Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes15kdownloads
runtime-config-connection.html582 linesDownload Raw Back to html
1<?xml version="1.0" encoding="UTF-8" standalone="no"?>2<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title>20.3. Connections and Authentication</title><link rel="stylesheet" type="text/css" href="stylesheet.css" /><link rev="made" href="pgsql-docs@lists.postgresql.org" /><meta name="generator" content="DocBook XSL Stylesheets Vsnapshot" /><link rel="prev" href="runtime-config-file-locations.html" title="20.2. File Locations" /><link rel="next" href="runtime-config-resource.html" title="20.4. Resource Consumption" /></head><body id="docContent" class="container-fluid col-10"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="5" align="center">20.3. Connections and Authentication</th></tr><tr><td width="10%" align="left"><a accesskey="p" href="runtime-config-file-locations.html" title="20.2. File Locations">Prev</a> </td><td width="10%" align="left"><a accesskey="u" href="runtime-config.html" title="Chapter 20. Server Configuration">Up</a></td><th width="60%" align="center">Chapter 20. Server Configuration</th><td width="10%" align="right"><a accesskey="h" href="index.html" title="PostgreSQL 16.3 Documentation">Home</a></td><td width="10%" align="right"> <a accesskey="n" href="runtime-config-resource.html" title="20.4. Resource Consumption">Next</a></td></tr></table><hr /></div><div class="sect1" id="RUNTIME-CONFIG-CONNECTION"><div class="titlepage"><div><div><h2 class="title" style="clear: both">20.3. Connections and Authentication <a href="#RUNTIME-CONFIG-CONNECTION" class="id_link">#</a></h2></div></div></div><div class="toc"><dl class="toc"><dt><span class="sect2"><a href="runtime-config-connection.html#RUNTIME-CONFIG-CONNECTION-SETTINGS">20.3.1. Connection Settings</a></span></dt><dt><span class="sect2"><a href="runtime-config-connection.html#RUNTIME-CONFIG-TCP-SETTINGS">20.3.2. TCP Settings</a></span></dt><dt><span class="sect2"><a href="runtime-config-connection.html#RUNTIME-CONFIG-CONNECTION-AUTHENTICATION">20.3.3. Authentication</a></span></dt><dt><span class="sect2"><a href="runtime-config-connection.html#RUNTIME-CONFIG-CONNECTION-SSL">20.3.4. SSL</a></span></dt></dl></div><div class="sect2" id="RUNTIME-CONFIG-CONNECTION-SETTINGS"><div class="titlepage"><div><div><h3 class="title">20.3.1. Connection Settings <a href="#RUNTIME-CONFIG-CONNECTION-SETTINGS" class="id_link">#</a></h3></div></div></div><div class="variablelist"><dl class="variablelist"><dt id="GUC-LISTEN-ADDRESSES"><span class="term"><code class="varname">listen_addresses</code> (<code class="type">string</code>)3      <a id="id-1.6.7.6.2.2.1.1.3" class="indexterm"></a>4      </span> <a href="#GUC-LISTEN-ADDRESSES" class="id_link">#</a></dt><dd><p>5         Specifies the TCP/IP address(es) on which the server is6         to listen for connections from client applications.7         The value takes the form of a comma-separated list of host names8         and/or numeric IP addresses.  The special entry <code class="literal">*</code>9         corresponds to all available IP interfaces.  The entry10         <code class="literal">0.0.0.0</code> allows listening for all IPv4 addresses and11         <code class="literal">::</code> allows listening for all IPv6 addresses.12         If the list is empty, the server does not listen on any IP interface13         at all, in which case only Unix-domain sockets can be used to connect14         to it.  If the list is not empty, the server will start if it15         can listen on at least one TCP/IP address.  A warning will be16         emitted for any TCP/IP address which cannot be opened.17         The default value is <span class="systemitem">localhost</span>,18         which allows only local TCP/IP <span class="quote">“<span class="quote">loopback</span>”</span> connections to be19         made.20       </p><p>21         While client authentication (<a class="xref" href="client-authentication.html" title="Chapter 21. Client Authentication">Chapter 21</a>) allows fine-grained control22         over who can access the server, <code class="varname">listen_addresses</code>23         controls which interfaces accept connection attempts, which24         can help prevent repeated malicious connection requests on25         insecure network interfaces.  This parameter can only be set26         at server start.27       </p></dd><dt id="GUC-PORT"><span class="term"><code class="varname">port</code> (<code class="type">integer</code>)28      <a id="id-1.6.7.6.2.2.2.1.3" class="indexterm"></a>29      </span> <a href="#GUC-PORT" class="id_link">#</a></dt><dd><p>30        The TCP port the server listens on; 5432 by default.  Note that the31        same port number is used for all IP addresses the server listens on.32        This parameter can only be set at server start.33       </p></dd><dt id="GUC-MAX-CONNECTIONS"><span class="term"><code class="varname">max_connections</code> (<code class="type">integer</code>)34      <a id="id-1.6.7.6.2.2.3.1.3" class="indexterm"></a>35      </span> <a href="#GUC-MAX-CONNECTIONS" class="id_link">#</a></dt><dd><p>36        Determines the maximum number of concurrent connections to the37        database server. The default is typically 100 connections, but38        might be less if your kernel settings will not support it (as39        determined during <span class="application">initdb</span>).  This parameter can40        only be set at server start.41       </p><p>42        When running a standby server, you must set this parameter to the43        same or higher value than on the primary server. Otherwise, queries44        will not be allowed in the standby server.45       </p></dd><dt id="GUC-RESERVED-CONNECTIONS"><span class="term"><code class="varname">reserved_connections</code> (<code class="type">integer</code>)46      <a id="id-1.6.7.6.2.2.4.1.3" class="indexterm"></a>47      </span> <a href="#GUC-RESERVED-CONNECTIONS" class="id_link">#</a></dt><dd><p>48        Determines the number of connection <span class="quote">“<span class="quote">slots</span>”</span> that are49        reserved for connections by roles with privileges of the50        <a class="link" href="predefined-roles.html#PREDEFINED-ROLES-TABLE" title="Table 22.1. Predefined Roles"><code class="literal">pg_use_reserved_connections</code></a>51        role.  Whenever the number of free connection slots is greater than52        <a class="xref" href="runtime-config-connection.html#GUC-SUPERUSER-RESERVED-CONNECTIONS">superuser_reserved_connections</a> but less than or53        equal to the sum of <code class="varname">superuser_reserved_connections</code>54        and <code class="varname">reserved_connections</code>, new connections will be55        accepted only for superusers and roles with privileges of56        <code class="literal">pg_use_reserved_connections</code>.  If57        <code class="varname">superuser_reserved_connections</code> or fewer connection58        slots are available, new connections will be accepted only for59        superusers.60       </p><p>61        The default value is zero connections.  The value must be less than62        <code class="varname">max_connections</code> minus63        <code class="varname">superuser_reserved_connections</code>.  This parameter can64        only be set at server start.65       </p></dd><dt id="GUC-SUPERUSER-RESERVED-CONNECTIONS"><span class="term"><code class="varname">superuser_reserved_connections</code>66      (<code class="type">integer</code>)67      <a id="id-1.6.7.6.2.2.5.1.3" class="indexterm"></a>68      </span> <a href="#GUC-SUPERUSER-RESERVED-CONNECTIONS" class="id_link">#</a></dt><dd><p>69        Determines the number of connection <span class="quote">“<span class="quote">slots</span>”</span> that70        are reserved for connections by <span class="productname">PostgreSQL</span>71        superusers.  At most <a class="xref" href="runtime-config-connection.html#GUC-MAX-CONNECTIONS">max_connections</a>72        connections can ever be active simultaneously.  Whenever the73        number of active concurrent connections is at least74        <code class="varname">max_connections</code> minus75        <code class="varname">superuser_reserved_connections</code>, new76        connections will be accepted only for superusers.  The connection slots77        reserved by this parameter are intended as final reserve for emergency78        use after the slots reserved by79        <a class="xref" href="runtime-config-connection.html#GUC-RESERVED-CONNECTIONS">reserved_connections</a> have been exhausted.80       </p><p>81        The default value is three connections. The value must be less82        than <code class="varname">max_connections</code> minus83        <code class="varname">reserved_connections</code>.84        This parameter can only be set at server start.85       </p></dd><dt id="GUC-UNIX-SOCKET-DIRECTORIES"><span class="term"><code class="varname">unix_socket_directories</code> (<code class="type">string</code>)86      <a id="id-1.6.7.6.2.2.6.1.3" class="indexterm"></a>87      </span> <a href="#GUC-UNIX-SOCKET-DIRECTORIES" class="id_link">#</a></dt><dd><p>88        Specifies the directory of the Unix-domain socket(s) on which the89        server is to listen for connections from client applications.90        Multiple sockets can be created by listing multiple directories91        separated by commas.  Whitespace between entries is92        ignored; surround a directory name with double quotes if you need93        to include whitespace or commas in the name.94        An empty value95        specifies not listening on any Unix-domain sockets, in which case96        only TCP/IP sockets can be used to connect to the server.97       </p><p>98        A value that starts with <code class="literal">@</code> specifies that a99        Unix-domain socket in the abstract namespace should be created100        (currently supported on Linux only).  In that case, this value101        does not specify a <span class="quote">“<span class="quote">directory</span>”</span> but a prefix from which102        the actual socket name is computed in the same manner as for the103        file-system namespace.  While the abstract socket name prefix can be104        chosen freely, since it is not a file-system location, the convention105        is to nonetheless use file-system-like values such as106        <code class="literal">@/tmp</code>.107       </p><p>108        The default value is normally109        <code class="filename">/tmp</code>, but that can be changed at build time.110        On Windows, the default is empty, which means no Unix-domain socket is111        created by default.112        This parameter can only be set at server start.113       </p><p>114        In addition to the socket file itself, which is named115        <code class="literal">.s.PGSQL.<em class="replaceable"><code>nnnn</code></em></code> where116        <em class="replaceable"><code>nnnn</code></em> is the server's port number, an ordinary file117        named <code class="literal">.s.PGSQL.<em class="replaceable"><code>nnnn</code></em>.lock</code> will be118        created in each of the <code class="varname">unix_socket_directories</code> directories.119        Neither file should ever be removed manually.120        For sockets in the abstract namespace, no lock file is created.121       </p></dd><dt id="GUC-UNIX-SOCKET-GROUP"><span class="term"><code class="varname">unix_socket_group</code> (<code class="type">string</code>)122      <a id="id-1.6.7.6.2.2.7.1.3" class="indexterm"></a>123      </span> <a href="#GUC-UNIX-SOCKET-GROUP" class="id_link">#</a></dt><dd><p>124        Sets the owning group of the Unix-domain socket(s).  (The owning125        user of the sockets is always the user that starts the126        server.)  In combination with the parameter127        <code class="varname">unix_socket_permissions</code> this can be used as128        an additional access control mechanism for Unix-domain connections.129        By default this is the empty string, which uses the default130        group of the server user.  This parameter can only be set at131        server start.132       </p><p>133        This parameter is not supported on Windows.  Any setting will be134        ignored.  Also, sockets in the abstract namespace have no file owner,135        so this setting is also ignored in that case.136       </p></dd><dt id="GUC-UNIX-SOCKET-PERMISSIONS"><span class="term"><code class="varname">unix_socket_permissions</code> (<code class="type">integer</code>)137      <a id="id-1.6.7.6.2.2.8.1.3" class="indexterm"></a>138      </span> <a href="#GUC-UNIX-SOCKET-PERMISSIONS" class="id_link">#</a></dt><dd><p>139        Sets the access permissions of the Unix-domain socket(s).  Unix-domain140        sockets use the usual Unix file system permission set.141        The parameter value is expected to be a numeric mode142        specified in the format accepted by the143        <code class="function">chmod</code> and <code class="function">umask</code>144        system calls.  (To use the customary octal format the number145        must start with a <code class="literal">0</code> (zero).)146       </p><p>147        The default permissions are <code class="literal">0777</code>, meaning148        anyone can connect. Reasonable alternatives are149        <code class="literal">0770</code> (only user and group, see also150        <code class="varname">unix_socket_group</code>) and <code class="literal">0700</code>151        (only user). (Note that for a Unix-domain socket, only write152        permission matters, so there is no point in setting or revoking153        read or execute permissions.)154       </p><p>155        This access control mechanism is independent of the one156        described in <a class="xref" href="client-authentication.html" title="Chapter 21. Client Authentication">Chapter 21</a>.157       </p><p>158        This parameter can only be set at server start.159       </p><p>160        This parameter is irrelevant on systems, notably Solaris as of Solaris161        10, that ignore socket permissions entirely.  There, one can achieve a162        similar effect by pointing <code class="varname">unix_socket_directories</code> to a163        directory having search permission limited to the desired audience.164       </p><p>165        Sockets in the abstract namespace have no file permissions, so this166        setting is also ignored in that case.167       </p></dd><dt id="GUC-BONJOUR"><span class="term"><code class="varname">bonjour</code> (<code class="type">boolean</code>)168      <a id="id-1.6.7.6.2.2.9.1.3" class="indexterm"></a>169      </span> <a href="#GUC-BONJOUR" class="id_link">#</a></dt><dd><p>170        Enables advertising the server's existence via171        <span class="productname">Bonjour</span>.  The default is off.172        This parameter can only be set at server start.173       </p></dd><dt id="GUC-BONJOUR-NAME"><span class="term"><code class="varname">bonjour_name</code> (<code class="type">string</code>)174      <a id="id-1.6.7.6.2.2.10.1.3" class="indexterm"></a>175      </span> <a href="#GUC-BONJOUR-NAME" class="id_link">#</a></dt><dd><p>176        Specifies the <span class="productname">Bonjour</span> service177        name.  The computer name is used if this parameter is set to the178        empty string <code class="literal">''</code> (which is the default).  This parameter is179        ignored if the server was not compiled with180        <span class="productname">Bonjour</span> support.181        This parameter can only be set at server start.182       </p></dd></dl></div></div><div class="sect2" id="RUNTIME-CONFIG-TCP-SETTINGS"><div class="titlepage"><div><div><h3 class="title">20.3.2. TCP Settings <a href="#RUNTIME-CONFIG-TCP-SETTINGS" class="id_link">#</a></h3></div></div></div><div class="variablelist"><dl class="variablelist"><dt id="GUC-TCP-KEEPALIVES-IDLE"><span class="term"><code class="varname">tcp_keepalives_idle</code> (<code class="type">integer</code>)183      <a id="id-1.6.7.6.3.2.1.1.3" class="indexterm"></a>184      </span> <a href="#GUC-TCP-KEEPALIVES-IDLE" class="id_link">#</a></dt><dd><p>185        Specifies the amount of time with no network activity after which186        the operating system should send a TCP keepalive message to the client.187        If this value is specified without units, it is taken as seconds.188        A value of 0 (the default) selects the operating system's default.189        On Windows, setting a value of 0 will set this parameter to 2 hours,190        since Windows does not provide a way to read the system default value.191        This parameter is supported only on systems that support192        <code class="symbol">TCP_KEEPIDLE</code> or an equivalent socket option, and on193        Windows; on other systems, it must be zero.194        In sessions connected via a Unix-domain socket, this parameter is195        ignored and always reads as zero.196       </p></dd><dt id="GUC-TCP-KEEPALIVES-INTERVAL"><span class="term"><code class="varname">tcp_keepalives_interval</code> (<code class="type">integer</code>)197      <a id="id-1.6.7.6.3.2.2.1.3" class="indexterm"></a>198      </span> <a href="#GUC-TCP-KEEPALIVES-INTERVAL" class="id_link">#</a></dt><dd><p>199        Specifies the amount of time after which a TCP keepalive message200        that has not been acknowledged by the client should be retransmitted.201        If this value is specified without units, it is taken as seconds.202        A value of 0 (the default) selects the operating system's default.203        On Windows, setting a value of 0 will set this parameter to 1 second,204        since Windows does not provide a way to read the system default value.205        This parameter is supported only on systems that support206        <code class="symbol">TCP_KEEPINTVL</code> or an equivalent socket option, and on207        Windows; on other systems, it must be zero.208        In sessions connected via a Unix-domain socket, this parameter is209        ignored and always reads as zero.210       </p></dd><dt id="GUC-TCP-KEEPALIVES-COUNT"><span class="term"><code class="varname">tcp_keepalives_count</code> (<code class="type">integer</code>)211      <a id="id-1.6.7.6.3.2.3.1.3" class="indexterm"></a>212      </span> <a href="#GUC-TCP-KEEPALIVES-COUNT" class="id_link">#</a></dt><dd><p>213        Specifies the number of TCP keepalive messages that can be lost before214        the server's connection to the client is considered dead.215        A value of 0 (the default) selects the operating system's default.216        This parameter is supported only on systems that support217        <code class="symbol">TCP_KEEPCNT</code> or an equivalent socket option (which does not include Windows);218        on other systems, it must be zero.219        In sessions connected via a Unix-domain socket, this parameter is220        ignored and always reads as zero.221       </p></dd><dt id="GUC-TCP-USER-TIMEOUT"><span class="term"><code class="varname">tcp_user_timeout</code> (<code class="type">integer</code>)222      <a id="id-1.6.7.6.3.2.4.1.3" class="indexterm"></a>223      </span> <a href="#GUC-TCP-USER-TIMEOUT" class="id_link">#</a></dt><dd><p>224        Specifies the amount of time that transmitted data may225        remain unacknowledged before the TCP connection is forcibly closed.226        If this value is specified without units, it is taken as milliseconds.227        A value of 0 (the default) selects the operating system's default.228        This parameter is supported only on systems that support229        <code class="symbol">TCP_USER_TIMEOUT</code> (which does not include Windows); on other systems, it must be zero.230        In sessions connected via a Unix-domain socket, this parameter is231        ignored and always reads as zero.232       </p></dd><dt id="GUC-CLIENT-CONNECTION-CHECK-INTERVAL"><span class="term"><code class="varname">client_connection_check_interval</code> (<code class="type">integer</code>)233      <a id="id-1.6.7.6.3.2.5.1.3" class="indexterm"></a>234      </span> <a href="#GUC-CLIENT-CONNECTION-CHECK-INTERVAL" class="id_link">#</a></dt><dd><p>235        Sets the time interval between optional checks that the client is still236        connected, while running queries.  The check is performed by polling237        the socket, and allows long running queries to be aborted sooner if238        the kernel reports that the connection is closed.239       </p><p>240        This option relies on kernel events exposed by Linux, macOS, illumos241        and the BSD family of operating systems, and is not currently available242        on other systems.243       </p><p>244        If the value is specified without units, it is taken as milliseconds.245        The default value is <code class="literal">0</code>, which disables connection246        checks.  Without connection checks, the server will detect the loss of247        the connection only at the next interaction with the socket, when it248        waits for, receives or sends data.249       </p><p>250        For the kernel itself to detect lost TCP connections reliably and within251        a known timeframe in all scenarios including network failure, it may252        also be necessary to adjust the TCP keepalive settings of the operating253        system, or the <a class="xref" href="runtime-config-connection.html#GUC-TCP-KEEPALIVES-IDLE">tcp_keepalives_idle</a>,254        <a class="xref" href="runtime-config-connection.html#GUC-TCP-KEEPALIVES-INTERVAL">tcp_keepalives_interval</a> and255        <a class="xref" href="runtime-config-connection.html#GUC-TCP-KEEPALIVES-COUNT">tcp_keepalives_count</a> settings of256        <span class="productname">PostgreSQL</span>.257       </p></dd></dl></div></div><div class="sect2" id="RUNTIME-CONFIG-CONNECTION-AUTHENTICATION"><div class="titlepage"><div><div><h3 class="title">20.3.3. Authentication <a href="#RUNTIME-CONFIG-CONNECTION-AUTHENTICATION" class="id_link">#</a></h3></div></div></div><div class="variablelist"><dl class="variablelist"><dt id="GUC-AUTHENTICATION-TIMEOUT"><span class="term"><code class="varname">authentication_timeout</code> (<code class="type">integer</code>)258      <a id="id-1.6.7.6.4.2.1.1.3" class="indexterm"></a>259      <a id="id-1.6.7.6.4.2.1.1.4" class="indexterm"></a>260      <a id="id-1.6.7.6.4.2.1.1.5" class="indexterm"></a>261      </span> <a href="#GUC-AUTHENTICATION-TIMEOUT" class="id_link">#</a></dt><dd><p>262        Maximum amount of time allowed to complete client authentication. If a263        would-be client has not completed the authentication protocol in264        this much time, the server closes the connection. This prevents265        hung clients from occupying a connection indefinitely.266        If this value is specified without units, it is taken as seconds.267        The default is one minute (<code class="literal">1m</code>).268        This parameter can only be set in the <code class="filename">postgresql.conf</code>269        file or on the server command line.270       </p></dd><dt id="GUC-PASSWORD-ENCRYPTION"><span class="term"><code class="varname">password_encryption</code> (<code class="type">enum</code>)271      <a id="id-1.6.7.6.4.2.2.1.3" class="indexterm"></a>272      </span> <a href="#GUC-PASSWORD-ENCRYPTION" class="id_link">#</a></dt><dd><p>273        When a password is specified in <a class="xref" href="sql-createrole.html" title="CREATE ROLE"><span class="refentrytitle">CREATE ROLE</span></a> or274        <a class="xref" href="sql-alterrole.html" title="ALTER ROLE"><span class="refentrytitle">ALTER ROLE</span></a>, this parameter determines the275        algorithm to use to encrypt the password.  Possible values are276        <code class="literal">scram-sha-256</code>, which will encrypt the password with277        SCRAM-SHA-256, and <code class="literal">md5</code>, which stores the password278        as an MD5 hash.  The default is <code class="literal">scram-sha-256</code>.279       </p><p>280        Note that older clients might lack support for the SCRAM authentication281        mechanism, and hence not work with passwords encrypted with282        SCRAM-SHA-256.  See <a class="xref" href="auth-password.html" title="21.5. Password Authentication">Section 21.5</a> for more details.283       </p></dd><dt id="GUC-SCRAM-ITERATIONS"><span class="term"><code class="varname">scram_iterations</code> (<code class="type">integer</code>)284      <a id="id-1.6.7.6.4.2.3.1.3" class="indexterm"></a>285      </span> <a href="#GUC-SCRAM-ITERATIONS" class="id_link">#</a></dt><dd><p>286        The number of computational iterations to be performed when encrypting287        a password using SCRAM-SHA-256. The default is <code class="literal">4096</code>.288        A higher number of iterations provides additional protection against289        brute-force attacks on stored passwords, but makes authentication290        slower. Changing the value has no effect on existing passwords291        encrypted with SCRAM-SHA-256 as the iteration count is fixed at the292        time of encryption. In order to make use of a changed value, a new293        password must be set.294       </p></dd><dt id="GUC-KRB-SERVER-KEYFILE"><span class="term"><code class="varname">krb_server_keyfile</code> (<code class="type">string</code>)295      <a id="id-1.6.7.6.4.2.4.1.3" class="indexterm"></a>296      </span> <a href="#GUC-KRB-SERVER-KEYFILE" class="id_link">#</a></dt><dd><p>297        Sets the location of the server's Kerberos key file.  The default is298        <code class="filename">FILE:/usr/local/pgsql/etc/krb5.keytab</code>299        (where the directory part is whatever was specified300        as <code class="varname">sysconfdir</code> at build time; use301        <code class="literal">pg_config --sysconfdir</code> to determine that).302        If this parameter is set to an empty string, it is ignored and a303        system-dependent default is used.304        This parameter can only be set in the305        <code class="filename">postgresql.conf</code> file or on the server command line.306        See <a class="xref" href="gssapi-auth.html" title="21.6. GSSAPI Authentication">Section 21.6</a> for more information.307       </p></dd><dt id="GUC-KRB-CASEINS-USERS"><span class="term"><code class="varname">krb_caseins_users</code> (<code class="type">boolean</code>)308      <a id="id-1.6.7.6.4.2.5.1.3" class="indexterm"></a>309      </span> <a href="#GUC-KRB-CASEINS-USERS" class="id_link">#</a></dt><dd><p>310        Sets whether GSSAPI user names should be treated311        case-insensitively.312        The default is <code class="literal">off</code> (case sensitive). This parameter can only be313        set in the <code class="filename">postgresql.conf</code> file or on the server command line.314       </p></dd><dt id="GUC-GSS-ACCEPT-DELEGATION"><span class="term"><code class="varname">gss_accept_delegation</code> (<code class="type">boolean</code>)315      <a id="id-1.6.7.6.4.2.6.1.3" class="indexterm"></a>316      </span> <a href="#GUC-GSS-ACCEPT-DELEGATION" class="id_link">#</a></dt><dd><p>317        Sets whether GSSAPI delegation should be accepted from the client.318        The default is <code class="literal">off</code> meaning credentials from the client will319        <span class="emphasis"><em>not</em></span> be accepted.  Changing this to <code class="literal">on</code> will make the server320        accept credentials delegated to it from the client. This parameter can only be321        set in the <code class="filename">postgresql.conf</code> file or on the server command line.322       </p></dd><dt id="GUC-DB-USER-NAMESPACE"><span class="term"><code class="varname">db_user_namespace</code> (<code class="type">boolean</code>)323      <a id="id-1.6.7.6.4.2.7.1.3" class="indexterm"></a>324      </span> <a href="#GUC-DB-USER-NAMESPACE" class="id_link">#</a></dt><dd><p>325        This parameter enables per-database user names.  It is off by default.326        This parameter can only be set in the <code class="filename">postgresql.conf</code>327        file or on the server command line.328       </p><p>329        If this is on, you should create users as <em class="replaceable"><code>username@dbname</code></em>.330        When <em class="replaceable"><code>username</code></em> is passed by a connecting client,331        <code class="literal">@</code> and the database name are appended to the user332        name and that database-specific user name is looked up by the333        server. Note that when you create users with names containing334        <code class="literal">@</code> within the SQL environment, you will need to335        quote the user name.336       </p><p>337        With this parameter enabled, you can still create ordinary global338        users.  Simply append <code class="literal">@</code> when specifying the user339        name in the client, e.g., <code class="literal">joe@</code>.  The <code class="literal">@</code>340        will be stripped off before the user name is looked up by the341        server.342       </p><p>343        <code class="varname">db_user_namespace</code> causes the client's and344        server's user name representation to differ.345        Authentication checks are always done with the server's user name346        so authentication methods must be configured for the347        server's user name, not the client's.  Because348        <code class="literal">md5</code> uses the user name as salt on both the349        client and server, <code class="literal">md5</code> cannot be used with350        <code class="varname">db_user_namespace</code>.351       </p><div class="note"><h3 class="title">Note</h3><p>352         This feature is intended as a temporary measure until a353         complete solution is found.  At that time, this option will354         be removed.355        </p></div></dd></dl></div></div><div class="sect2" id="RUNTIME-CONFIG-CONNECTION-SSL"><div class="titlepage"><div><div><h3 class="title">20.3.4. SSL <a href="#RUNTIME-CONFIG-CONNECTION-SSL" class="id_link">#</a></h3></div></div></div><p>356      See <a class="xref" href="ssl-tcp.html" title="19.9. Secure TCP/IP Connections with SSL">Section 19.9</a> for more information about setting up357      <acronym class="acronym">SSL</acronym>. The configuration parameters for controlling358      transfer encryption using <acronym class="acronym">TLS</acronym> protocols are named359      <code class="literal">ssl</code> for historic reasons, even though support for360      the <acronym class="acronym">SSL</acronym> protocol has been deprecated.361      <acronym class="acronym">SSL</acronym> is in this context used interchangeably with362      <acronym class="acronym">TLS</acronym>.363     </p><div class="variablelist"><dl class="variablelist"><dt id="GUC-SSL"><span class="term"><code class="varname">ssl</code> (<code class="type">boolean</code>)364      <a id="id-1.6.7.6.5.3.1.1.3" class="indexterm"></a>365      </span> <a href="#GUC-SSL" class="id_link">#</a></dt><dd><p>366        Enables <acronym class="acronym">SSL</acronym> connections.367        This parameter can only be set in the <code class="filename">postgresql.conf</code>368        file or on the server command line.369        The default is <code class="literal">off</code>.370       </p></dd><dt id="GUC-SSL-CA-FILE"><span class="term"><code class="varname">ssl_ca_file</code> (<code class="type">string</code>)371      <a id="id-1.6.7.6.5.3.2.1.3" class="indexterm"></a>372      </span> <a href="#GUC-SSL-CA-FILE" class="id_link">#</a></dt><dd><p>373        Specifies the name of the file containing the SSL server certificate374        authority (CA).375        Relative paths are relative to the data directory.376        This parameter can only be set in the <code class="filename">postgresql.conf</code>377        file or on the server command line.378        The default is empty, meaning no CA file is loaded,379        and client certificate verification is not performed.380       </p></dd><dt id="GUC-SSL-CERT-FILE"><span class="term"><code class="varname">ssl_cert_file</code> (<code class="type">string</code>)381      <a id="id-1.6.7.6.5.3.3.1.3" class="indexterm"></a>382      </span> <a href="#GUC-SSL-CERT-FILE" class="id_link">#</a></dt><dd><p>383        Specifies the name of the file containing the SSL server certificate.384        Relative paths are relative to the data directory.385        This parameter can only be set in the <code class="filename">postgresql.conf</code>386        file or on the server command line.387        The default is <code class="filename">server.crt</code>.388       </p></dd><dt id="GUC-SSL-CRL-FILE"><span class="term"><code class="varname">ssl_crl_file</code> (<code class="type">string</code>)389      <a id="id-1.6.7.6.5.3.4.1.3" class="indexterm"></a>390      </span> <a href="#GUC-SSL-CRL-FILE" class="id_link">#</a></dt><dd><p>391        Specifies the name of the file containing the SSL client certificate392        revocation list (CRL).393        Relative paths are relative to the data directory.394        This parameter can only be set in the <code class="filename">postgresql.conf</code>395        file or on the server command line.396        The default is empty, meaning no CRL file is loaded (unless397        <a class="xref" href="runtime-config-connection.html#GUC-SSL-CRL-DIR">ssl_crl_dir</a> is set).398       </p></dd><dt id="GUC-SSL-CRL-DIR"><span class="term"><code class="varname">ssl_crl_dir</code> (<code class="type">string</code>)399      <a id="id-1.6.7.6.5.3.5.1.3" class="indexterm"></a>400      </span> <a href="#GUC-SSL-CRL-DIR" class="id_link">#</a></dt><dd><p>401        Specifies the name of the directory containing the SSL client402        certificate revocation list (CRL).  Relative paths are relative to the403        data directory.  This parameter can only be set in404        the <code class="filename">postgresql.conf</code> file or on the server command405        line.  The default is empty, meaning no CRLs are used (unless406        <a class="xref" href="runtime-config-connection.html#GUC-SSL-CRL-FILE">ssl_crl_file</a> is set).407       </p><p>408        The directory needs to be prepared with the409        <span class="productname">OpenSSL</span> command410        <code class="literal">openssl rehash</code> or <code class="literal">c_rehash</code>.  See411        its documentation for details.412       </p><p>413        When using this setting, CRLs in the specified directory are loaded414        on-demand at connection time.  New CRLs can be added to the directory415        and will be used immediately.  This is unlike <a class="xref" href="runtime-config-connection.html#GUC-SSL-CRL-FILE">ssl_crl_file</a>, which causes the CRL in the file to be416        loaded at server start time or when the configuration is reloaded.417        Both settings can be used together.418       </p></dd><dt id="GUC-SSL-KEY-FILE"><span class="term"><code class="varname">ssl_key_file</code> (<code class="type">string</code>)419      <a id="id-1.6.7.6.5.3.6.1.3" class="indexterm"></a>420      </span> <a href="#GUC-SSL-KEY-FILE" class="id_link">#</a></dt><dd><p>421        Specifies the name of the file containing the SSL server private key.422        Relative paths are relative to the data directory.423        This parameter can only be set in the <code class="filename">postgresql.conf</code>424        file or on the server command line.425        The default is <code class="filename">server.key</code>.426       </p></dd><dt id="GUC-SSL-CIPHERS"><span class="term"><code class="varname">ssl_ciphers</code> (<code class="type">string</code>)427      <a id="id-1.6.7.6.5.3.7.1.3" class="indexterm"></a>428      </span> <a href="#GUC-SSL-CIPHERS" class="id_link">#</a></dt><dd><p>429        Specifies a list of <acronym class="acronym">SSL</acronym> cipher suites that are430        allowed to be used by SSL connections.  See the431        <span class="citerefentry"><span class="refentrytitle">ciphers</span></span>432        manual page in the <span class="productname">OpenSSL</span> package for the433        syntax of this setting and a list of supported values.  Only434        connections using TLS version 1.2 and lower are affected.  There is435        currently no setting that controls the cipher choices used by TLS436        version 1.3 connections.  The default value is437        <code class="literal">HIGH:MEDIUM:+3DES:!aNULL</code>.  The default is usually a438        reasonable choice unless you have specific security requirements.439       </p><p>440        This parameter can only be set in the441        <code class="filename">postgresql.conf</code> file or on the server command442        line.443       </p><p>444        Explanation of the default value:445        </p><div class="variablelist"><dl class="variablelist"><dt id="GUC-SSL-CIPHERS-HIGH"><span class="term"><code class="literal">HIGH</code></span> <a href="#GUC-SSL-CIPHERS-HIGH" class="id_link">#</a></dt><dd><p>446            Cipher suites that use ciphers from <code class="literal">HIGH</code> group (e.g.,447            AES, Camellia, 3DES)448           </p></dd><dt id="GUC-SSL-CIPHERS-MEDIUM"><span class="term"><code class="literal">MEDIUM</code></span> <a href="#GUC-SSL-CIPHERS-MEDIUM" class="id_link">#</a></dt><dd><p>449            Cipher suites that use ciphers from <code class="literal">MEDIUM</code> group450            (e.g., RC4, SEED)451           </p></dd><dt id="GUC-SSL-CIPHERS-PLUS-3DES"><span class="term"><code class="literal">+3DES</code></span> <a href="#GUC-SSL-CIPHERS-PLUS-3DES" class="id_link">#</a></dt><dd><p>452            The <span class="productname">OpenSSL</span> default order for453            <code class="literal">HIGH</code> is problematic because it orders 3DES454            higher than AES128.  This is wrong because 3DES offers less455            security than AES128, and it is also much slower.456            <code class="literal">+3DES</code> reorders it after all other457            <code class="literal">HIGH</code> and <code class="literal">MEDIUM</code> ciphers.458           </p></dd><dt id="GUC-SSL-CIPHERS-NOT-ANULL"><span class="term"><code class="literal">!aNULL</code></span> <a href="#GUC-SSL-CIPHERS-NOT-ANULL" class="id_link">#</a></dt><dd><p>459            Disables anonymous cipher suites that do no authentication.  Such460            cipher suites are vulnerable to <acronym class="acronym">MITM</acronym> attacks and461            therefore should not be used.462           </p></dd></dl></div><p>463       </p><p>464        Available cipher suite details will vary across465        <span class="productname">OpenSSL</span> versions.  Use the command466        <code class="literal">openssl ciphers -v 'HIGH:MEDIUM:+3DES:!aNULL'</code> to467        see actual details for the currently installed468        <span class="productname">OpenSSL</span> version.  Note that this list is469        filtered at run time based on the server key type.470       </p></dd><dt id="GUC-SSL-PREFER-SERVER-CIPHERS"><span class="term"><code class="varname">ssl_prefer_server_ciphers</code> (<code class="type">boolean</code>)471      <a id="id-1.6.7.6.5.3.8.1.3" class="indexterm"></a>472      </span> <a href="#GUC-SSL-PREFER-SERVER-CIPHERS" class="id_link">#</a></dt><dd><p>473        Specifies whether to use the server's SSL cipher preferences, rather474        than the client's.475        This parameter can only be set in the <code class="filename">postgresql.conf</code>476        file or on the server command line.477        The default is <code class="literal">on</code>.478       </p><p>479        Older PostgreSQL versions do not have this setting and always use the480        client's preferences.  This setting is mainly for backward481        compatibility with those versions.  Using the server's preferences is482        usually better because it is more likely that the server is appropriately483        configured.484       </p></dd><dt id="GUC-SSL-ECDH-CURVE"><span class="term"><code class="varname">ssl_ecdh_curve</code> (<code class="type">string</code>)485      <a id="id-1.6.7.6.5.3.9.1.3" class="indexterm"></a>486      </span> <a href="#GUC-SSL-ECDH-CURVE" class="id_link">#</a></dt><dd><p>487        Specifies the name of the curve to use in <acronym class="acronym">ECDH</acronym> key488        exchange.  It needs to be supported by all clients that connect.489        It does not need to be the same curve used by the server's Elliptic490        Curve key.491        This parameter can only be set in the <code class="filename">postgresql.conf</code>492        file or on the server command line.493        The default is <code class="literal">prime256v1</code>.494       </p><p>495        <span class="productname">OpenSSL</span> names for the most common curves496        are:497        <code class="literal">prime256v1</code> (NIST P-256),498        <code class="literal">secp384r1</code> (NIST P-384),499        <code class="literal">secp521r1</code> (NIST P-521).500        The full list of available curves can be shown with the command501        <code class="command">openssl ecparam -list_curves</code>.  Not all of them502        are usable in <acronym class="acronym">TLS</acronym> though.503       </p></dd><dt id="GUC-SSL-MIN-PROTOCOL-VERSION"><span class="term"><code class="varname">ssl_min_protocol_version</code> (<code class="type">enum</code>)504      <a id="id-1.6.7.6.5.3.10.1.3" class="indexterm"></a>505      </span> <a href="#GUC-SSL-MIN-PROTOCOL-VERSION" class="id_link">#</a></dt><dd><p>506        Sets the minimum SSL/TLS protocol version to use.  Valid values are507        currently: <code class="literal">TLSv1</code>, <code class="literal">TLSv1.1</code>,508        <code class="literal">TLSv1.2</code>, <code class="literal">TLSv1.3</code>.  Older509        versions of the <span class="productname">OpenSSL</span> library do not510        support all values; an error will be raised if an unsupported setting511        is chosen.  Protocol versions before TLS 1.0, namely SSL version 2 and512        3, are always disabled.513       </p><p>514        The default is <code class="literal">TLSv1.2</code>, which satisfies industry515        best practices as of this writing.516       </p><p>517        This parameter can only be set in the <code class="filename">postgresql.conf</code>518        file or on the server command line.519       </p></dd><dt id="GUC-SSL-MAX-PROTOCOL-VERSION"><span class="term"><code class="varname">ssl_max_protocol_version</code> (<code class="type">enum</code>)520      <a id="id-1.6.7.6.5.3.11.1.3" class="indexterm"></a>521      </span> <a href="#GUC-SSL-MAX-PROTOCOL-VERSION" class="id_link">#</a></dt><dd><p>522        Sets the maximum SSL/TLS protocol version to use.  Valid values are as523        for <a class="xref" href="runtime-config-connection.html#GUC-SSL-MIN-PROTOCOL-VERSION">ssl_min_protocol_version</a>, with addition of524        an empty string, which allows any protocol version.  The default is to525        allow any version.  Setting the maximum protocol version is mainly526        useful for testing or if some component has issues working with a527        newer protocol.528       </p><p>529        This parameter can only be set in the <code class="filename">postgresql.conf</code>530        file or on the server command line.531       </p></dd><dt id="GUC-SSL-DH-PARAMS-FILE"><span class="term"><code class="varname">ssl_dh_params_file</code> (<code class="type">string</code>)532      <a id="id-1.6.7.6.5.3.12.1.3" class="indexterm"></a>533      </span> <a href="#GUC-SSL-DH-PARAMS-FILE" class="id_link">#</a></dt><dd><p>534        Specifies the name of the file containing Diffie-Hellman parameters535        used for so-called ephemeral DH family of SSL ciphers. The default is536        empty, in which case compiled-in default DH parameters used. Using537        custom DH parameters reduces the exposure if an attacker manages to538        crack the well-known compiled-in DH parameters. You can create your own539        DH parameters file with the command540        <code class="command">openssl dhparam -out dhparams.pem 2048</code>.541       </p><p>542        This parameter can only be set in the <code class="filename">postgresql.conf</code>543        file or on the server command line.544       </p></dd><dt id="GUC-SSL-PASSPHRASE-COMMAND"><span class="term"><code class="varname">ssl_passphrase_command</code> (<code class="type">string</code>)545      <a id="id-1.6.7.6.5.3.13.1.3" class="indexterm"></a>546      </span> <a href="#GUC-SSL-PASSPHRASE-COMMAND" class="id_link">#</a></dt><dd><p>547        Sets an external command to be invoked when a passphrase for548        decrypting an SSL file such as a private key needs to be obtained.  By549        default, this parameter is empty, which means the built-in prompting550        mechanism is used.551       </p><p>552        The command must print the passphrase to the standard output and exit553        with code 0.  In the parameter value, <code class="literal">%p</code> is554        replaced by a prompt string.  (Write <code class="literal">%%</code> for a555        literal <code class="literal">%</code>.)  Note that the prompt string will556        probably contain whitespace, so be sure to quote adequately.  A single557        newline is stripped from the end of the output if present.558       </p><p>559        The command does not actually have to prompt the user for a560        passphrase.  It can read it from a file, obtain it from a keychain561        facility, or similar.  It is up to the user to make sure the chosen562        mechanism is adequately secure.563       </p><p>564        This parameter can only be set in the <code class="filename">postgresql.conf</code>565        file or on the server command line.566       </p></dd><dt id="GUC-SSL-PASSPHRASE-COMMAND-SUPPORTS-RELOAD"><span class="term"><code class="varname">ssl_passphrase_command_supports_reload</code> (<code class="type">boolean</code>)567      <a id="id-1.6.7.6.5.3.14.1.3" class="indexterm"></a>568      </span> <a href="#GUC-SSL-PASSPHRASE-COMMAND-SUPPORTS-RELOAD" class="id_link">#</a></dt><dd><p>569        This parameter determines whether the passphrase command set by570        <code class="varname">ssl_passphrase_command</code> will also be called during a571        configuration reload if a key file needs a passphrase.  If this572        parameter is off (the default), then573        <code class="varname">ssl_passphrase_command</code> will be ignored during a574        reload and the SSL configuration will not be reloaded if a passphrase575        is needed.  That setting is appropriate for a command that requires a576        TTY for prompting, which might not be available when the server is577        running.  Setting this parameter to on might be appropriate if the578        passphrase is obtained from a file, for example.579       </p><p>580        This parameter can only be set in the <code class="filename">postgresql.conf</code>581        file or on the server command line.582       </p></dd></dl></div></div></div><div class="navfooter"><hr /><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="runtime-config-file-locations.html" title="20.2. File Locations">Prev</a> </td><td width="20%" align="center"><a accesskey="u" href="runtime-config.html" title="Chapter 20. Server Configuration">Up</a></td><td width="40%" align="right"> <a accesskey="n" href="runtime-config-resource.html" title="20.4. Resource Consumption">Next</a></td></tr><tr><td width="40%" align="left" valign="top">20.2. File Locations </td><td width="20%" align="center"><a accesskey="h" href="index.html" title="PostgreSQL 16.3 Documentation">Home</a></td><td width="40%" align="right" valign="top"> 20.4. Resource Consumption</td></tr></table></div></body></html>
codekingpro/portable-devtools · Team Ai