通过有效的客户端 SSL/TLS 证书进行多因素身份验证
已记录的来源状态与原始语言说明;缺少版本证据时明确标为未知。
来源快照记录 PostgreSQL 8.1–18 的变化节点;历史矩阵独立记录 7.4–18 的状态。两者均未记录 PostgreSQL 19 或 20 的支持状态,较新版本明确保留为未知。这些来源声明与运行测量相互独立。
安全
说明
如果 pg_hba.conf 中的身份验证条目指定了 clientcert=verify-full,则客户端必须提供与登录名匹配的有效 SSL 证书,或者基于映射的客户端名称。
https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES
所选版本: PostgreSQL 18
支持
比较版本
原始文档链接
已记录旧标识: 326
完整来源事实与出处
yaml · center · 1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd
{
"Key": "multifactor-authentication-via-valid-client-ssltls-certificate",
"SourceKind": "yaml",
"SourceDatabase": "center",
"SourceTable": "featurematrix.yaml",
"SourceKey": "Multifactor authentication via valid client SSL/TLS certificate",
"SourceHash": "1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd",
"Name": "Multifactor authentication via valid client SSL/TLS certificate",
"NameLocale": "en",
"GroupKey": "security",
"GroupName": "Security",
"GroupLocale": "en",
"Ordinal": 14,
"GroupOrder": 14,
"Facts": {
"feature": {
"description": "If an authentication entry in the pg_hba.conf specifies the `clientcert=verify-full`, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.\r\n\r\n[https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES](https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES)",
"name": "Multifactor authentication via valid client SSL/TLS certificate",
"versions": {
"12": "Yes"
}
},
"group": "Security",
"versions": {
"max": 18,
"min": 8.1
}
},
"Cells": [
{
"Version": "10",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "11",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "12",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "13",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "14",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "15",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "16",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "17",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "18",
"State": "yes",
"EvidenceKind": "yaml-transition",
"TransitionVersion": "12",
"Supported": true,
"Original": "Yes"
},
{
"Version": "8.1",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "8.2",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "8.3",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "8.4",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.0",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.1",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.2",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.3",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.4",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.5",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
},
{
"Version": "9.6",
"State": "no",
"EvidenceKind": "yaml-default-no",
"TransitionVersion": "",
"Supported": false,
"Original": "No"
}
],
"Texts": [
{
"Locale": "en",
"Title": "Multifactor authentication via valid client SSL/TLS certificate",
"BodyHTML": "\u003cp\u003eIf an authentication entry in the pg_hba.conf specifies the \u003ccode\u003eclientcert=verify-full\u003c/code\u003e, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\" rel=\"nofollow\"\u003ehttps://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\u003c/a\u003e\u003c/p\u003e\n",
"SourceHash": "1dd22bf9a7f3ec325b894e2836fda535a25529f246a94dd41d6abbfe9997f7fd",
"ContentHash": "6ffde594e8dc7c79f9e7b2f05aec068a3873f20243ab44060f3d69421f816cca",
"Payload": {
"description": "If an authentication entry in the pg_hba.conf specifies the `clientcert=verify-full`, then the client must present a valid SSL certificate that matches the login name, or the client name based on a map.\r\n\r\n[https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES](https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES)",
"name": "Multifactor authentication via valid client SSL/TLS certificate",
"versions": {
"12": "Yes"
}
}
},
{
"Locale": "zh-Hans",
"Title": "通过有效的客户端 SSL/TLS 证书进行多因素身份验证",
"BodyHTML": "\u003cp\u003e如果 pg_hba.conf 中的身份验证条目指定了 \u003ccode\u003eclientcert=verify-full\u003c/code\u003e,则客户端必须提供与登录名匹配的有效 SSL 证书,或者基于映射的客户端名称。\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\" rel=\"nofollow\"\u003ehttps://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES\u003c/a\u003e\u003c/p\u003e\n",
"SourceHash": "071091951021357a5f492adb04caed6febf4d315ac2626ca027a48dd8ec01d50",
"ContentHash": "5b645361965bcc9649badea138d9cf77688a8825275c5b70b3a0d89a20f66452",
"Payload": {
"description": "如果 pg_hba.conf 中的身份验证条目指定了 `clientcert=verify-full`,则客户端必须提供与登录名匹配的有效 SSL 证书,或者基于映射的客户端名称。\n\n[https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES](https://www.postgresql.org/docs/12/ssl-tcp.html#SSL-CLIENT-CERTIFICATES)",
"name": "通过有效的客户端 SSL/TLS 证书进行多因素身份验证"
}
}
],
"GroupTitles": {
"en": "Security",
"zh-Hans": "安全"
},
"LegacyIDs": [
"326"
]
}