{"Entry":{"collection":"guc","key":"krb_server_keyfile","name":"krb_server_keyfile","aliases":[],"metadata":{"baseline":true,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / Authentication","category_zh":"","changed_in":["9.1","11"],"changes":[{"documentation_changed":true,"fields":{},"from":"8.0","status":"changed","to":"8.1"},{"documentation_changed":true,"fields":{},"from":"8.2","status":"changed","to":"8.3"},{"documentation_changed":true,"fields":{},"from":"8.3","status":"changed","to":"8.4"},{"documentation_changed":false,"fields":{"boot_val":{"from":"","to":"FILE:/etc/postgresql-common/krb5.keytab"}},"from":"9.0","status":"changed","to":"9.1"},{"documentation_changed":true,"fields":{},"from":"9.3","status":"changed","to":"9.4"},{"documentation_changed":true,"fields":{},"from":"9.5","status":"changed","to":"9.6"},{"documentation_changed":true,"fields":{"category":{"from":"Connections and Authentication / Security and Authentication","to":"Connections and Authentication / Authentication"}},"from":"10","status":"changed","to":"11"},{"documentation_changed":true,"fields":{},"from":"11","status":"changed","to":"12"},{"documentation_changed":true,"fields":{},"from":"13","status":"changed","to":"14"},{"documentation_changed":true,"fields":{},"from":"16","status":"changed","to":"17"}],"content_hash":"4590ff2edceb61da0ab6962f429d2afa0f60ce7447128866e323fa1340a610c3","context":"","default_changed_in":["9.1"],"default_history":[{"from":"9.0","to":"9.0","value":"Empty string"},{"from":"9.1","to":"19","value":"FILE:/etc/postgresql-common/krb5.keytab"}],"editorial":{"advice":{"olap":"Apply the same security baseline to analytical access; isolate any legacy client exception to a dedicated role and a dated migration plan.","oltp":"Set krb_server_keyfile from the authentication architecture and security policy, not workload throughput. Test every driver, identity mapping, failover path, and credential-rotation procedure.","small":"Prefer the current secure default for krb_server_keyfile. Avoid weakening authentication to save marginal CPU on a small node; reduce connection churn with pooling instead."},"mechanism":["krb_server_keyfile sets the location of the Kerberos server key file. The file contains service keys used by GSSAPI authentication; operating-system ownership and keytab rotation are part of the effective configuration.","krb_server_keyfile is a SIGHUP-context setting: a configuration reload activates the new server value without a restart; subsequent operations that consult it use the refreshed value.","The final authentication path combines this setting with pg_hba.conf, role attributes, credential material, client capabilities, and sometimes operating-system identity services."],"pitfalls":["Editing krb_server_keyfile without reloading configuration and verifying the effective value and subsequent behavior.","Changing one authentication setting without testing pg_hba.conf ordering, existing secrets, mappings, and every client library.","Weakening identity policy to solve connection churn or CPU cost that should be addressed with pooling and capacity planning.","Changing krb_server_keyfile globally without a rollback plan and a client or operational compatibility test."],"references":[{"title":"PostgreSQL 19 Beta 4: krb_server_keyfile","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["password_encryption","scram_iterations","md5_password_warnings","authentication_timeout","oauth_validator_libraries"],"summary":"krb_server_keyfile is the PostgreSQL setting that defines the location of the Kerberos server key file."},"enumvals":[],"first_version":"7.4","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:31.46025+08:00","intro_commit":{},"key":"krb_server_keyfile","last_version":"20","max_val":"","min_val":"","name":"krb_server_keyfile","position":204,"present_in":["7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"Sets the location of the server's Kerberos key file.","short_desc_zh":"","source_rev":"english-manuals:93da7d193ed33617ecc80c305422582ddce62aed6cc7d499e9f2bbcc63cd7cfd","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"krb_server_keyfile","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"krb_server_keyfile","SourceRevision":"english-manuals:93da7d193ed33617ecc80c305422582ddce62aed6cc7d499e9f2bbcc63cd7cfd","Facts":{"boot_val":"FILE:/etc/postgresql-common/krb5.keytab","category":"Connections and Authentication / Authentication","context":"sighup","description":"Sets the location of the server's Kerberos key file. The default is FILE:/usr/local/pgsql/etc/krb5.keytab (where the directory part is whatever was specified as sysconfdir at build time; use pg_config --sysconfdir to determine that). If this parameter is set to an empty string, it is ignored and a system-dependent default is used. This parameter can only be set in the postgresql.conf file or on the server command line. See Section 20.6 for more information.","doc":{"anchor":"GUC-KRB-SERVER-KEYFILE","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"krb_server_keyfile","short_desc":"Sets the location of the Kerberos server key file.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-KRB-SERVER-KEYFILE","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"krb_server_keyfile","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"krb_server_keyfile","Summary":"","BodyHTML":"\u003cp\u003e设置服务器的Kerberos密钥文件的位置。默认为\u003ccode\u003eFILE:/usr/local/pgsql/etc/krb5.keytab\u003c/code\u003e（其中目录部分是在构建时由\u003ccode\u003esysconfdir\u003c/code\u003e指定的；可用\u003ccode\u003epg_config --sysconfdir\u003c/code\u003e来确定该目录）。如果这个参数被设为空字符串，它将被忽略，并使用随系统而异的默认值。这个参数只能在\u003ccode\u003epostgresql.conf\u003c/code\u003e文件中或者服务器命令行上设置。详情请参考\u003ca href=\"/docs/18/gssapi-auth.html\" rel=\"nofollow\"\u003e第 20.6 节\u003c/a\u003e。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"ace14e4fc153d78de2c12abe41d6d56752444a0ee219a426d51ff224d5486a09","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e设置服务器的Kerberos密钥文件的位置。默认为\u003ccode class=\"filename\"\u003eFILE:/usr/local/pgsql/etc/krb5.keytab\u003c/code\u003e（其中目录部分是在构建时由\u003ccode class=\"varname\"\u003esysconfdir\u003c/code\u003e指定的；可用\u003ccode class=\"literal\"\u003epg_config --sysconfdir\u003c/code\u003e来确定该目录）。如果这个参数被设为空字符串，它将被忽略，并使用随系统而异的默认值。这个参数只能在\u003ccode class=\"filename\"\u003epostgresql.conf\u003c/code\u003e文件中或者服务器命令行上设置。详情请参考\u003ca href=\"/docs/18/gssapi-auth.html\" title=\"20.6. GSSAPI 认证\"\u003e第 20.6 节\u003c/a\u003e。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["10","11","12","13","14","15","16","17","18","19","20","7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
