{"Entry":{"collection":"guc","key":"krb_caseins_users","name":"krb_caseins_users","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / Authentication","category_zh":"","changed_in":["11"],"changes":[{"documentation_changed":false,"fields":{},"from":"8.0","status":"added","to":"8.1"},{"documentation_changed":true,"fields":{},"from":"8.2","status":"changed","to":"8.3"},{"documentation_changed":true,"fields":{},"from":"8.3","status":"changed","to":"8.4"},{"documentation_changed":true,"fields":{},"from":"9.3","status":"changed","to":"9.4"},{"documentation_changed":false,"fields":{"category":{"from":"Connections and Authentication / Security and Authentication","to":"Connections and Authentication / Authentication"}},"from":"10","status":"changed","to":"11"}],"content_hash":"fc584f895227b689fa411c9724de64b3884e77a2d9a87f96d404680f32472491","context":"","default_changed_in":[],"default_history":[{"from":"9.0","to":"19","value":"off"}],"editorial":{"advice":{"olap":"Apply the same security baseline to analytical access; isolate any legacy client exception to a dedicated role and a dated migration plan.","oltp":"Set krb_caseins_users from the authentication architecture and security policy, not workload throughput. Test every driver, identity mapping, failover path, and credential-rotation procedure.","small":"Prefer the current secure default for krb_caseins_users. Avoid weakening authentication to save marginal CPU on a small node; reduce connection churn with pooling instead."},"mechanism":["krb_caseins_users sets whether Kerberos and GSSAPI user names should be treated as case-insensitive. It affects comparison of authenticated Kerberos/GSS names with database role names; case folding can merge identities that an existing mapping treated as distinct.","krb_caseins_users is a SIGHUP-context setting: a configuration reload activates the new server value without a restart; subsequent operations that consult it use the refreshed value.","The final authentication path combines this setting with pg_hba.conf, role attributes, credential material, client capabilities, and sometimes operating-system identity services."],"pitfalls":["Editing krb_caseins_users without reloading configuration and verifying the effective value and subsequent behavior.","Changing one authentication setting without testing pg_hba.conf ordering, existing secrets, mappings, and every client library.","Weakening identity policy to solve connection churn or CPU cost that should be addressed with pooling and capacity planning.","Changing krb_caseins_users globally without a rollback plan and a client or operational compatibility test."],"references":[{"title":"PostgreSQL 19 Beta 4: krb_caseins_users","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-KRB-CASEINS-USERS"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["password_encryption","scram_iterations","md5_password_warnings","authentication_timeout","oauth_validator_libraries","krb_server_keyfile"],"summary":"krb_caseins_users is the PostgreSQL setting that defines whether Kerberos and GSSAPI user names should be treated as case-insensitive."},"enumvals":[],"first_version":"8.1","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:31.452785+08:00","intro_commit":{},"key":"krb_caseins_users","last_version":"20","max_val":"","min_val":"","name":"krb_caseins_users","position":201,"present_in":["8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"Sets whether GSSAPI user names should be treated case-insensitively.","short_desc_zh":"","source_rev":"english-manuals:2667d4856221a852bc47c5dd688cb43a5d77621160f113a6c0970d3ca8f70393","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"krb_caseins_users","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"krb_caseins_users","SourceRevision":"english-manuals:2667d4856221a852bc47c5dd688cb43a5d77621160f113a6c0970d3ca8f70393","Facts":{"boot_val":"off","category":"Connections and Authentication / Authentication","context":"sighup","description":"Sets whether GSSAPI user names should be treated case-insensitively. The default is off (case sensitive). This parameter can only be set in the postgresql.conf file or on the server command line.","doc":{"anchor":"GUC-KRB-CASEINS-USERS","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"krb_caseins_users","short_desc":"Sets whether Kerberos and GSSAPI user names should be treated as case-insensitive.","source":"pg-settings-source-snapshot","unit":null,"vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-KRB-CASEINS-USERS","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"krb_caseins_users","SourceDatabase":"center","Version":"18","Locale":"en","Title":"krb_caseins_users","Summary":"Sets whether GSSAPI user names should be treated case-insensitively. The default is off (case sensitive). This parameter can only be set in the postgresql.conf file or on the server command line.","BodyHTML":"\u003cp\u003eSets whether GSSAPI user names should be treated case-insensitively. The default is off (case sensitive). This parameter can only be set in the postgresql.conf file or on the server command line.\u003c/p\u003e","SourceRevision":"english-manuals:2667d4856221a852bc47c5dd688cb43a5d77621160f113a6c0970d3ca8f70393","ContentHash":"c677be292e19123151ed0bb9855f277ecb6d8492ca8352f6752d0bfb4444c162","Payload":{"description":"Sets whether GSSAPI user names should be treated case-insensitively. The default is off (case sensitive). This parameter can only be set in the postgresql.conf file or on the server command line."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
