{"Entry":{"collection":"auth","key":"pam","name":"pam","aliases":[],"metadata":{"aliases":[],"category":"Authentication and access control","content_hash":"fc4ee79fad90c2894ddaa032799b7c487c9aa9c6c4cc6468635da2ba85f2f652","imported_at":"2026-09-30T00:40:33.317699+08:00","name":"pam","name_zh":"","slug":"pam","summary":"Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.12 for details."}},"Definition":{"Collection":"auth","Key":"pam","SourceDatabase":"center","Version":"18","SourceTable":"authentication_method","SourceKey":"pam","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","Facts":{"aliases":[],"attributes":{"configuration":"pg_hba.conf","inventory":"User-visible source authentication method","method":"pam"},"comparison_data":{"documented_option_names":["pam_use_hostname","pamservice"],"method":"pam"},"comparison_hash":"e720d3348388b2db8e8cd0a06e3817320e147ff161d803b608628c9973d28741","description":["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details."],"facts":[{"label":"Method","value":"pam"},{"label":"Configuration","value":"pg_hba.conf"},{"label":"Inventory","value":"User-visible source authentication method"}],"manual_html":"\u003cdiv class=\"sect1\" id=\"AUTH-PAM\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e20.13. PAM Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThis authentication method operates similarly to \u003ccode class=\"literal\"\u003epassword\u003c/code\u003e except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is \u003ccode class=\"literal\"\u003epostgresql\u003c/code\u003e. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the \u003ca class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"\u003e\u003cspan class=\"productname\"\u003eLinux-PAM\u003c/span\u003e Page\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThe following configuration options are supported for PAM:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003epamservice\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003ePAM service name.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003epam_use_hostname\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eDetermines whether the remote IP address or the host name is provided to PAM modules through the \u003ccode class=\"symbol\"\u003ePAM_RHOST\u003c/code\u003e item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cdiv class=\"note\"\u003e\n\u003ch3 class=\"title\"\u003eNote\u003c/h3\u003e\n\u003cp\u003eIf PAM is set up to read \u003ccode class=\"filename\"\u003e/etc/shadow\u003c/code\u003e, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/div\u003e","manual_path":"/docs/18/auth-pam.html","related":[],"release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sections":[],"signature":"","sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"auth-pam.html","sha256":"e3d0a0d5ecb652f5534d7f62574b323d77436acd258b10a17a359873c1edf8d8","url":"/docs/18/auth-pam.html"},{"label":"PostgreSQL 18 English manual","path":"auth-pg-hba-conf.html","sha256":"6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9","url":"/docs/18/auth-pg-hba-conf.html"}],"tables":[{"columns":[{"key":"name","label":"Option or term"},{"key":"description","label":"Meaning"}],"key":"method-options","rows":[{"description":"PAM service name.","name":"pamservice"},{"description":"Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)","name":"pam_use_hostname"}],"title":"Documented method options and alternatives"}]},"ManualEvidence":{"manual_path":"/docs/18/auth-pam.html","release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"auth-pam.html","sha256":"e3d0a0d5ecb652f5534d7f62574b323d77436acd258b10a17a359873c1edf8d8","url":"/docs/18/auth-pam.html"},{"label":"PostgreSQL 18 English manual","path":"auth-pg-hba-conf.html","sha256":"6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9","url":"/docs/18/auth-pg-hba-conf.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"auth","Key":"pam","SourceDatabase":"center","Version":"18","Locale":"en","Title":"pam","Summary":"Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details.","BodyHTML":"\u003cdiv id=\"AUTH-PAM\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2\u003e20.13. PAM Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThis authentication method operates similarly to \u003ccode\u003epassword\u003c/code\u003e except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is \u003ccode\u003epostgresql\u003c/code\u003e. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the \u003ca href=\"https://www.kernel.org/pub/linux/libs/pam/\" rel=\"nofollow\"\u003e\u003cspan\u003eLinux-PAM\u003c/span\u003e Page\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThe following configuration options are supported for PAM:\u003c/p\u003e\n\u003cdiv\u003e\n\u003cdl\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003epamservice\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003ePAM service name.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003epam_use_hostname\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eDetermines whether the remote IP address or the host name is provided to PAM modules through the \u003ccode\u003ePAM_RHOST\u003c/code\u003e item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don\u0026#39;t use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cdiv\u003e\n\u003ch3\u003eNote\u003c/h3\u003e\n\u003cp\u003eIf PAM is set up to read \u003ccode\u003e/etc/shadow\u003c/code\u003e, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/div\u003e","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","ContentHash":"7041c581b58f98b0f4eb49886feb7937872e618b147305a0c2f4f28e12b752cd","Payload":{"description":["Authenticate using the Pluggable Authentication Modules (PAM) service provided by the operating system. See Section 20.13 for details."],"manual_html":"\u003cdiv class=\"sect1\" id=\"AUTH-PAM\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e20.13. PAM Authentication \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003eThis authentication method operates similarly to \u003ccode class=\"literal\"\u003epassword\u003c/code\u003e except that it uses PAM (Pluggable Authentication Modules) as the authentication mechanism. The default PAM service name is \u003ccode class=\"literal\"\u003epostgresql\u003c/code\u003e. PAM is used only to validate user name/password pairs and optionally the connected remote host name or IP address. Therefore the user must already exist in the database before PAM can be used for authentication. For more information about PAM, please read the \u003ca class=\"ulink\" href=\"https://www.kernel.org/pub/linux/libs/pam/\"\u003e\u003cspan class=\"productname\"\u003eLinux-PAM\u003c/span\u003e Page\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThe following configuration options are supported for PAM:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003epamservice\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003ePAM service name.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003epam_use_hostname\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eDetermines whether the remote IP address or the host name is provided to PAM modules through the \u003ccode class=\"symbol\"\u003ePAM_RHOST\u003c/code\u003e item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cdiv class=\"note\"\u003e\n\u003ch3 class=\"title\"\u003eNote\u003c/h3\u003e\n\u003cp\u003eIf PAM is set up to read \u003ccode class=\"filename\"\u003e/etc/shadow\u003c/code\u003e, authentication will fail because the PostgreSQL server is started by a non-root user. However, this is not an issue when PAM is configured to use LDAP or other authentication methods.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/div\u003e","related":[],"sections":[],"tables":[{"columns":[{"key":"name","label":"Option or term"},{"key":"description","label":"Meaning"}],"key":"method-options","rows":[{"description":"PAM service name.","name":"pamservice"},{"description":"Determines whether the remote IP address or the host name is provided to PAM modules through the PAM_RHOST item. By default, the IP address is used. Set this option to 1 to use the resolved host name instead. Host name resolution can lead to login delays. (Most PAM configurations don't use this information, so it is only necessary to consider this setting if a PAM configuration was specifically created to make use of it.)","name":"pam_use_hostname"}],"title":"Documented method options and alternatives"}]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
