{"Entry":{"collection":"guc","key":"password_expiration_warning_threshold","name":"password_expiration_warning_threshold","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / Authentication","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"18","status":"added","to":"19"}],"content_hash":"33513471337fa7c7acbbde2f8153028b2dac7f7cb106278b2236c0280244e1bb","context":"","default_changed_in":[],"default_history":[{"from":"19","to":"19","value":"7 d"}],"editorial":{"advice":{"olap":"Apply the same security policy to batch drivers and long-lived ETL connections. Test clients that omit SNI, credential-expiry automation, reload behavior, and certificate-chain compatibility.","oltp":"Roll out through staged clients, validate certificate selection and expiry warnings, and monitor authentication failures. Keep a tested fallback and treat file permissions and secret rotation as part of the same change.","small":"Prefer a simple, documented TLS and credential policy. Do not enable multi-certificate routing without a test for every hostname and fallback path, and never weaken verification to hide configuration mistakes."},"mechanism":["PostgreSQL describes password_expiration_warning_threshold as follows: “Threshold for password expiration warnings.” A configuration reload applies the value to the server without a full restart. The atlas measures it in PG19 Beta 3; boot_val is the compiled or initialized baseline, not proof of a running cluster's effective setting.","After successful password authentication, PostgreSQL warns when a role with VALID UNTIL has less than this interval remaining. Zero disables the warning; the default seven-day window is advisory and does not create, rotate, or extend credentials, and non-password authentication does not make password expiry management automatic.","Read it together with password_encryption, authentication_timeout, md5_password_warnings, hba_file. Check SHOW and pg_settings on the target server, verify the source and pending_restart fields, and compare workload, logs, and resource metrics before and after any change."],"pitfalls":["Treating the measured boot_val for password_expiration_warning_threshold as proof of the effective value on an initialized or managed cluster.","Applying a change as though it were immediate while pg_settings reports sighup context.","Changing this setting in isolation without checking the linked limits, observability, and rollback path.","Depending on beta behavior in production without retesting the PostgreSQL 19 final release."],"references":[{"title":"PostgreSQL 19 Beta 4: password_expiration_warning_threshold","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-PASSWORD-EXPIRATION-WARNING-THRESHOLD"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["password_encryption","authentication_timeout","md5_password_warnings","hba_file"],"summary":"password_expiration_warning_threshold — Threshold for password expiration warnings. Observed in PG19 Beta 4; its last measured boot default is 7 d in PG19 Beta 4, with sighup context. This is a beta-snapshot fact and can change before PostgreSQL 19 GA."},"enumvals":[],"first_version":"19","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:31.82517+08:00","intro_commit":{"authored_at":"2026-02-11T10:36:15-06:00","discussion":["https://postgr.es/m/129bcfbf-47a6-e58a-190a-62fc21a17d03%40migops.com"],"hash":"1d92e0c2cc4789255c630d8776bbe85ca9ebc27f","subject":"Add password expiration warnings.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=1d92e0c2cc4789255c630d8776bbe85ca9ebc27f"},"key":"password_expiration_warning_threshold","last_version":"20","max_val":"","min_val":"","name":"password_expiration_warning_threshold","position":310,"present_in":["19","20"],"short_desc":"When this parameter is greater than zero, the server will emit a WARNING upon successful password authentication if less than this amount of time remains until the authenticated role's password expires.","short_desc_zh":"","source_rev":"english-manuals:8f1b9a99bd6e711fc64f127489fb83290bc2fdd2f760df9e7da8b540c3517aec","unit":"","vartype":"integer"}},"Definition":{"Collection":"guc","Key":"password_expiration_warning_threshold","SourceDatabase":"center","Version":"20","SourceTable":"guc","SourceKey":"password_expiration_warning_threshold","SourceRevision":"english-manuals:8f1b9a99bd6e711fc64f127489fb83290bc2fdd2f760df9e7da8b540c3517aec","Facts":{"boot_val":null,"category":"Authentication","context":"","description":"When this parameter is greater than zero, the server will emit a WARNING upon successful password authentication if less than this amount of time remains until the authenticated role's password expires. Note that a role's password only expires if a date was specified in a VALID UNTIL clause for CREATE ROLE or ALTER ROLE. If this value is specified without units, it is taken as seconds. The default is 7 days. This parameter can only be set in the postgresql.conf file or on the server command line.","doc":{"anchor":"GUC-PASSWORD-EXPIRATION-WARNING-THRESHOLD","file":"runtime-config-connection.html","lang":"en","sha256":"4b80661e9622d2555407e5bd755b09f6beb861e678e1670b0c34695e79ae140e","slug":"devel"},"documented":true,"enumvals":[],"extra_desc":"","lang":"en","max_val":null,"metadata_version":"","min_val":null,"name":"password_expiration_warning_threshold","short_desc":"","source":"english-manual","unit":"","vartype":"integer"},"ManualEvidence":{"doc":{"anchor":"GUC-PASSWORD-EXPIRATION-WARNING-THRESHOLD","file":"runtime-config-connection.html","lang":"en","sha256":"4b80661e9622d2555407e5bd755b09f6beb861e678e1670b0c34695e79ae140e","slug":"devel"}},"MeasuredEvidence":{"metadata_version":""}},"Text":{"Collection":"guc","Key":"password_expiration_warning_threshold","SourceDatabase":"center","Version":"20","Locale":"en","Title":"password_expiration_warning_threshold","Summary":"When this parameter is greater than zero, the server will emit a WARNING upon successful password authentication if less than this amount of time remains until the authenticated role's password expires. Note that a role's password only expires if a date was specified in a VALID UNTIL clause for CREATE ROLE or ALTER ROLE. If this value is specified without units, it is taken as seconds. The default is 7 days. This parameter can only be set in the postgresql.conf file or on the server command line.","BodyHTML":"\u003cp\u003eWhen this parameter is greater than zero, the server will emit a WARNING upon successful password authentication if less than this amount of time remains until the authenticated role\u0026#39;s password expires. Note that a role\u0026#39;s password only expires if a date was specified in a VALID UNTIL clause for CREATE ROLE or ALTER ROLE. If this value is specified without units, it is taken as seconds. The default is 7 days. This parameter can only be set in the postgresql.conf file or on the server command line.\u003c/p\u003e","SourceRevision":"english-manuals:8f1b9a99bd6e711fc64f127489fb83290bc2fdd2f760df9e7da8b540c3517aec","ContentHash":"04c28e498cf98c7d37855b4e5a6ad3444d2c8ab2d677a4c2189624ae20959e4a","Payload":{"description":"When this parameter is greater than zero, the server will emit a WARNING upon successful password authentication if less than this amount of time remains until the authenticated role's password expires. Note that a role's password only expires if a date was specified in a VALID UNTIL clause for CREATE ROLE or ALTER ROLE. If this value is specified without units, it is taken as seconds. The default is 7 days. This parameter can only be set in the postgresql.conf file or on the server command line."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
