN to begin the search for the user in, when doing search+bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapbinddn\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eDN of user to bind to the directory with to perform the search when doing search+bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapbindpasswd\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003ePassword for user to bind to the directory with to perform the search when doing search+bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapsearchattribute\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAttribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the \u003ccode\u003euid\u003c/code\u003e attribute will be used.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapsearchfilter\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eThe search filter to use when doing search+bind authentication. Occurrences of \u003ccode\u003e$username\u003c/code\u003e will be replaced with the user name. This allows for more flexible search filters than \u003ccode\u003eldapsearchattribute\u003c/code\u003e.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eThe following option may be used as an alternative way to write some of the above LDAP options in a more compact and standard form:\u003c/p\u003e\n\u003cdiv\u003e\n\u003cdl\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eldapurl\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAn \u003ca href=\"https://datatracker.ietf.org/doc/html/rfc4516\" rel=\"nofollow\"\u003eRFC 4516\u003c/a\u003e LDAP URL. The format is\u003c/p\u003e\n\u003cpre\u003eldap[s]://\u003cem\u003e\u003ccode\u003ehost\u003c/code\u003e\u003c/em\u003e[:\u003cem\u003e\u003ccode\u003eport\u003c/code\u003e\u003c/em\u003e]/\u003cem\u003e\u003ccode\u003ebasedn\u003c/code\u003e\u003c/em\u003e[?[\u003cem\u003e\u003ccode\u003eattribute\u003c/code\u003e\u003c/em\u003e][?[\u003cem\u003e\u003ccode\u003escope\u003c/code\u003e\u003c/em\u003e][?[\u003cem\u003e\u003ccode\u003efilter\u003c/code\u003e\u003c/em\u003e]]]]\n\u003c/pre\u003e\n\u003cp\u003e\u003cem\u003e\u003ccode\u003escope\u003c/code\u003e\u003c/em\u003e must be one of \u003ccode\u003ebase\u003c/code\u003e, \u003ccode\u003eone\u003c/code\u003e, \u003ccode\u003esub\u003c/code\u003e, typically the last. (The default is \u003ccode\u003ebase\u003c/code\u003e, which is normally not useful in this application.) \u003cem\u003e\u003ccode\u003eattribute\u003c/code\u003e\u003c/em\u003e can nominate a single attribute, in which case it is used as a value for \u003ccode\u003eldapsearchattribute\u003c/code\u003e. If \u003cem\u003e\u003ccode\u003eattribute\u003c/code\u003e\u003c/em\u003e is empty then \u003cem\u003e\u003ccode\u003efilter\u003c/code\u003e\u003c/em\u003e can be used as a value for \u003ccode\u003eldapsearchfilter\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThe URL scheme \u003ccode\u003eldaps\u003c/code\u003e chooses the LDAPS method for making LDAP connections over SSL, equivalent to using \u003ccode\u003eldapscheme=ldaps\u003c/code\u003e. To use encrypted LDAP connections using the \u003ccode\u003eStartTLS\u003c/code\u003e operation, use the normal URL scheme \u003ccode\u003eldap\u003c/code\u003e and specify the \u003ccode\u003eldaptls\u003c/code\u003e option in addition to \u003ccode\u003eldapurl\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eFor non-anonymous binds, \u003ccode\u003eldapbinddn\u003c/code\u003e and \u003ccode\u003eldapbindpasswd\u003c/code\u003e must be specified as separate options.\u003c/p\u003e\n\u003cp\u003eLDAP URLs are currently only supported with \u003cspan\u003eOpenLDAP\u003c/span\u003e, not on Windows.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eIt is an error to mix configuration options for simple bind with options for search+bind. To use \u003ccode\u003eldapurl\u003c/code\u003e in simple bind mode, the URL must not contain a \u003ccode\u003ebasedn\u003c/code\u003e or query elements.\u003c/p\u003e\n\u003cp\u003eWhen using search+bind mode, the search can be performed using a single attribute specified with \u003ccode\u003eldapsearchattribute\u003c/code\u003e, or using a custom search filter specified with \u003ccode\u003eldapsearchfilter\u003c/code\u003e. Specifying \u003ccode\u003eldapsearchattribute=foo\u003c/code\u003e is equivalent to specifying \u003ccode\u003eldapsearchfilter=\u0026#34;(foo=$username)\u0026#34;\u003c/code\u003e. If neither option is specified the default is \u003ccode\u003eldapsearchattribute=uid\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIf \u003cspan\u003ePostgreSQL\u003c/span\u003e was compiled with \u003cspan\u003eOpenLDAP\u003c/span\u003e as the LDAP client library, the \u003ccode\u003eldapserver\u003c/code\u003e setting may be omitted. In that case, a list of host names and ports is looked up via \u003ca href=\"https://datatracker.ietf.org/doc/html/rfc2782\" rel=\"nofollow\"\u003eRFC 2782\u003c/a\u003e DNS SRV records. The name \u003ccode\u003e_ldap._tcp.DOMAIN\u003c/code\u003e is looked up, where \u003ccode\u003eDOMAIN\u003c/code\u003e is extracted from \u003ccode\u003eldapbasedn\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eHere is an example for a simple-bind LDAP configuration:\u003c/p\u003e\n\u003cpre\u003ehost ... ldap ldapserver=ldap.example.net ldapprefix=\u0026#34;cn=\u0026#34; ldapsuffix=\u0026#34;, dc=example, dc=net\u0026#34;\n\u003c/pre\u003e\n\u003cp\u003eWhen a connection to the database server as database user \u003ccode\u003esomeuser\u003c/code\u003e is requested, PostgreSQL will attempt to bind to the LDAP server using the DN \u003ccode\u003ecn=someuser, dc=example, dc=net\u003c/code\u003e and the password provided by the client. If that connection succeeds, the database access is granted.\u003c/p\u003e\n\u003cp\u003eHere is a different simple-bind configuration, which uses the LDAPS scheme and a custom port number, written as a URL:\u003c/p\u003e\n\u003cpre\u003ehost ... ldap ldapurl=\u0026#34;ldaps://ldap.example.net:49151\u0026#34; ldapprefix=\u0026#34;cn=\u0026#34; ldapsuffix=\u0026#34;, dc=example, dc=net\u0026#34;\n\u003c/pre\u003e\n\u003cp\u003eThis is slightly more compact than specifying \u003ccode\u003eldapserver\u003c/code\u003e, \u003ccode\u003eldapscheme\u003c/code\u003e, and \u003ccode\u003eldapport\u003c/code\u003e separately.\u003c/p\u003e\n\u003cp\u003eHere is an example for a search+bind configuration:\u003c/p\u003e\n\u003cpre\u003ehost ... ldap ldapserver=ldap.example.net ldapbasedn=\u0026#34;dc=example, dc=net\u0026#34; ldapsearchattribute=uid\n\u003c/pre\u003e\n\u003cp\u003eWhen a connection to the database server as database user \u003ccode\u003esomeuser\u003c/code\u003e is requested, PostgreSQL will attempt to bind anonymously (since \u003ccode\u003eldapbinddn\u003c/code\u003e was not specified) to the LDAP server, perform a search for \u003ccode\u003e(uid=someuser)\u003c/code\u003e under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second bind succeeds, the database access is granted.\u003c/p\u003e\n\u003cp\u003eHere is the same search+bind configuration written as a URL:\u003c/p\u003e\n\u003cpre\u003ehost ... ldap ldapurl=\u0026#34;ldap://ldap.example.net/dc=example,dc=net?uid?sub\u0026#34;\n\u003c/pre\u003e\n\u003cp\u003eSome other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.\u003c/p\u003e\n\u003cp\u003eHere is an example for a search+bind configuration that uses \u003ccode\u003eldapsearchfilter\u003c/code\u003e instead of \u003ccode\u003eldapsearchattribute\u003c/code\u003e to allow authentication by user ID or email address:\u003c/p\u003e\n\u003cpre\u003ehost ... ldap ldapserver=ldap.example.net ldapbasedn=\u0026#34;dc=example, dc=net\u0026#34; ldapsearchfilter=\u0026#34;(|(uid=$username)(mail=$username))\u0026#34;\n\u003c/pre\u003e\n\u003cp\u003eHere is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name \u003ccode\u003eexample.net\u003c/code\u003e:\u003c/p\u003e\n\u003cpre\u003ehost ... ldap ldapbasedn=\u0026#34;dc=example,dc=net\u0026#34;\n\u003c/pre\u003e\n\u003cdiv\u003e\n\u003ch3\u003eTip\u003c/h3\u003e\n\u003cp\u003eSince LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/div\u003e","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","ContentHash":"693316270287bacad0a5a6f1502f21f5c3d51a4b8bad6a9840c18873ef8f89bd","Payload":{"description":["Authenticate using an LDAP server. See Section 20.10 for details."],"manual_html":"\u003cdiv class=\"sect1\" id=\"AUTH-LDAP\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e20.10. LDAP Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThis authentication method operates similarly to \u003ccode class=\"literal\"\u003epassword\u003c/code\u003e except that it uses LDAP as the password verification method. LDAP is used only to validate the user name/password pairs. Therefore the user must already exist in the database before LDAP can be used for authentication.\u003c/p\u003e\n\u003cp\u003eLDAP authentication can operate in two modes. In the first mode, which we will call the simple bind mode, the server will bind to the distinguished name constructed as \u003cem class=\"replaceable\"\u003e\u003ccode\u003eprefix\u003c/code\u003e\u003c/em\u003e \u003cem class=\"replaceable\"\u003e\u003ccode\u003eusername\u003c/code\u003e\u003c/em\u003e \u003cem class=\"replaceable\"\u003e\u003ccode\u003esuffix\u003c/code\u003e\u003c/em\u003e. Typically, the \u003cem class=\"replaceable\"\u003e\u003ccode\u003eprefix\u003c/code\u003e\u003c/em\u003e parameter is used to specify \u003ccode class=\"literal\"\u003ecn=\u003c/code\u003e, or \u003cem class=\"replaceable\"\u003e\u003ccode\u003eDOMAIN\u003c/code\u003e\u003c/em\u003e\u003ccode class=\"literal\"\u003e\\\u003c/code\u003e in an Active Directory environment. \u003cem class=\"replaceable\"\u003e\u003ccode\u003esuffix\u003c/code\u003e\u003c/em\u003e is used to specify the remaining part of the DN in a non-Active Directory environment.\u003c/p\u003e\n\u003cp\u003eIn the second mode, which we will call the search+bind mode, the server first binds to the LDAP directory with a fixed user name and password, specified with \u003cem class=\"replaceable\"\u003e\u003ccode\u003eldapbinddn\u003c/code\u003e\u003c/em\u003e and \u003cem class=\"replaceable\"\u003e\u003ccode\u003eldapbindpasswd\u003c/code\u003e\u003c/em\u003e, and performs a search for the user trying to log in to the database. If no user and password is configured, an anonymous bind will be attempted to the directory. The search will be performed over the subtree at \u003cem class=\"replaceable\"\u003e\u003ccode\u003eldapbasedn\u003c/code\u003e\u003c/em\u003e, and will try to do an exact match of the attribute specified in \u003cem class=\"replaceable\"\u003e\u003ccode\u003eldapsearchattribute\u003c/code\u003e\u003c/em\u003e. Once the user has been found in this search, the server re-binds to the directory as this user, using the password specified by the client, to verify that the login is correct. This mode is the same as that used by LDAP authentication schemes in other software, such as Apache \u003ccode class=\"literal\"\u003emod_authnz_ldap\u003c/code\u003e and \u003ccode class=\"literal\"\u003epam_ldap\u003c/code\u003e. This method allows for significantly more flexibility in where the user objects are located in the directory, but will cause two additional requests to the LDAP server to be made.\u003c/p\u003e\n\u003cp\u003eThe following configuration options are used in both modes:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapserver\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eNames or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapport\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003ePort number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapscheme\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eSet to \u003ccode class=\"literal\"\u003eldaps\u003c/code\u003e to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the \u003ccode class=\"literal\"\u003eldaptls\u003c/code\u003e option for an alternative.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldaptls\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eSet to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the \u003ccode class=\"literal\"\u003eStartTLS\u003c/code\u003e operation per \u003ca class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4513\"\u003eRFC 4513\u003c/a\u003e. See also the \u003ccode class=\"literal\"\u003eldapscheme\u003c/code\u003e option for an alternative.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eNote that using \u003ccode class=\"literal\"\u003eldapscheme\u003c/code\u003e or \u003ccode class=\"literal\"\u003eldaptls\u003c/code\u003e only encrypts the traffic between the PostgreSQL server and the LDAP server. The connection between the PostgreSQL server and the PostgreSQL client will still be unencrypted unless SSL is used there as well.\u003c/p\u003e\n\u003cp\u003eThe following options are used in simple bind mode only:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapprefix\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eString to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapsuffix\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eString to append to the user name when forming the DN to bind as, when doing simple bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eThe following options are used in search+bind mode only:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapbasedn\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eRoot DN to begin the search for the user in, when doing search+bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapbinddn\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eDN of user to bind to the directory with to perform the search when doing search+bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapbindpasswd\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003ePassword for user to bind to the directory with to perform the search when doing search+bind authentication.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapsearchattribute\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAttribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the \u003ccode class=\"literal\"\u003euid\u003c/code\u003e attribute will be used.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapsearchfilter\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eThe search filter to use when doing search+bind authentication. Occurrences of \u003ccode class=\"literal\"\u003e$username\u003c/code\u003e will be replaced with the user name. This allows for more flexible search filters than \u003ccode class=\"literal\"\u003eldapsearchattribute\u003c/code\u003e.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eThe following option may be used as an alternative way to write some of the above LDAP options in a more compact and standard form:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eldapurl\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eAn \u003ca class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc4516\"\u003eRFC 4516\u003c/a\u003e LDAP URL. The format is\u003c/p\u003e\n\u003cpre class=\"synopsis\"\u003eldap[s]://\u003cem class=\"replaceable\"\u003e\u003ccode\u003ehost\u003c/code\u003e\u003c/em\u003e[:\u003cem class=\"replaceable\"\u003e\u003ccode\u003eport\u003c/code\u003e\u003c/em\u003e]/\u003cem class=\"replaceable\"\u003e\u003ccode\u003ebasedn\u003c/code\u003e\u003c/em\u003e[?[\u003cem class=\"replaceable\"\u003e\u003ccode\u003eattribute\u003c/code\u003e\u003c/em\u003e][?[\u003cem class=\"replaceable\"\u003e\u003ccode\u003escope\u003c/code\u003e\u003c/em\u003e][?[\u003cem class=\"replaceable\"\u003e\u003ccode\u003efilter\u003c/code\u003e\u003c/em\u003e]]]]\n\u003c/pre\u003e\n\u003cp\u003e\u003cem class=\"replaceable\"\u003e\u003ccode\u003escope\u003c/code\u003e\u003c/em\u003e must be one of \u003ccode class=\"literal\"\u003ebase\u003c/code\u003e, \u003ccode class=\"literal\"\u003eone\u003c/code\u003e, \u003ccode class=\"literal\"\u003esub\u003c/code\u003e, typically the last. (The default is \u003ccode class=\"literal\"\u003ebase\u003c/code\u003e, which is normally not useful in this application.) \u003cem class=\"replaceable\"\u003e\u003ccode\u003eattribute\u003c/code\u003e\u003c/em\u003e can nominate a single attribute, in which case it is used as a value for \u003ccode class=\"literal\"\u003eldapsearchattribute\u003c/code\u003e. If \u003cem class=\"replaceable\"\u003e\u003ccode\u003eattribute\u003c/code\u003e\u003c/em\u003e is empty then \u003cem class=\"replaceable\"\u003e\u003ccode\u003efilter\u003c/code\u003e\u003c/em\u003e can be used as a value for \u003ccode class=\"literal\"\u003eldapsearchfilter\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThe URL scheme \u003ccode class=\"literal\"\u003eldaps\u003c/code\u003e chooses the LDAPS method for making LDAP connections over SSL, equivalent to using \u003ccode class=\"literal\"\u003eldapscheme=ldaps\u003c/code\u003e. To use encrypted LDAP connections using the \u003ccode class=\"literal\"\u003eStartTLS\u003c/code\u003e operation, use the normal URL scheme \u003ccode class=\"literal\"\u003eldap\u003c/code\u003e and specify the \u003ccode class=\"literal\"\u003eldaptls\u003c/code\u003e option in addition to \u003ccode class=\"literal\"\u003eldapurl\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eFor non-anonymous binds, \u003ccode class=\"literal\"\u003eldapbinddn\u003c/code\u003e and \u003ccode class=\"literal\"\u003eldapbindpasswd\u003c/code\u003e must be specified as separate options.\u003c/p\u003e\n\u003cp\u003eLDAP URLs are currently only supported with \u003cspan class=\"productname\"\u003eOpenLDAP\u003c/span\u003e, not on Windows.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eIt is an error to mix configuration options for simple bind with options for search+bind. To use \u003ccode class=\"literal\"\u003eldapurl\u003c/code\u003e in simple bind mode, the URL must not contain a \u003ccode class=\"literal\"\u003ebasedn\u003c/code\u003e or query elements.\u003c/p\u003e\n\u003cp\u003eWhen using search+bind mode, the search can be performed using a single attribute specified with \u003ccode class=\"literal\"\u003eldapsearchattribute\u003c/code\u003e, or using a custom search filter specified with \u003ccode class=\"literal\"\u003eldapsearchfilter\u003c/code\u003e. Specifying \u003ccode class=\"literal\"\u003eldapsearchattribute=foo\u003c/code\u003e is equivalent to specifying \u003ccode class=\"literal\"\u003eldapsearchfilter=\"(foo=$username)\"\u003c/code\u003e. If neither option is specified the default is \u003ccode class=\"literal\"\u003eldapsearchattribute=uid\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIf \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e was compiled with \u003cspan class=\"productname\"\u003eOpenLDAP\u003c/span\u003e as the LDAP client library, the \u003ccode class=\"literal\"\u003eldapserver\u003c/code\u003e setting may be omitted. In that case, a list of host names and ports is looked up via \u003ca class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2782\"\u003eRFC 2782\u003c/a\u003e DNS SRV records. The name \u003ccode class=\"literal\"\u003e_ldap._tcp.DOMAIN\u003c/code\u003e is looked up, where \u003ccode class=\"literal\"\u003eDOMAIN\u003c/code\u003e is extracted from \u003ccode class=\"literal\"\u003eldapbasedn\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eHere is an example for a simple-bind LDAP configuration:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapserver=ldap.example.net ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n\u003c/pre\u003e\n\u003cp\u003eWhen a connection to the database server as database user \u003ccode class=\"literal\"\u003esomeuser\u003c/code\u003e is requested, PostgreSQL will attempt to bind to the LDAP server using the DN \u003ccode class=\"literal\"\u003ecn=someuser, dc=example, dc=net\u003c/code\u003e and the password provided by the client. If that connection succeeds, the database access is granted.\u003c/p\u003e\n\u003cp\u003eHere is a different simple-bind configuration, which uses the LDAPS scheme and a custom port number, written as a URL:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapurl=\"ldaps://ldap.example.net:49151\" ldapprefix=\"cn=\" ldapsuffix=\", dc=example, dc=net\"\n\u003c/pre\u003e\n\u003cp\u003eThis is slightly more compact than specifying \u003ccode class=\"literal\"\u003eldapserver\u003c/code\u003e, \u003ccode class=\"literal\"\u003eldapscheme\u003c/code\u003e, and \u003ccode class=\"literal\"\u003eldapport\u003c/code\u003e separately.\u003c/p\u003e\n\u003cp\u003eHere is an example for a search+bind configuration:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchattribute=uid\n\u003c/pre\u003e\n\u003cp\u003eWhen a connection to the database server as database user \u003ccode class=\"literal\"\u003esomeuser\u003c/code\u003e is requested, PostgreSQL will attempt to bind anonymously (since \u003ccode class=\"literal\"\u003eldapbinddn\u003c/code\u003e was not specified) to the LDAP server, perform a search for \u003ccode class=\"literal\"\u003e(uid=someuser)\u003c/code\u003e under the specified base DN. If an entry is found, it will then attempt to bind using that found information and the password supplied by the client. If that second bind succeeds, the database access is granted.\u003c/p\u003e\n\u003cp\u003eHere is the same search+bind configuration written as a URL:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapurl=\"ldap://ldap.example.net/dc=example,dc=net?uid?sub\"\n\u003c/pre\u003e\n\u003cp\u003eSome other software that supports authentication against LDAP uses the same URL format, so it will be easier to share the configuration.\u003c/p\u003e\n\u003cp\u003eHere is an example for a search+bind configuration that uses \u003ccode class=\"literal\"\u003eldapsearchfilter\u003c/code\u003e instead of \u003ccode class=\"literal\"\u003eldapsearchattribute\u003c/code\u003e to allow authentication by user ID or email address:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapserver=ldap.example.net ldapbasedn=\"dc=example, dc=net\" ldapsearchfilter=\"(|(uid=$username)(mail=$username))\"\n\u003c/pre\u003e\n\u003cp\u003eHere is an example for a search+bind configuration that uses DNS SRV discovery to find the host name(s) and port(s) for the LDAP service for the domain name \u003ccode class=\"literal\"\u003eexample.net\u003c/code\u003e:\u003c/p\u003e\n\u003cpre class=\"programlisting\"\u003ehost ... ldap ldapbasedn=\"dc=example,dc=net\"\n\u003c/pre\u003e\n\u003cdiv class=\"tip\"\u003e\n\u003ch3 class=\"title\"\u003eTip\u003c/h3\u003e\n\u003cp\u003eSince LDAP often uses commas and spaces to separate the different parts of a DN, it is often necessary to use double-quoted parameter values when configuring LDAP options, as shown in the examples.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/div\u003e","related":[],"sections":[],"tables":[{"columns":[{"key":"name","label":"Option or term"},{"key":"description","label":"Meaning"}],"key":"method-options","rows":[{"description":"Names or IP addresses of LDAP servers to connect to. Multiple servers may be specified, separated by spaces.","name":"ldapserver"},{"description":"Port number on LDAP server to connect to. If no port is specified, the LDAP library's default port setting will be used.","name":"ldapport"},{"description":"Set to ldaps to use LDAPS. This is a non-standard way of using LDAP over SSL, supported by some LDAP server implementations. See also the ldaptls option for an alternative.","name":"ldapscheme"},{"description":"Set to 1 to make the connection between PostgreSQL and the LDAP server use TLS encryption. This uses the StartTLS operation per RFC 4513 . See also the ldapscheme option for an alternative.","name":"ldaptls"},{"description":"String to prepend to the user name when forming the DN to bind as, when doing simple bind authentication.","name":"ldapprefix"},{"description":"String to append to the user name when forming the DN to bind as, when doing simple bind authentication.","name":"ldapsuffix"},{"description":"Root DN to begin the search for the user in, when doing search+bind authentication.","name":"ldapbasedn"},{"description":"DN of user to bind to the directory with to perform the search when doing search+bind authentication.","name":"ldapbinddn"},{"description":"Password for user to bind to the directory with to perform the search when doing search+bind authentication.","name":"ldapbindpasswd"},{"description":"Attribute to match against the user name in the search when doing search+bind authentication. If no attribute is specified, the uid attribute will be used.","name":"ldapsearchattribute"},{"description":"The search filter to use when doing search+bind authentication. Occurrences of $username will be replaced with the user name. This allows for more flexible search filters than ldapsearchattribute .","name":"ldapsearchfilter"},{"description":"An RFC 4516 LDAP URL. The format is ldap[s]:// host [: port ]/ basedn [?[ attribute ][?[ scope ][?[ filter ]]]] scope must be one of base , one , sub , typically the last. (The default is base , which is normally not useful in this application.) attribute can nominate a single attribute, in which case it is used as a value for ldapsearchattribute . If attribute is empty then filter can be used as a value for ldapsearchfilter . The URL scheme ldaps chooses the LDAPS method for making LDAP connections over SSL, equivalent to using ldapscheme=ldaps . To use encrypted LDAP connections using the StartTLS operation, use the normal URL scheme ldap and specify the ldaptls option in addition to ldapurl . For non-anonymous binds, ldapbinddn and ldapbindpasswd must be specified as separate options. LDAP URLs are currently only supported with OpenLDAP , not on Windows.","name":"ldapurl"}],"title":"Documented method options and alternatives"}]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
