{"Entry":{"collection":"guc","key":"password_encryption","name":"password_encryption","aliases":[],"metadata":{"baseline":true,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / Authentication","category_zh":"","changed_in":["10","11","14"],"changes":[{"documentation_changed":true,"fields":{},"from":"8.1","status":"changed","to":"8.2"},{"documentation_changed":true,"fields":{},"from":"9.0","status":"changed","to":"9.1"},{"documentation_changed":true,"fields":{"boot_val":{"from":"on","to":"md5"},"enumvals":{"from":null,"to":["md5","scram-sha-256"]},"extra_desc":{"from":"When a password is specified in CREATE USER or ALTER USER without writing either ENCRYPTED or UNENCRYPTED, this parameter determines whether the password is to be encrypted.","to":null},"short_desc":{"from":"Encrypt passwords.","to":"Chooses the algorithm for encrypting passwords."},"vartype":{"from":"bool","to":"enum"}},"from":"9.6","status":"changed","to":"10"},{"documentation_changed":true,"fields":{"category":{"from":"Connections and Authentication / Security and Authentication","to":"Connections and Authentication / Authentication"}},"from":"10","status":"changed","to":"11"},{"documentation_changed":true,"fields":{"boot_val":{"from":"md5","to":"scram-sha-256"}},"from":"13","status":"changed","to":"14"},{"documentation_changed":true,"fields":{},"from":"16","status":"changed","to":"17"},{"documentation_changed":true,"fields":{},"from":"17","status":"changed","to":"18"}],"content_hash":"535051ce2bb2dad0c0d73939139ebfb98235c0efb4c4a446b7ae10e5791e0c1a","context":"","default_changed_in":["10","14"],"default_history":[{"from":"9.0","to":"9.6","value":"on"},{"from":"10","to":"13","value":"md5"},{"from":"14","to":"19","value":"scram-sha-256"}],"editorial":{"advice":{"olap":"Apply the same security baseline to analytical access; isolate any legacy client exception to a dedicated role and a dated migration plan.","oltp":"Set password_encryption from the authentication architecture and security policy, not workload throughput. Test every driver, identity mapping, failover path, and credential-rotation procedure.","small":"Prefer the current secure default for password_encryption. Avoid weakening authentication to save marginal CPU on a small node; reduce connection churn with pooling instead."},"mechanism":["password_encryption chooses the algorithm for encrypting passwords. It affects secrets generated by CREATE ROLE, ALTER ROLE, and password-setting commands; existing stored secrets are not rehashed automatically.","password_encryption is a USER-context setting. An authorized role can change it for a session, while ALTER ROLE or ALTER DATABASE can establish a default for future sessions.","The final authentication path combines this setting with pg_hba.conf, role attributes, credential material, client capabilities, and sometimes operating-system identity services."],"pitfalls":["Changing password_encryption in one session and assuming role defaults, database defaults, or other pooled sessions changed with it.","Changing one authentication setting without testing pg_hba.conf ordering, existing secrets, mappings, and every client library.","Weakening identity policy to solve connection churn or CPU cost that should be addressed with pooling and capacity planning.","Changing the algorithm and assuming existing role secrets are automatically converted."],"references":[{"title":"PostgreSQL 19 Beta 4: password_encryption","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-PASSWORD-ENCRYPTION"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["scram_iterations","md5_password_warnings","authentication_timeout","oauth_validator_libraries","krb_server_keyfile"],"summary":"password_encryption is the PostgreSQL setting that chooses the algorithm for encrypting passwords."},"enumvals":[],"first_version":"7.4","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:31.818926+08:00","intro_commit":{},"key":"password_encryption","last_version":"20","max_val":"","min_val":"","name":"password_encryption","position":309,"present_in":["7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"When a password is specified in CREATE ROLE or ALTER ROLE, this parameter determines the algorithm to use to encrypt the password.","short_desc_zh":"","source_rev":"english-manuals:5b72a19822d709f8e109411755445158b5b1e72ee562e1f253db4ba57e62f466","unit":"","vartype":"enum"}},"Definition":{"Collection":"guc","Key":"password_encryption","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"password_encryption","SourceRevision":"english-manuals:5b72a19822d709f8e109411755445158b5b1e72ee562e1f253db4ba57e62f466","Facts":{"boot_val":"scram-sha-256","category":"Connections and Authentication / Authentication","context":"user","description":"When a password is specified in CREATE ROLE or ALTER ROLE, this parameter determines the algorithm to use to encrypt the password. Possible values are scram-sha-256, which will encrypt the password with SCRAM-SHA-256, and md5, which stores the password as an MD5 hash. The default is scram-sha-256. Note that older clients might lack support for the SCRAM authentication mechanism, and hence not work with passwords encrypted with SCRAM-SHA-256. See Section 20.5 for more details. Warning Support for MD5-encrypted passwords is deprecated and will be removed in a future release of PostgreSQL. Refer to Section 20.5 for details about migrating to another password type.","doc":{"anchor":"GUC-PASSWORD-ENCRYPTION","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":["md5","scram-sha-256"],"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"password_encryption","short_desc":"Chooses the algorithm for encrypting passwords.","source":"pg-settings-source-snapshot","unit":null,"vartype":"enum"},"ManualEvidence":{"doc":{"anchor":"GUC-PASSWORD-ENCRYPTION","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"password_encryption","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"password_encryption","Summary":"","BodyHTML":"\u003cp\u003e当在\u003ca href=\"/docs/18/sql-createrole.html\" title=\"CREATE ROLE\" rel=\"nofollow\"\u003e\u003cspan\u003eCREATE ROLE\u003c/span\u003e\u003c/a\u003e或\u003ca href=\"/docs/18/sql-alterrole.html\" title=\"ALTER ROLE\" rel=\"nofollow\"\u003e\u003cspan\u003eALTER ROLE\u003c/span\u003e\u003c/a\u003e中指定密码时，该参数决定用于加密密码的算法。可能的值有 \u003ccode\u003escram-sha-256\u003c/code\u003e，即使用 SCRAM-SHA-256 加密密码，以及 \u003ccode\u003emd5\u003c/code\u003e，即将密码存储为 MD5 hash。默认值为 \u003ccode\u003escram-sha-256\u003c/code\u003e。\u003c/p\u003e\u003cp\u003e请注意，较旧的客户端可能缺少对 SCRAM 认证机制的支持，因此无法使用以 SCRAM-SHA-256 加密的密码。详情参见\u003ca href=\"/docs/18/auth-password.html\" rel=\"nofollow\"\u003e第 20.5 节\u003c/a\u003e。\u003c/p\u003e\u003cdiv\u003e\n警告\u003cp\u003e对 MD5 加密密码的支持已弃用，并将在\u003cspan\u003ePostgreSQL\u003c/span\u003e的未来版本中移除。迁移到其他密码类型的详细信息见\u003ca href=\"/docs/18/auth-password.html\" rel=\"nofollow\"\u003e第 20.5 节\u003c/a\u003e。\u003c/p\u003e\u003c/div\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"1abb5c197c5638b684ffb22e31015a8175ed206114f823442087c422b382783b","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e当在\u003ca href=\"/docs/18/sql-createrole.html\" title=\"CREATE ROLE\"\u003e\u003cspan class=\"refentrytitle\"\u003eCREATE ROLE\u003c/span\u003e\u003c/a\u003e或\u003ca href=\"/docs/18/sql-alterrole.html\" title=\"ALTER ROLE\"\u003e\u003cspan class=\"refentrytitle\"\u003eALTER ROLE\u003c/span\u003e\u003c/a\u003e中指定密码时，该参数决定用于加密密码的算法。可能的值有 \u003ccode class=\"literal\"\u003escram-sha-256\u003c/code\u003e，即使用 SCRAM-SHA-256 加密密码，以及 \u003ccode class=\"literal\"\u003emd5\u003c/code\u003e，即将密码存储为 MD5 hash。默认值为 \u003ccode class=\"literal\"\u003escram-sha-256\u003c/code\u003e。\u003c/p\u003e\u003cp\u003e请注意，较旧的客户端可能缺少对 SCRAM 认证机制的支持，因此无法使用以 SCRAM-SHA-256 加密的密码。详情参见\u003ca href=\"/docs/18/auth-password.html\" title=\"20.5. 密码认证\"\u003e第 20.5 节\u003c/a\u003e。\u003c/p\u003e\u003cdiv class=\"warning\"\u003e\n警告\u003cp\u003e对 MD5 加密密码的支持已弃用，并将在\u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e的未来版本中移除。迁移到其他密码类型的详细信息见\u003ca href=\"/docs/18/auth-password.html\" title=\"20.5. 密码认证\"\u003e第 20.5 节\u003c/a\u003e。\u003c/p\u003e\u003c/div\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["10","11","12","13","14","15","16","17","18","19","20","7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
