{"Entry":{"collection":"guc","key":"gss_accept_delegation","name":"gss_accept_delegation","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / Authentication","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"15","status":"added","to":"16"}],"content_hash":"7972a2d111d0ac78ea9ba41d6734ab2a398106813ae45e8fe8a2ebba6c6b64ba","context":"","default_changed_in":[],"default_history":[{"from":"16","to":"19","value":"off"}],"editorial":{"advice":{"olap":"Apply the same security baseline to analytical access; isolate any legacy client exception to a dedicated role and a dated migration plan.","oltp":"Set gss_accept_delegation from the authentication architecture and security policy, not workload throughput. Test every driver, identity mapping, failover path, and credential-rotation procedure.","small":"Prefer the current secure default for gss_accept_delegation. Avoid weakening authentication to save marginal CPU on a small node; reduce connection churn with pooling instead."},"mechanism":["gss_accept_delegation sets whether GSSAPI delegation should be accepted from the client. Accepting delegated credentials lets server-side code act with the client's GSS identity, so it expands trust beyond ordinary authentication.","gss_accept_delegation is a SIGHUP-context setting: a configuration reload activates the new server value without a restart; subsequent operations that consult it use the refreshed value.","The final authentication path combines this setting with pg_hba.conf, role attributes, credential material, client capabilities, and sometimes operating-system identity services."],"pitfalls":["Editing gss_accept_delegation without reloading configuration and verifying the effective value and subsequent behavior.","Changing one authentication setting without testing pg_hba.conf ordering, existing secrets, mappings, and every client library.","Weakening identity policy to solve connection churn or CPU cost that should be addressed with pooling and capacity planning.","Changing gss_accept_delegation globally without a rollback plan and a client or operational compatibility test."],"references":[{"title":"PostgreSQL 19 Beta 4: gss_accept_delegation","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-GSS-ACCEPT-DELEGATION"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["password_encryption","scram_iterations","md5_password_warnings","authentication_timeout","oauth_validator_libraries","krb_server_keyfile"],"summary":"gss_accept_delegation is the PostgreSQL setting that defines whether GSSAPI delegation should be accepted from the client."},"enumvals":[],"first_version":"16","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:31.339872+08:00","intro_commit":{"authored_at":"2023-05-20T21:32:54-04:00","discussion":["https://postgr.es/m/ZGdnEsGtNj7+fZoa@momjian.us"],"hash":"9c0a0e2ed92a1a94ec30d36f8ea1ab12c928292b","subject":"rename \"gss_accept_deleg\" to \"gss_accept_delegation\".","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=9c0a0e2ed92a1a94ec30d36f8ea1ab12c928292b"},"key":"gss_accept_delegation","last_version":"20","max_val":"","min_val":"","name":"gss_accept_delegation","position":162,"present_in":["16","17","18","19","20"],"short_desc":"Sets whether GSSAPI delegation should be accepted from the client.","short_desc_zh":"","source_rev":"english-manuals:7df5893205f9aab58aa4a434c47b9d5cf2f3aaa2c1a5f8d6d05bbbffe7714e54","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"gss_accept_delegation","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"gss_accept_delegation","SourceRevision":"english-manuals:7df5893205f9aab58aa4a434c47b9d5cf2f3aaa2c1a5f8d6d05bbbffe7714e54","Facts":{"boot_val":"off","category":"Connections and Authentication / Authentication","context":"sighup","description":"Sets whether GSSAPI delegation should be accepted from the client. The default is off meaning credentials from the client will not be accepted. Changing this to on will make the server accept credentials delegated to it from the client. This parameter can only be set in the postgresql.conf file or on the server command line.","doc":{"anchor":"GUC-GSS-ACCEPT-DELEGATION","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"gss_accept_delegation","short_desc":"Sets whether GSSAPI delegation should be accepted from the client.","source":"pg-settings-source-snapshot","unit":null,"vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-GSS-ACCEPT-DELEGATION","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"gss_accept_delegation","SourceDatabase":"center","Version":"18","Locale":"en","Title":"gss_accept_delegation","Summary":"Sets whether GSSAPI delegation should be accepted from the client. The default is off meaning credentials from the client will not be accepted. Changing this to on will make the server accept credentials delegated to it from the client. This parameter can only be set in the postgresql.conf file or on the server command line.","BodyHTML":"\u003cp\u003eSets whether GSSAPI delegation should be accepted from the client. The default is off meaning credentials from the client will not be accepted. Changing this to on will make the server accept credentials delegated to it from the client. This parameter can only be set in the postgresql.conf file or on the server command line.\u003c/p\u003e","SourceRevision":"english-manuals:7df5893205f9aab58aa4a434c47b9d5cf2f3aaa2c1a5f8d6d05bbbffe7714e54","ContentHash":"74f9ab2712f012cf86ee24615eded0e45d3be7541adf33f8aff708ee696ab0f1","Payload":{"description":"Sets whether GSSAPI delegation should be accepted from the client. The default is off meaning credentials from the client will not be accepted. Changing this to on will make the server accept credentials delegated to it from the client. This parameter can only be set in the postgresql.conf file or on the server command line."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
