{"kind": "auth", "major": "18", "item": {"slug": "gss", "name": "gss", "name_zh": "", "category": "\u8eab\u4efd\u8ba4\u8bc1\u4e0e\u8bbf\u95ee\u63a7\u5236", "summary": "\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002", "aliases": [], "content_hash": "770da2f51fed73bc6d028052f2303c4f5dd052a0fca58c2251997565689e06e2", "versions": {"10": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u4e0e\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e username@EXAMPLE.COM \uff08\u6216\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\u8fd9\u6837\u7684 GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u6620\u5c04\u6240\u7528\u7684\u7528\u6237\u540d\u662f username@EXAMPLE.COM \uff08\u6216\u76f8\u5e94\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5c06 include_realm \u8bbe\u4e3a 0\uff0c\u6b64\u65f6\u6620\u5c04\u6240\u89c1\u7684\u7cfb\u7edf\u7528\u6237\u540d\u4e3a username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "10.23", "major": "10", "channel": "historical", "revision": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "catalog_fingerprint": "691be281b476dde4374d7f805b2bacc2e75bdef40f1e9d3d42e91f97fe95cfd0"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, {"url": "https://pg.center/docs/10/auth-methods.html#GSSAPI-AUTH", "path": "auth-methods.html", "label": "PostgreSQL 10 English manual", "sha256": "856d36a3fdfe8c45a25832e49bd07e9b7480f2ff9a33e58ac7c392630149bc34", "language": "en", "original_url": "/docs/10/auth-methods.html#GSSAPI-AUTH"}, {"url": "https://pg.center/docs/10/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 10 English manual", "sha256": "04fed609a50e8fd3013ffebb83039c544d39b6c73a6c2b2e23cd7864a70b42da", "language": "en", "original_url": "/docs/10/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.3.3 \u8282\u3002"], "manual_html": "<div class=\"sect2\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h3 class=\"title\" lang=\"zh\"><span class=\"sect2\"><a href=\"/docs/10/auth-methods.html#GSSAPI-AUTH\">20.3.3. GSSAPI \u8ba4\u8bc1</a></span></h3>\n</div>\n</div>\n</div>\n<p lang=\"zh\">GSSAPI \u662f RFC 2743 \u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002PostgreSQL \u6309\u7167 RFC 1964 \u652f\u6301\u57fa\u4e8e Kerberos \u7684 GSSAPI \u8ba4\u8bc1\u3002\u5bf9\u4e8e\u652f\u6301\u5b83\u7684\u7cfb\u7edf\uff0cGSSAPI \u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\uff0c\u4f46\u9664\u975e\u4f7f\u7528 SSL\uff0c\u5426\u5219\u6570\u636e\u5e93\u8fde\u63a5\u4e0a\u4f20\u8f93\u7684\u6570\u636e\u4e0d\u4f1a\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/10/installation.html\" title=\"\u7b2c\u00a016\u00a0\u7ae0\u00a0 \u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a016\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">GSSAPI \u4f7f\u7528 Kerberos \u65f6\uff0c\u91c7\u7528 servicename/hostname@realm \u5f62\u5f0f\u7684\u6807\u51c6\u4e3b\u4f53\u540d\u79f0\u3002PostgreSQL \u670d\u52a1\u5668\u63a5\u53d7\u5176 keytab \u4e2d\u5305\u542b\u7684\u4efb\u610f\u4e3b\u4f53\uff0c\u4f46\u5ba2\u6237\u7aef\u8fde\u63a5\u65f6\u5e94\u786e\u4fdd krbsrvname \u8fde\u63a5\u53c2\u6570\u6307\u5b9a\u7684\u4e3b\u4f53\u4fe1\u606f\u6b63\u786e\uff0c\u53e6\u89c1\u7b2c 33.1.2 \u8282\u3002\u53ef\u5728\u6784\u5efa\u65f6\u7528 ./configure --with-krb-srvnam=whatever \u5c06\u5b89\u88c5\u9ed8\u8ba4\u503c\u4ece postgres \u6539\u4e3a\u5176\u4ed6\u503c\u3002\u591a\u6570\u73af\u5883\u65e0\u9700\u4fee\u6539\u6b64\u53c2\u6570\uff1b\u67d0\u4e9b Kerberos \u5b9e\u73b0\u53ef\u80fd\u8981\u6c42\u4e0d\u540c\u7684\u670d\u52a1\u540d\uff0c\u4f8b\u5982 Microsoft Active Directory \u8981\u6c42\u4f7f\u7528\u5927\u5199 POSTGRES\u3002</p>\n<p lang=\"zh\"><em class=\"replaceable\"><code>hostname</code></em> \u662f\u670d\u52a1\u5668\u673a\u5668\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002\u670d\u52a1\u4e3b\u4f53\u7684 realm \u662f\u670d\u52a1\u5668\u673a\u5668\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u53ef\u4ee5\u901a\u8fc7 <code class=\"filename\">pg_ident.conf</code> \u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u5230\u4e0d\u540c\u7684 <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u4f8b\u5982\uff0c\u53ef\u4ee5\u5c06 <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a <code class=\"literal\">pgusername</code>\u3002\u4e5f\u53ef\u4ee5\u4e0d\u4f7f\u7528\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5c06\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u7528\u4f5c <span class=\"productname\">PostgreSQL</span> \u4e2d\u7684\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u901a\u8fc7\u53c2\u6570\u4ece\u4e3b\u4f53\u540d\u79f0\u4e2d\u53bb\u6389 realm\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u786e\u4fdd <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u6237\u80fd\u591f\u8bfb\u53d6\u670d\u52a1\u5668\u7684 keytab \u6587\u4ef6\uff08\u6700\u597d\u53ea\u80fd\u8bfb\u53d6\uff0c\u4e0d\u80fd\u5199\u5165\uff09\u3002\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/10/runtime.html#POSTGRES-USER\" title=\"18.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a018.1\u00a0\u8282</a>\u3002\uff09\u5bc6\u94a5\u6587\u4ef6\u7684\u4f4d\u7f6e\u7531<a class=\"xref\" href=\"/docs/10/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u914d\u7f6e\u53c2\u6570\u6307\u5b9a\u3002\u9ed8\u8ba4\u4f4d\u7f6e\u662f <code class=\"filename\">/usr/local/pgsql/etc/krb5.keytab</code>\uff08\u6216\u8005\u6784\u5efa\u65f6\u7528 <code class=\"varname\">sysconfdir</code> \u6307\u5b9a\u7684\u76ee\u5f55\uff09\u3002\u51fa\u4e8e\u5b89\u5168\u8003\u8651\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4f7f\u7528\u4e13\u7528 keytab\uff0c\u800c\u4e0d\u662f\u653e\u5bbd\u7cfb\u7edf keytab \u6587\u4ef6\u7684\u6743\u9650\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7531 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u60c5\u53c2\u89c1 Kerberos \u6587\u6863\u3002\u4ee5\u4e0b\u793a\u4f8b\u9002\u7528\u4e8e\u517c\u5bb9 MIT \u7684 Kerberos 5 \u5b9e\u73b0\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ank -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\">\u8fde\u63a5\u6570\u636e\u5e93\u65f6\uff0c\u8bf7\u786e\u4fdd\u6301\u6709\u4e0e\u8bf7\u6c42\u7684\u6570\u636e\u5e93\u7528\u6237\u540d\u76f8\u5339\u914d\u7684\u4e3b\u4f53\u7968\u636e\u3002\u4f8b\u5982\uff0c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e3a <code class=\"literal\">fred</code> \u65f6\uff0c\u4e3b\u4f53 <code class=\"literal\">fred@EXAMPLE.COM</code> \u53ef\u4ee5\u8fde\u63a5\u3002\u5982\u679c\u8fd8\u8981\u5141\u8bb8\u4e3b\u4f53 <code class=\"literal\">fred/users.example.com@EXAMPLE.COM</code>\uff0c\u8bf7\u6309<a class=\"xref\" href=\"/docs/10/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u6240\u8ff0\u4f7f\u7528\u7528\u6237\u540d\u6620\u5c04\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u9002\u7528\u4e8e <span class=\"productname\">GSSAPI</span>\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/10/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u4e0e\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/10/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\u8fd9\u6837\u7684 GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u6620\u5c04\u6240\u7528\u7684\u7528\u6237\u540d\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u76f8\u5e94\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff0c\u6b64\u65f6\u6620\u5c04\u6240\u89c1\u7684\u7cfb\u7edf\u7528\u6237\u540d\u4e3a <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/10/auth-methods.html#GSSAPI-AUTH", "localization": {"status": "complete", "sources": [{"url": "/docs/10/auth-methods.html", "method": "same-major semantic node", "sha256": "128b4f29cf06d6bde5b9e357daacb6d538044ee392e4aece0e31c90b0a37b647", "language": "zh", "matched_nodes": ["#AUTH-METHODS/div[1]/dl[0]/dt[2]", "#AUTH-METHODS/div[5]/div[13]/dl[0]/dd[1]", "#AUTH-METHODS/div[5]/div[13]/dl[0]/dd[3]", "#AUTH-METHODS/div[5]/div[13]/dl[0]/dd[5]", "#AUTH-METHODS/div[5]/p[11]", "#AUTH-METHODS/div[5]/p[12]", "#AUTH-METHODS/div[5]/p[3]", "#AUTH-METHODS/div[5]/p[5]", "#AUTH-METHODS/div[5]/p[6]", "#AUTH-METHODS/div[5]/p[8]", "#AUTH-METHODS/div[5]/p[9]"]}], "language": "zh", "original_text": {"/versions/10/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.3.3 for details.", "/versions/10/facts/0/label": "Method", "/versions/10/facts/1/label": "Configuration", "/versions/10/facts/2/label": "Inventory", "/versions/10/facts/2/value": "User-visible source authentication method", "/versions/10/tables/0/title": "Documented method options and alternatives", "/versions/10/tables/0/columns/0/label": "Option or term", "/versions/10/tables/0/columns/1/label": "Meaning", "/versions/10/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/10/tables/0/rows/1/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/10/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "f1b102ccc72a34c1025eb79dafdd4f1ffe63847c2c2fbf8fa44dcc1ce46c0c0a"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "11": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u4e0e\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e username@EXAMPLE.COM \uff08\u6216\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\u8fd9\u6837\u7684 GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u6620\u5c04\u6240\u7528\u7684\u7528\u6237\u540d\u662f username@EXAMPLE.COM \uff08\u6216\u76f8\u5e94\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5c06 include_realm \u8bbe\u4e3a 0\uff0c\u6b64\u65f6\u6620\u5c04\u6240\u89c1\u7684\u7cfb\u7edf\u7528\u6237\u540d\u4e3a username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "11.22", "major": "11", "channel": "historical", "revision": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "catalog_fingerprint": "8f21f4444b7f68923f4762af0eb7937fa2907026e91249483e79050de012c901"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, {"url": "https://pg.center/docs/11/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 11 English manual", "sha256": "123965cdb7be25b3abcb43a1eb36ca4918913ed79859779f9bc9607bf41656fb", "language": "en", "original_url": "/docs/11/gssapi-auth.html"}, {"url": "https://pg.center/docs/11/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 11 English manual", "sha256": "5477c61a002171f5b4c462052d91231c405f39d89d825faf71e52fbae358eef7", "language": "en", "original_url": "/docs/11/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.6 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">GSSAPI \u662f RFC 2743 \u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002PostgreSQL \u6309\u7167 RFC 1964 \u652f\u6301\u57fa\u4e8e Kerberos \u7684 GSSAPI \u8ba4\u8bc1\u3002\u5bf9\u4e8e\u652f\u6301\u5b83\u7684\u7cfb\u7edf\uff0cGSSAPI \u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\uff0c\u4f46\u9664\u975e\u4f7f\u7528 SSL\uff0c\u5426\u5219\u6570\u636e\u5e93\u8fde\u63a5\u4e0a\u4f20\u8f93\u7684\u6570\u636e\u4e0d\u4f1a\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/11/installation.html\" title=\"\u7b2c\u00a016\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a016\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">GSSAPI \u4f7f\u7528 Kerberos \u65f6\uff0c\u91c7\u7528 servicename/hostname@realm \u5f62\u5f0f\u7684\u6807\u51c6\u4e3b\u4f53\u540d\u79f0\u3002PostgreSQL \u670d\u52a1\u5668\u63a5\u53d7\u5176 keytab \u4e2d\u5305\u542b\u7684\u4efb\u610f\u4e3b\u4f53\uff0c\u4f46\u5ba2\u6237\u7aef\u8fde\u63a5\u65f6\u5e94\u786e\u4fdd krbsrvname \u8fde\u63a5\u53c2\u6570\u6307\u5b9a\u7684\u4e3b\u4f53\u4fe1\u606f\u6b63\u786e\uff0c\u53e6\u89c1\u7b2c 34.1.2 \u8282\u3002\u53ef\u5728\u6784\u5efa\u65f6\u7528 ./configure --with-krb-srvnam=whatever \u5c06\u5b89\u88c5\u9ed8\u8ba4\u503c\u4ece postgres \u6539\u4e3a\u5176\u4ed6\u503c\u3002\u591a\u6570\u73af\u5883\u65e0\u9700\u4fee\u6539\u6b64\u53c2\u6570\uff1b\u67d0\u4e9b Kerberos \u5b9e\u73b0\u53ef\u80fd\u8981\u6c42\u4e0d\u540c\u7684\u670d\u52a1\u540d\uff0c\u4f8b\u5982 Microsoft Active Directory \u8981\u6c42\u4f7f\u7528\u5927\u5199 POSTGRES\u3002</p>\n<p lang=\"zh\"><em class=\"replaceable\"><code>hostname</code></em> \u662f\u670d\u52a1\u5668\u673a\u5668\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002\u670d\u52a1\u4e3b\u4f53\u7684 realm \u662f\u670d\u52a1\u5668\u673a\u5668\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u53ef\u4ee5\u901a\u8fc7 <code class=\"filename\">pg_ident.conf</code> \u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u5230\u4e0d\u540c\u7684 <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u4f8b\u5982\uff0c\u53ef\u4ee5\u5c06 <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a <code class=\"literal\">pgusername</code>\u3002\u4e5f\u53ef\u4ee5\u4e0d\u4f7f\u7528\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5c06\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u7528\u4f5c <span class=\"productname\">PostgreSQL</span> \u4e2d\u7684\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u901a\u8fc7\u53c2\u6570\u4ece\u4e3b\u4f53\u540d\u79f0\u4e2d\u53bb\u6389 realm\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u786e\u4fdd <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u6237\u80fd\u591f\u8bfb\u53d6\u670d\u52a1\u5668\u7684 keytab \u6587\u4ef6\uff08\u6700\u597d\u53ea\u80fd\u8bfb\u53d6\uff0c\u4e0d\u80fd\u5199\u5165\uff09\u3002\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/11/runtime.html#POSTGRES-USER\" title=\"18.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a018.1\u00a0\u8282</a>\u3002\uff09\u5bc6\u94a5\u6587\u4ef6\u7684\u4f4d\u7f6e\u7531<a class=\"xref\" href=\"/docs/11/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u914d\u7f6e\u53c2\u6570\u6307\u5b9a\u3002\u9ed8\u8ba4\u4f4d\u7f6e\u662f <code class=\"filename\">/usr/local/pgsql/etc/krb5.keytab</code>\uff08\u6216\u8005\u6784\u5efa\u65f6\u7528 <code class=\"varname\">sysconfdir</code> \u6307\u5b9a\u7684\u76ee\u5f55\uff09\u3002\u51fa\u4e8e\u5b89\u5168\u8003\u8651\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4f7f\u7528\u4e13\u7528 keytab\uff0c\u800c\u4e0d\u662f\u653e\u5bbd\u7cfb\u7edf keytab \u6587\u4ef6\u7684\u6743\u9650\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7531 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u60c5\u53c2\u89c1 Kerberos \u6587\u6863\u3002\u4ee5\u4e0b\u793a\u4f8b\u9002\u7528\u4e8e\u517c\u5bb9 MIT \u7684 Kerberos 5 \u5b9e\u73b0\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ank -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\">\u8fde\u63a5\u6570\u636e\u5e93\u65f6\uff0c\u8bf7\u786e\u4fdd\u6301\u6709\u4e0e\u8bf7\u6c42\u7684\u6570\u636e\u5e93\u7528\u6237\u540d\u76f8\u5339\u914d\u7684\u4e3b\u4f53\u7968\u636e\u3002\u4f8b\u5982\uff0c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e3a <code class=\"literal\">fred</code> \u65f6\uff0c\u4e3b\u4f53 <code class=\"literal\">fred@EXAMPLE.COM</code> \u53ef\u4ee5\u8fde\u63a5\u3002\u5982\u679c\u8fd8\u8981\u5141\u8bb8\u4e3b\u4f53 <code class=\"literal\">fred/users.example.com@EXAMPLE.COM</code>\uff0c\u8bf7\u6309<a class=\"xref\" href=\"/docs/11/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u6240\u8ff0\u4f7f\u7528\u7528\u6237\u540d\u6620\u5c04\u3002</p>\n<p lang=\"zh\">\u4ee5\u4e0b\u914d\u7f6e\u9009\u9879\u9002\u7528\u4e8e <span class=\"productname\">GSSAPI</span>\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/11/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u4e0e\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/11/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\u8fd9\u6837\u7684 GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u6620\u5c04\u6240\u7528\u7684\u7528\u6237\u540d\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u76f8\u5e94\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff0c\u6b64\u65f6\u6620\u5c04\u6240\u89c1\u7684\u7cfb\u7edf\u7528\u6237\u540d\u4e3a <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/11/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/11/gssapi-auth.html", "method": "same-major semantic node", "sha256": "67618cfbefdcb501b27c607fb3c24fea007d5113dbecb6b354130878751bff64", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[13]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[13]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[13]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[12]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/versions/11/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.6 for details.", "/versions/11/facts/0/label": "Method", "/versions/11/facts/1/label": "Configuration", "/versions/11/facts/2/label": "Inventory", "/versions/11/facts/2/value": "User-visible source authentication method", "/versions/11/tables/0/title": "Documented method options and alternatives", "/versions/11/tables/0/columns/0/label": "Option or term", "/versions/11/tables/0/columns/1/label": "Meaning", "/versions/11/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/11/tables/0/rows/1/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/11/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "45a028f12ec1801b2299cff1849a4e320ff87b8379ab0e4cea511152a341e814"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "12": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "12.22", "major": "12", "channel": "historical", "revision": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "catalog_fingerprint": "9f857f4ee4875f9c7de6bfc9df4b757dec8b3a0bb88eadb519c7bd267bd56149"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, {"url": "https://pg.center/docs/12/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 12 English manual", "sha256": "2d46945dcabedb2ca954fdacaebd3d7c59425f53db971d33d92be3ea1d6d03ea", "language": "en", "original_url": "/docs/12/gssapi-auth.html"}, {"url": "https://pg.center/docs/12/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 12 English manual", "sha256": "07e8cddcb38076c86dab95b72c4380a7a325f22401b5b7f9af5dd4931876f2cb", "language": "en", "original_url": "/docs/12/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span>\u662f\u4e00\u79cd\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2743\" target=\"_top\">RFC 2743</a> \u4e2d\u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002<span class=\"productname\">PostgreSQL</span>\u652f\u6301<span class=\"productname\">GSSAPI</span>\u7528\u4e8e\u8ba4\u8bc1\u3001\u901a\u4fe1\u52a0\u5bc6\uff0c\u6216\u4e24\u8005\u517c\u800c\u6709\u4e4b\u3002<span class=\"productname\">GSSAPI</span>\u4e3a\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\u3002\u5982\u679c\u4f7f\u7528<span class=\"productname\">GSSAPI</span>\u52a0\u5bc6\u6216<acronym class=\"acronym\">SSL</acronym>\u52a0\u5bc6\uff0c\u6cbf\u6570\u636e\u5e93\u8fde\u63a5\u53d1\u9001\u7684\u6570\u636e\u5c06\u88ab\u52a0\u5bc6\uff1b\u5426\u5219\uff0c\u5c06\u4e0d\u4f1a\u88ab\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/12/installation.html\" title=\"\u7b2c\u00a016\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a016\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u5f53 <span class=\"productname\">GSSAPI</span> \u4f7f\u7528 <span class=\"productname\">Kerberos</span> \u65f6\uff0c\u5b83\u4f1a\u4f7f\u7528\u4e00\u4e2a\u6807\u51c6\u7684\u670d\u52a1\u4e3b\u4f53\uff08\u8ba4\u8bc1\u8eab\u4efd\uff09\u540d\u79f0\uff0c\u5176\u683c\u5f0f\u4e3a <code class=\"literal\"><em class=\"replaceable\"><code>servicename</code></em>/<em class=\"replaceable\"><code>hostname</code></em>@<em class=\"replaceable\"><code>realm</code></em></code>\u3002\u67d0\u4e2a\u5b89\u88c5\u5b9e\u9645\u4f7f\u7528\u7684\u4e3b\u4f53\u540d\uff08principal name\uff09\u4e0d\u4f1a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u786c\u7f16\u7801\u5728 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4e2d\uff1b\u76f8\u53cd\uff0c\u5b83\u662f\u5728\u670d\u52a1\u5668\u8bfb\u53d6\u7684 <em class=\"firstterm\">keytab</em> \u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\uff0c\u670d\u52a1\u5668\u636e\u6b64\u786e\u5b9a\u81ea\u5df1\u7684\u8eab\u4efd\u3002\u5982\u679c keytab \u6587\u4ef6\u4e2d\u5217\u51fa\u4e86\u591a\u4e2a\u4e3b\u4f53\uff0c\u670d\u52a1\u5668\u4f1a\u63a5\u53d7\u5176\u4e2d\u4efb\u610f\u4e00\u4e2a\u3002\u670d\u52a1\u5668\u7684 realm \u540d\u79f0\u662f\u670d\u52a1\u5668\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u5fc5\u987b\u77e5\u9053\u5b83\u6253\u7b97\u8fde\u63a5\u7684\u670d\u52a1\u5668\u4e3b\u4f53\u540d\u3002\u8be5\u4e3b\u4f53\u540d\u4e2d\u7684 <em class=\"replaceable\"><code>servicename</code></em> \u90e8\u5206\u901a\u5e38\u662f <code class=\"literal\">postgres</code>\uff0c\u4f46\u4e5f\u53ef\u4ee5\u901a\u8fc7 <span class=\"application\">libpq</span> \u7684\u8fde\u63a5\u53c2\u6570<a class=\"xref\" href=\"/docs/12/libpq.html#LIBPQ-CONNECT-KRBSRVNAME\">krbsrvname</a>\u9009\u62e9\u5176\u4ed6\u503c\u3002<em class=\"replaceable\"><code>hostname</code></em> \u90e8\u5206\u5219\u662f <span class=\"application\">libpq</span> \u88ab\u544a\u77e5\u8981\u8fde\u63a5\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002realm \u540d\u79f0\u662f\u5ba2\u6237\u7aef\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u5ba2\u6237\u7aef\u4e5f\u4f1a\u6709\u4e00\u4e2a\u8868\u793a\u5176\u81ea\u8eab\u8eab\u4efd\u7684\u4e3b\u4f53\u540d\uff08\u5e76\u4e14\u5b83\u5fc5\u987b\u6301\u6709\u8be5\u4e3b\u4f53\u5bf9\u5e94\u7684\u6709\u6548\u7968\u636e\uff09\u3002\u8981\u4f7f\u7528 <span class=\"productname\">GSSAPI</span> \u8fdb\u884c\u8ba4\u8bc1\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u5fc5\u987b\u4e0e\u67d0\u4e2a <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u5173\u8054\u3002\u53ef\u4ee5\u4f7f\u7528 <code class=\"filename\">pg_ident.conf</code> \u914d\u7f6e\u6587\u4ef6\u5c06\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\uff1b\u4f8b\u5982\uff0c\u53ef\u4ee5\u628a <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a\u7b80\u5355\u7684 <code class=\"literal\">pgusername</code>\u3002\u53e6\u4e00\u79cd\u505a\u6cd5\u662f\u4e0d\u505a\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5728 <span class=\"productname\">PostgreSQL</span> \u4e2d\u628a\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u540d\u7528\u4f5c\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u4ec5\u901a\u8fc7\u53bb\u6389\u4e3b\u4f53\u540d\u79f0\u4e2d\u7684 realm\uff0c\u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u670d\u52a1\u5668 keytab \u6587\u4ef6\u7684\u4f4d\u7f6e\u7531\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/12/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u6307\u5b9a\u3002\u51fa\u4e8e\u5b89\u5168\u539f\u56e0\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u5355\u72ec\u4f7f\u7528\u4e00\u4e2a keytab\uff0c\u800c\u4e0d\u8981\u8ba9\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u7cfb\u7edf keytab \u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u670d\u52a1\u5668 keytab \u6587\u4ef6\u5bf9 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u53f7\u53ef\u8bfb\uff08\u5e76\u4e14\u6700\u597d\u53ea\u8bfb\u3001\u4e0d\u53ef\u5199\uff09\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/12/runtime.html#POSTGRES-USER\" title=\"18.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a018.1\u00a0\u8282</a>\uff09\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7528 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u89c1 Kerberos \u6587\u6863\u3002\u4e0b\u9762\u5c55\u793a\u4e86\u7528 MIT \u517c\u5bb9\u7684 Kerberos 5 \u5b9e\u73b0\u7684<span class=\"application\">kadmin</span>\u6765\u505a\u8fd9\u4e2a\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>addprinc -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span> \u8ba4\u8bc1\u65b9\u6cd5\u652f\u6301\u4e0b\u5217\u8ba4\u8bc1\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/12/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/12/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u9664\u4e86\u8fd9\u4e9b\u53ef\u9488\u5bf9\u4e0d\u540c <code class=\"filename\">pg_hba.conf</code> \u9879\u5206\u522b\u8bbe\u7f6e\u7684\u9009\u9879\u4e4b\u5916\uff0c\u8fd8\u6709\u4e00\u4e2a\u670d\u52a1\u5668\u8303\u56f4\u7684\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/12/runtime-config-connection.html#GUC-KRB-CASEINS-USERS\">krb_caseins_users</a>\u3002\u5982\u679c\u5b83\u88ab\u8bbe\u4e3a\u771f\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u4e0e\u7528\u6237\u6620\u5c04\u6761\u76ee\u7684\u5339\u914d\u5c06\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002\u5982\u679c\u8bbe\u7f6e\u4e86 <code class=\"literal\">krb_realm</code>\uff0c\u5176\u5339\u914d\u4e5f\u540c\u6837\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002</p>\n</div>", "manual_path": "/docs/12/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/12/gssapi-auth.html", "method": "same-major semantic node", "sha256": "9753d5d5662838783ac0ed72c756bc0be06db16dd2b9987ccb6b1c6e1e4e58a8", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[13]", "#GSSAPI-AUTH/p[2]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[4]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/versions/12/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.6 for details. It can be used in conjunction with GSSAPI encryption.", "/versions/12/facts/0/label": "Method", "/versions/12/facts/1/label": "Configuration", "/versions/12/facts/2/label": "Inventory", "/versions/12/facts/2/value": "User-visible source authentication method", "/versions/12/tables/0/title": "Documented method options and alternatives", "/versions/12/tables/0/columns/0/label": "Option or term", "/versions/12/tables/0/columns/1/label": "Meaning", "/versions/12/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/12/tables/0/rows/1/description": "Allows mapping from client principals to database user names. See Section 20.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/12/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "adc37c24e6d276559a44e1f21dbc9300452c94154925249a084342823907af33"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "13": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "13.23", "major": "13", "channel": "historical", "revision": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "catalog_fingerprint": "c7015c845255c9d721c547c8ab9ef37825d332588c9691d982e6906b7d571002"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, {"url": "https://pg.center/docs/13/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 13 English manual", "sha256": "4e0099fbc60cc16079a25f6188de6e2123bb58bc2b4e1a0aceb7cedda0872776", "language": "en", "original_url": "/docs/13/gssapi-auth.html"}, {"url": "https://pg.center/docs/13/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 13 English manual", "sha256": "3cc6ce851945cba450e6b26ecf9cae1efd3c03fb7b55e17876f4d9ea418a7c2e", "language": "en", "original_url": "/docs/13/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span>\u662f\u4e00\u79cd\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2743\" target=\"_top\">RFC 2743</a> \u4e2d\u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002<span class=\"productname\">PostgreSQL</span>\u652f\u6301<span class=\"productname\">GSSAPI</span>\u7528\u4e8e\u8ba4\u8bc1\u3001\u901a\u4fe1\u52a0\u5bc6\uff0c\u6216\u4e24\u8005\u517c\u800c\u6709\u4e4b\u3002<span class=\"productname\">GSSAPI</span>\u4e3a\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\u3002\u5982\u679c\u4f7f\u7528<span class=\"productname\">GSSAPI</span>\u52a0\u5bc6\u6216<acronym class=\"acronym\">SSL</acronym>\u52a0\u5bc6\uff0c\u6cbf\u6570\u636e\u5e93\u8fde\u63a5\u53d1\u9001\u7684\u6570\u636e\u5c06\u88ab\u52a0\u5bc6\uff1b\u5426\u5219\uff0c\u5c06\u4e0d\u4f1a\u88ab\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/13/installation.html\" title=\"\u7b2c\u00a016\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a016\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u5f53 <span class=\"productname\">GSSAPI</span> \u4f7f\u7528 <span class=\"productname\">Kerberos</span> \u65f6\uff0c\u5b83\u4f1a\u4f7f\u7528\u4e00\u4e2a\u6807\u51c6\u7684\u670d\u52a1\u4e3b\u4f53\uff08\u8ba4\u8bc1\u8eab\u4efd\uff09\u540d\u79f0\uff0c\u5176\u683c\u5f0f\u4e3a <code class=\"literal\"><em class=\"replaceable\"><code>servicename</code></em>/<em class=\"replaceable\"><code>hostname</code></em>@<em class=\"replaceable\"><code>realm</code></em></code>\u3002\u67d0\u4e2a\u5b89\u88c5\u5b9e\u9645\u4f7f\u7528\u7684\u4e3b\u4f53\u540d\uff08principal name\uff09\u4e0d\u4f1a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u786c\u7f16\u7801\u5728 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4e2d\uff1b\u76f8\u53cd\uff0c\u5b83\u662f\u5728\u670d\u52a1\u5668\u8bfb\u53d6\u7684 <em class=\"firstterm\">keytab</em> \u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\uff0c\u670d\u52a1\u5668\u636e\u6b64\u786e\u5b9a\u81ea\u5df1\u7684\u8eab\u4efd\u3002\u5982\u679c keytab \u6587\u4ef6\u4e2d\u5217\u51fa\u4e86\u591a\u4e2a\u4e3b\u4f53\uff0c\u670d\u52a1\u5668\u4f1a\u63a5\u53d7\u5176\u4e2d\u4efb\u610f\u4e00\u4e2a\u3002\u670d\u52a1\u5668\u7684 realm \u540d\u79f0\u662f\u670d\u52a1\u5668\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u5fc5\u987b\u77e5\u9053\u5b83\u6253\u7b97\u8fde\u63a5\u7684\u670d\u52a1\u5668\u4e3b\u4f53\u540d\u3002\u8be5\u4e3b\u4f53\u540d\u4e2d\u7684 <em class=\"replaceable\"><code>servicename</code></em> \u90e8\u5206\u901a\u5e38\u662f <code class=\"literal\">postgres</code>\uff0c\u4f46\u4e5f\u53ef\u4ee5\u901a\u8fc7 <span class=\"application\">libpq</span> \u7684\u8fde\u63a5\u53c2\u6570<a class=\"xref\" href=\"/docs/13/libpq.html#LIBPQ-CONNECT-KRBSRVNAME\">krbsrvname</a>\u9009\u62e9\u5176\u4ed6\u503c\u3002<em class=\"replaceable\"><code>hostname</code></em> \u90e8\u5206\u5219\u662f <span class=\"application\">libpq</span> \u88ab\u544a\u77e5\u8981\u8fde\u63a5\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002realm \u540d\u79f0\u662f\u5ba2\u6237\u7aef\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u5ba2\u6237\u7aef\u4e5f\u4f1a\u6709\u4e00\u4e2a\u8868\u793a\u5176\u81ea\u8eab\u8eab\u4efd\u7684\u4e3b\u4f53\u540d\uff08\u5e76\u4e14\u5b83\u5fc5\u987b\u6301\u6709\u8be5\u4e3b\u4f53\u5bf9\u5e94\u7684\u6709\u6548\u7968\u636e\uff09\u3002\u8981\u4f7f\u7528 <span class=\"productname\">GSSAPI</span> \u8fdb\u884c\u8ba4\u8bc1\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u5fc5\u987b\u4e0e\u67d0\u4e2a <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u5173\u8054\u3002\u53ef\u4ee5\u4f7f\u7528 <code class=\"filename\">pg_ident.conf</code> \u914d\u7f6e\u6587\u4ef6\u5c06\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\uff1b\u4f8b\u5982\uff0c\u53ef\u4ee5\u628a <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a\u7b80\u5355\u7684 <code class=\"literal\">pgusername</code>\u3002\u53e6\u4e00\u79cd\u505a\u6cd5\u662f\u4e0d\u505a\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5728 <span class=\"productname\">PostgreSQL</span> \u4e2d\u628a\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u540d\u7528\u4f5c\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u4ec5\u901a\u8fc7\u53bb\u6389\u4e3b\u4f53\u540d\u79f0\u4e2d\u7684 realm\uff0c\u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u670d\u52a1\u5668 keytab \u6587\u4ef6\u7684\u4f4d\u7f6e\u7531\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/13/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u6307\u5b9a\u3002\u51fa\u4e8e\u5b89\u5168\u539f\u56e0\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u5355\u72ec\u4f7f\u7528\u4e00\u4e2a keytab\uff0c\u800c\u4e0d\u8981\u8ba9\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u7cfb\u7edf keytab \u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u670d\u52a1\u5668 keytab \u6587\u4ef6\u5bf9 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u53f7\u53ef\u8bfb\uff08\u5e76\u4e14\u6700\u597d\u53ea\u8bfb\u3001\u4e0d\u53ef\u5199\uff09\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/13/runtime.html#POSTGRES-USER\" title=\"18.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a018.1\u00a0\u8282</a>\uff09\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7528 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u89c1 Kerberos \u6587\u6863\u3002\u4e0b\u9762\u5c55\u793a\u4e86\u7528 MIT \u517c\u5bb9\u7684 Kerberos 5 \u5b9e\u73b0\u7684<span class=\"application\">kadmin</span>\u6765\u505a\u8fd9\u4e2a\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>addprinc -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span> \u8ba4\u8bc1\u65b9\u6cd5\u652f\u6301\u4e0b\u5217\u8ba4\u8bc1\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/13/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/13/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u9664\u4e86\u8fd9\u4e9b\u53ef\u9488\u5bf9\u4e0d\u540c <code class=\"filename\">pg_hba.conf</code> \u9879\u5206\u522b\u8bbe\u7f6e\u7684\u9009\u9879\u4e4b\u5916\uff0c\u8fd8\u6709\u4e00\u4e2a\u670d\u52a1\u5668\u8303\u56f4\u7684\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/13/runtime-config-connection.html#GUC-KRB-CASEINS-USERS\">krb_caseins_users</a>\u3002\u5982\u679c\u5b83\u88ab\u8bbe\u4e3a\u771f\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u4e0e\u7528\u6237\u6620\u5c04\u6761\u76ee\u7684\u5339\u914d\u5c06\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002\u5982\u679c\u8bbe\u7f6e\u4e86 <code class=\"literal\">krb_realm</code>\uff0c\u5176\u5339\u914d\u4e5f\u540c\u6837\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002</p>\n</div>", "manual_path": "/docs/13/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/13/gssapi-auth.html", "method": "same-major semantic node", "sha256": "8989d8357c1a8b014d47b04ed9f6b68d15a9e715cb00322726adb2cf28d5d9b4", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[13]", "#GSSAPI-AUTH/p[2]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[4]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/versions/13/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.6 for details. It can be used in conjunction with GSSAPI encryption.", "/versions/13/facts/0/label": "Method", "/versions/13/facts/1/label": "Configuration", "/versions/13/facts/2/label": "Inventory", "/versions/13/facts/2/value": "User-visible source authentication method", "/versions/13/tables/0/title": "Documented method options and alternatives", "/versions/13/tables/0/columns/0/label": "Option or term", "/versions/13/tables/0/columns/1/label": "Meaning", "/versions/13/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/13/tables/0/rows/1/description": "Allows mapping from client principals to database user names. See Section 20.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/13/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "c17992d800a6e893008edf7ad8b8c3634766e0d35e4e5178f9cb3add376c1a75"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "14": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 21.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1 \u7b2c 21.2 \u8282 \u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "14.24", "major": "14", "channel": "stable", "revision": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "catalog_fingerprint": "b272e6a82e4c46efda81c3a6a4cdf7de6a83dfff7f02f226a392fbe9acdd3adb"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, {"url": "https://pg.center/docs/14/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 14 English manual", "sha256": "011fe931c24ac53aeb85f98a816976e6c12c754b115fc458c37af750f5404c7e", "language": "en", "original_url": "/docs/14/gssapi-auth.html"}, {"url": "https://pg.center/docs/14/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 14 English manual", "sha256": "c9a75f04fd4a1069ea261ba061578a75c47a4b7e0bbf88761502fd4c19ccbc3f", "language": "en", "original_url": "/docs/14/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 21.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">21.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span>\u662f\u4e00\u79cd\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2743\" target=\"_top\">RFC 2743</a> \u4e2d\u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002<span class=\"productname\">PostgreSQL</span>\u652f\u6301<span class=\"productname\">GSSAPI</span>\u7528\u4e8e\u8ba4\u8bc1\u3001\u901a\u4fe1\u52a0\u5bc6\uff0c\u6216\u4e24\u8005\u517c\u800c\u6709\u4e4b\u3002<span class=\"productname\">GSSAPI</span>\u4e3a\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\u3002\u5982\u679c\u4f7f\u7528<span class=\"productname\">GSSAPI</span>\u52a0\u5bc6\u6216<acronym class=\"acronym\">SSL</acronym>\u52a0\u5bc6\uff0c\u6cbf\u6570\u636e\u5e93\u8fde\u63a5\u53d1\u9001\u7684\u6570\u636e\u5c06\u88ab\u52a0\u5bc6\uff1b\u5426\u5219\uff0c\u5c06\u4e0d\u4f1a\u88ab\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/14/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u5f53 <span class=\"productname\">GSSAPI</span> \u4f7f\u7528 <span class=\"productname\">Kerberos</span> \u65f6\uff0c\u5b83\u4f1a\u4f7f\u7528\u4e00\u4e2a\u6807\u51c6\u7684\u670d\u52a1\u4e3b\u4f53\uff08\u8ba4\u8bc1\u8eab\u4efd\uff09\u540d\u79f0\uff0c\u5176\u683c\u5f0f\u4e3a <code class=\"literal\"><em class=\"replaceable\"><code>servicename</code></em>/<em class=\"replaceable\"><code>hostname</code></em>@<em class=\"replaceable\"><code>realm</code></em></code>\u3002\u67d0\u4e2a\u5b89\u88c5\u5b9e\u9645\u4f7f\u7528\u7684\u4e3b\u4f53\u540d\uff08principal name\uff09\u4e0d\u4f1a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u786c\u7f16\u7801\u5728 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4e2d\uff1b\u76f8\u53cd\uff0c\u5b83\u662f\u5728\u670d\u52a1\u5668\u8bfb\u53d6\u7684 <em class=\"firstterm\">keytab</em> \u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\uff0c\u670d\u52a1\u5668\u636e\u6b64\u786e\u5b9a\u81ea\u5df1\u7684\u8eab\u4efd\u3002\u5982\u679c keytab \u6587\u4ef6\u4e2d\u5217\u51fa\u4e86\u591a\u4e2a\u4e3b\u4f53\uff0c\u670d\u52a1\u5668\u4f1a\u63a5\u53d7\u5176\u4e2d\u4efb\u610f\u4e00\u4e2a\u3002\u670d\u52a1\u5668\u7684 realm \u540d\u79f0\u662f\u670d\u52a1\u5668\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u5fc5\u987b\u77e5\u9053\u5b83\u6253\u7b97\u8fde\u63a5\u7684\u670d\u52a1\u5668\u4e3b\u4f53\u540d\u3002\u8be5\u4e3b\u4f53\u540d\u4e2d\u7684 <em class=\"replaceable\"><code>servicename</code></em> \u90e8\u5206\u901a\u5e38\u662f <code class=\"literal\">postgres</code>\uff0c\u4f46\u4e5f\u53ef\u4ee5\u901a\u8fc7 <span class=\"application\">libpq</span> \u7684\u8fde\u63a5\u53c2\u6570<a class=\"xref\" href=\"/docs/14/libpq.html#LIBPQ-CONNECT-KRBSRVNAME\">krbsrvname</a>\u9009\u62e9\u5176\u4ed6\u503c\u3002<em class=\"replaceable\"><code>hostname</code></em> \u90e8\u5206\u5219\u662f <span class=\"application\">libpq</span> \u88ab\u544a\u77e5\u8981\u8fde\u63a5\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002realm \u540d\u79f0\u662f\u5ba2\u6237\u7aef\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u5ba2\u6237\u7aef\u4e5f\u4f1a\u6709\u4e00\u4e2a\u8868\u793a\u5176\u81ea\u8eab\u8eab\u4efd\u7684\u4e3b\u4f53\u540d\uff08\u5e76\u4e14\u5b83\u5fc5\u987b\u6301\u6709\u8be5\u4e3b\u4f53\u5bf9\u5e94\u7684\u6709\u6548\u7968\u636e\uff09\u3002\u8981\u4f7f\u7528 <span class=\"productname\">GSSAPI</span> \u8fdb\u884c\u8ba4\u8bc1\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u5fc5\u987b\u4e0e\u67d0\u4e2a <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u5173\u8054\u3002\u53ef\u4ee5\u4f7f\u7528 <code class=\"filename\">pg_ident.conf</code> \u914d\u7f6e\u6587\u4ef6\u5c06\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\uff1b\u4f8b\u5982\uff0c\u53ef\u4ee5\u628a <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a\u7b80\u5355\u7684 <code class=\"literal\">pgusername</code>\u3002\u53e6\u4e00\u79cd\u505a\u6cd5\u662f\u4e0d\u505a\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5728 <span class=\"productname\">PostgreSQL</span> \u4e2d\u628a\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u540d\u7528\u4f5c\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u4ec5\u901a\u8fc7\u53bb\u6389\u4e3b\u4f53\u540d\u79f0\u4e2d\u7684 realm\uff0c\u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u670d\u52a1\u5668 keytab \u6587\u4ef6\u7684\u4f4d\u7f6e\u7531\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/14/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u6307\u5b9a\u3002\u51fa\u4e8e\u5b89\u5168\u539f\u56e0\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u5355\u72ec\u4f7f\u7528\u4e00\u4e2a keytab\uff0c\u800c\u4e0d\u8981\u8ba9\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u7cfb\u7edf keytab \u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u670d\u52a1\u5668 keytab \u6587\u4ef6\u5bf9 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u53f7\u53ef\u8bfb\uff08\u5e76\u4e14\u6700\u597d\u53ea\u8bfb\u3001\u4e0d\u53ef\u5199\uff09\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/14/runtime.html#POSTGRES-USER\" title=\"19.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a019.1\u00a0\u8282</a>\uff09\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7528 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u89c1 Kerberos \u6587\u6863\u3002\u4e0b\u9762\u5c55\u793a\u4e86\u7528 MIT \u517c\u5bb9\u7684 Kerberos 5 \u5b9e\u73b0\u7684<span class=\"application\">kadmin</span>\u6765\u505a\u8fd9\u4e2a\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>addprinc -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span> \u8ba4\u8bc1\u65b9\u6cd5\u652f\u6301\u4e0b\u5217\u8ba4\u8bc1\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/14/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/14/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u9664\u4e86\u8fd9\u4e9b\u53ef\u9488\u5bf9\u4e0d\u540c <code class=\"filename\">pg_hba.conf</code> \u9879\u5206\u522b\u8bbe\u7f6e\u7684\u9009\u9879\u4e4b\u5916\uff0c\u8fd8\u6709\u4e00\u4e2a\u670d\u52a1\u5668\u8303\u56f4\u7684\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/14/runtime-config-connection.html#GUC-KRB-CASEINS-USERS\">krb_caseins_users</a>\u3002\u5982\u679c\u5b83\u88ab\u8bbe\u4e3a\u771f\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u4e0e\u7528\u6237\u6620\u5c04\u6761\u76ee\u7684\u5339\u914d\u5c06\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002\u5982\u679c\u8bbe\u7f6e\u4e86 <code class=\"literal\">krb_realm</code>\uff0c\u5176\u5339\u914d\u4e5f\u540c\u6837\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002</p>\n</div>", "manual_path": "/docs/14/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/14/gssapi-auth.html", "method": "same-major semantic node", "sha256": "251da3b9a24fa3e9cc8ad2ebb3c4637874d5fbb64ed996268032b877cbbf4b4b", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[13]", "#GSSAPI-AUTH/p[2]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[4]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/versions/14/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 21.6 for details. It can be used in conjunction with GSSAPI encryption.", "/versions/14/facts/0/label": "Method", "/versions/14/facts/1/label": "Configuration", "/versions/14/facts/2/label": "Inventory", "/versions/14/facts/2/value": "User-visible source authentication method", "/versions/14/tables/0/title": "Documented method options and alternatives", "/versions/14/tables/0/columns/0/label": "Option or term", "/versions/14/tables/0/columns/1/label": "Meaning", "/versions/14/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 21.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/14/tables/0/rows/1/description": "Allows mapping from client principals to database user names. See Section 21.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/14/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "aa90f260638097919e767985dc176c4a3af6decc74da3cc777a538264605c59e"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "15": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 21.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1 \u7b2c 21.2 \u8282 \u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "15.19", "major": "15", "channel": "stable", "revision": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "catalog_fingerprint": "fefe3c425147a86defada190c9b0663cfe02caa1724f5dede93e46457572252d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, {"url": "https://pg.center/docs/15/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 15 English manual", "sha256": "16f71c4b4c07cc5f56deeb8f302e0bacfeeea542558aa5b77da7be2eb81fdeb9", "language": "en", "original_url": "/docs/15/gssapi-auth.html"}, {"url": "https://pg.center/docs/15/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 15 English manual", "sha256": "0470cd3eeb82cbc32d4b8b79e29f4427bdfd01f5bb15e6d9b7cee2f6dd2bba44", "language": "en", "original_url": "/docs/15/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 21.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">21.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span>\u662f\u4e00\u79cd\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2743\" target=\"_top\">RFC 2743</a> \u4e2d\u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002<span class=\"productname\">PostgreSQL</span>\u652f\u6301<span class=\"productname\">GSSAPI</span>\u7528\u4e8e\u8ba4\u8bc1\u3001\u901a\u4fe1\u52a0\u5bc6\uff0c\u6216\u4e24\u8005\u517c\u800c\u6709\u4e4b\u3002<span class=\"productname\">GSSAPI</span>\u4e3a\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\u3002\u5982\u679c\u4f7f\u7528<span class=\"productname\">GSSAPI</span>\u52a0\u5bc6\u6216<acronym class=\"acronym\">SSL</acronym>\u52a0\u5bc6\uff0c\u6cbf\u6570\u636e\u5e93\u8fde\u63a5\u53d1\u9001\u7684\u6570\u636e\u5c06\u88ab\u52a0\u5bc6\uff1b\u5426\u5219\uff0c\u5c06\u4e0d\u4f1a\u88ab\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/15/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u5f53 <span class=\"productname\">GSSAPI</span> \u4f7f\u7528 <span class=\"productname\">Kerberos</span> \u65f6\uff0c\u5b83\u4f1a\u4f7f\u7528\u4e00\u4e2a\u6807\u51c6\u7684\u670d\u52a1\u4e3b\u4f53\uff08\u8ba4\u8bc1\u8eab\u4efd\uff09\u540d\u79f0\uff0c\u5176\u683c\u5f0f\u4e3a <code class=\"literal\"><em class=\"replaceable\"><code>servicename</code></em>/<em class=\"replaceable\"><code>hostname</code></em>@<em class=\"replaceable\"><code>realm</code></em></code>\u3002\u67d0\u4e2a\u5b89\u88c5\u5b9e\u9645\u4f7f\u7528\u7684\u4e3b\u4f53\u540d\uff08principal name\uff09\u4e0d\u4f1a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u786c\u7f16\u7801\u5728 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4e2d\uff1b\u76f8\u53cd\uff0c\u5b83\u662f\u5728\u670d\u52a1\u5668\u8bfb\u53d6\u7684 <em class=\"firstterm\">keytab</em> \u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\uff0c\u670d\u52a1\u5668\u636e\u6b64\u786e\u5b9a\u81ea\u5df1\u7684\u8eab\u4efd\u3002\u5982\u679c keytab \u6587\u4ef6\u4e2d\u5217\u51fa\u4e86\u591a\u4e2a\u4e3b\u4f53\uff0c\u670d\u52a1\u5668\u4f1a\u63a5\u53d7\u5176\u4e2d\u4efb\u610f\u4e00\u4e2a\u3002\u670d\u52a1\u5668\u7684 realm \u540d\u79f0\u662f\u670d\u52a1\u5668\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u5fc5\u987b\u77e5\u9053\u5b83\u6253\u7b97\u8fde\u63a5\u7684\u670d\u52a1\u5668\u4e3b\u4f53\u540d\u3002\u8be5\u4e3b\u4f53\u540d\u4e2d\u7684 <em class=\"replaceable\"><code>servicename</code></em> \u90e8\u5206\u901a\u5e38\u662f <code class=\"literal\">postgres</code>\uff0c\u4f46\u4e5f\u53ef\u4ee5\u901a\u8fc7 <span class=\"application\">libpq</span> \u7684\u8fde\u63a5\u53c2\u6570<a class=\"xref\" href=\"/docs/15/libpq.html#LIBPQ-CONNECT-KRBSRVNAME\">krbsrvname</a>\u9009\u62e9\u5176\u4ed6\u503c\u3002<em class=\"replaceable\"><code>hostname</code></em> \u90e8\u5206\u5219\u662f <span class=\"application\">libpq</span> \u88ab\u544a\u77e5\u8981\u8fde\u63a5\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002realm \u540d\u79f0\u662f\u5ba2\u6237\u7aef\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u5ba2\u6237\u7aef\u4e5f\u4f1a\u6709\u4e00\u4e2a\u8868\u793a\u5176\u81ea\u8eab\u8eab\u4efd\u7684\u4e3b\u4f53\u540d\uff08\u5e76\u4e14\u5b83\u5fc5\u987b\u6301\u6709\u8be5\u4e3b\u4f53\u5bf9\u5e94\u7684\u6709\u6548\u7968\u636e\uff09\u3002\u8981\u4f7f\u7528 <span class=\"productname\">GSSAPI</span> \u8fdb\u884c\u8ba4\u8bc1\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u5fc5\u987b\u4e0e\u67d0\u4e2a <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u5173\u8054\u3002\u53ef\u4ee5\u4f7f\u7528 <code class=\"filename\">pg_ident.conf</code> \u914d\u7f6e\u6587\u4ef6\u5c06\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\uff1b\u4f8b\u5982\uff0c\u53ef\u4ee5\u628a <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a\u7b80\u5355\u7684 <code class=\"literal\">pgusername</code>\u3002\u53e6\u4e00\u79cd\u505a\u6cd5\u662f\u4e0d\u505a\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5728 <span class=\"productname\">PostgreSQL</span> \u4e2d\u628a\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u540d\u7528\u4f5c\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u4ec5\u901a\u8fc7\u53bb\u6389\u4e3b\u4f53\u540d\u79f0\u4e2d\u7684 realm\uff0c\u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u670d\u52a1\u5668 keytab \u6587\u4ef6\u7684\u4f4d\u7f6e\u7531\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/15/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u6307\u5b9a\u3002\u51fa\u4e8e\u5b89\u5168\u539f\u56e0\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u5355\u72ec\u4f7f\u7528\u4e00\u4e2a keytab\uff0c\u800c\u4e0d\u8981\u8ba9\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u7cfb\u7edf keytab \u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u670d\u52a1\u5668 keytab \u6587\u4ef6\u5bf9 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u53f7\u53ef\u8bfb\uff08\u5e76\u4e14\u6700\u597d\u53ea\u8bfb\u3001\u4e0d\u53ef\u5199\uff09\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/15/runtime.html#POSTGRES-USER\" title=\"19.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a019.1\u00a0\u8282</a>\uff09\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7528 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u89c1 Kerberos \u6587\u6863\u3002\u4e0b\u9762\u5c55\u793a\u4e86\u7528 MIT \u517c\u5bb9\u7684 Kerberos 5 \u5b9e\u73b0\u7684<span class=\"application\">kadmin</span>\u6765\u505a\u8fd9\u4e2a\u7684\u793a\u4f8b\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>addprinc -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span> \u8ba4\u8bc1\u65b9\u6cd5\u652f\u6301\u4e0b\u5217\u8ba4\u8bc1\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/15/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/15/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u9664\u4e86\u8fd9\u4e9b\u53ef\u9488\u5bf9\u4e0d\u540c <code class=\"filename\">pg_hba.conf</code> \u9879\u5206\u522b\u8bbe\u7f6e\u7684\u9009\u9879\u4e4b\u5916\uff0c\u8fd8\u6709\u4e00\u4e2a\u670d\u52a1\u5668\u8303\u56f4\u7684\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/15/runtime-config-connection.html#GUC-KRB-CASEINS-USERS\">krb_caseins_users</a>\u3002\u5982\u679c\u5b83\u88ab\u8bbe\u4e3a\u771f\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u4e0e\u7528\u6237\u6620\u5c04\u6761\u76ee\u7684\u5339\u914d\u5c06\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002\u5982\u679c\u8bbe\u7f6e\u4e86 <code class=\"literal\">krb_realm</code>\uff0c\u5176\u5339\u914d\u4e5f\u540c\u6837\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002</p>\n</div>", "manual_path": "/docs/15/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/15/gssapi-auth.html", "method": "same-major semantic node", "sha256": "f8960d1bbf8ea6e62b31531e0985b103ab592ecdcd90133c466dd370f2ccb132", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[13]", "#GSSAPI-AUTH/p[2]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[4]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/versions/15/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 21.6 for details. It can be used in conjunction with GSSAPI encryption.", "/versions/15/facts/0/label": "Method", "/versions/15/facts/1/label": "Configuration", "/versions/15/facts/2/label": "Inventory", "/versions/15/facts/2/value": "User-visible source authentication method", "/versions/15/tables/0/title": "Documented method options and alternatives", "/versions/15/tables/0/columns/0/label": "Option or term", "/versions/15/tables/0/columns/1/label": "Meaning", "/versions/15/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 21.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/15/tables/0/rows/1/description": "Allows mapping from client principals to database user names. See Section 21.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/15/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "9c5acf0984c82020579956bb98529a7a8d9400b4a3ec878b9a95c7002ab349e8"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "16": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 21.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1 \u7b2c 21.2 \u8282 \u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "16.15", "major": "16", "channel": "stable", "revision": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "catalog_fingerprint": "fa133458dc8f52e15083b4f59b7a582e2e378b608d3ac5c53054df458a374e23"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, {"url": "https://pg.center/docs/16/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 16 English manual", "sha256": "7e04796130a51899cc5c7fa3cc162f962c8db7608b0c67011e42b0ac011aac96", "language": "en", "original_url": "/docs/16/gssapi-auth.html"}, {"url": "https://pg.center/docs/16/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 16 English manual", "sha256": "ccc5146375a184646d5992edbc693e12c0de4431a35141d6b56c8dd6b3c52132", "language": "en", "original_url": "/docs/16/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 21.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">21.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span>\u662f\u4e00\u79cd\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2743\" target=\"_top\">RFC 2743</a> \u4e2d\u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002<span class=\"productname\">PostgreSQL</span>\u652f\u6301<span class=\"productname\">GSSAPI</span>\u7528\u4e8e\u8ba4\u8bc1\u3001\u901a\u4fe1\u52a0\u5bc6\uff0c\u6216\u4e24\u8005\u517c\u800c\u6709\u4e4b\u3002<span class=\"productname\">GSSAPI</span>\u4e3a\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\u3002\u5982\u679c\u4f7f\u7528<span class=\"productname\">GSSAPI</span>\u52a0\u5bc6\u6216<acronym class=\"acronym\">SSL</acronym>\u52a0\u5bc6\uff0c\u6cbf\u6570\u636e\u5e93\u8fde\u63a5\u53d1\u9001\u7684\u6570\u636e\u5c06\u88ab\u52a0\u5bc6\uff1b\u5426\u5219\uff0c\u5c06\u4e0d\u4f1a\u88ab\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/16/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u5f53 <span class=\"productname\">GSSAPI</span> \u4f7f\u7528 <span class=\"productname\">Kerberos</span> \u65f6\uff0c\u5b83\u4f1a\u4f7f\u7528\u4e00\u4e2a\u6807\u51c6\u7684\u670d\u52a1\u4e3b\u4f53\uff08\u8ba4\u8bc1\u8eab\u4efd\uff09\u540d\u79f0\uff0c\u5176\u683c\u5f0f\u4e3a <code class=\"literal\"><em class=\"replaceable\"><code>servicename</code></em>/<em class=\"replaceable\"><code>hostname</code></em>@<em class=\"replaceable\"><code>realm</code></em></code>\u3002\u67d0\u4e2a\u5b89\u88c5\u5b9e\u9645\u4f7f\u7528\u7684\u4e3b\u4f53\u540d\uff08principal name\uff09\u4e0d\u4f1a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u786c\u7f16\u7801\u5728 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4e2d\uff1b\u76f8\u53cd\uff0c\u5b83\u662f\u5728\u670d\u52a1\u5668\u8bfb\u53d6\u7684 <em class=\"firstterm\">keytab</em> \u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\uff0c\u670d\u52a1\u5668\u636e\u6b64\u786e\u5b9a\u81ea\u5df1\u7684\u8eab\u4efd\u3002\u5982\u679c keytab \u6587\u4ef6\u4e2d\u5217\u51fa\u4e86\u591a\u4e2a\u4e3b\u4f53\uff0c\u670d\u52a1\u5668\u4f1a\u63a5\u53d7\u5176\u4e2d\u4efb\u610f\u4e00\u4e2a\u3002\u670d\u52a1\u5668\u7684 realm \u540d\u79f0\u662f\u670d\u52a1\u5668\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u5fc5\u987b\u77e5\u9053\u5b83\u6253\u7b97\u8fde\u63a5\u7684\u670d\u52a1\u5668\u4e3b\u4f53\u540d\u3002\u8be5\u4e3b\u4f53\u540d\u4e2d\u7684 <em class=\"replaceable\"><code>servicename</code></em> \u90e8\u5206\u901a\u5e38\u662f <code class=\"literal\">postgres</code>\uff0c\u4f46\u4e5f\u53ef\u4ee5\u901a\u8fc7 <span class=\"application\">libpq</span> \u7684\u8fde\u63a5\u53c2\u6570<a class=\"xref\" href=\"/docs/16/libpq-connect.html#LIBPQ-CONNECT-KRBSRVNAME\">krbsrvname</a>\u9009\u62e9\u5176\u4ed6\u503c\u3002<em class=\"replaceable\"><code>hostname</code></em> \u90e8\u5206\u5219\u662f <span class=\"application\">libpq</span> \u88ab\u544a\u77e5\u8981\u8fde\u63a5\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002realm \u540d\u79f0\u662f\u5ba2\u6237\u7aef\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u5ba2\u6237\u7aef\u4e5f\u4f1a\u6709\u4e00\u4e2a\u8868\u793a\u5176\u81ea\u8eab\u8eab\u4efd\u7684\u4e3b\u4f53\u540d\uff08\u5e76\u4e14\u5b83\u5fc5\u987b\u6301\u6709\u8be5\u4e3b\u4f53\u5bf9\u5e94\u7684\u6709\u6548\u7968\u636e\uff09\u3002\u8981\u4f7f\u7528 <span class=\"productname\">GSSAPI</span> \u8fdb\u884c\u8ba4\u8bc1\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u5fc5\u987b\u4e0e\u67d0\u4e2a <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u5173\u8054\u3002\u53ef\u4ee5\u4f7f\u7528 <code class=\"filename\">pg_ident.conf</code> \u914d\u7f6e\u6587\u4ef6\u5c06\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\uff1b\u4f8b\u5982\uff0c\u53ef\u4ee5\u628a <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a\u7b80\u5355\u7684 <code class=\"literal\">pgusername</code>\u3002\u53e6\u4e00\u79cd\u505a\u6cd5\u662f\u4e0d\u505a\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5728 <span class=\"productname\">PostgreSQL</span> \u4e2d\u628a\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u540d\u7528\u4f5c\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u4ec5\u901a\u8fc7\u53bb\u6389\u4e3b\u4f53\u540d\u79f0\u4e2d\u7684 realm\uff0c\u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u670d\u52a1\u5668 keytab \u6587\u4ef6\u7684\u4f4d\u7f6e\u7531\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/16/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u6307\u5b9a\u3002\u51fa\u4e8e\u5b89\u5168\u539f\u56e0\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u5355\u72ec\u4f7f\u7528\u4e00\u4e2a keytab\uff0c\u800c\u4e0d\u8981\u8ba9\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u7cfb\u7edf keytab \u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u670d\u52a1\u5668 keytab \u6587\u4ef6\u5bf9 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u53f7\u53ef\u8bfb\uff08\u5e76\u4e14\u6700\u597d\u53ea\u8bfb\u3001\u4e0d\u53ef\u5199\uff09\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/16/postgres-user.html\" title=\"19.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a019.1\u00a0\u8282</a>\uff09\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7528 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u89c1 Kerberos \u6587\u6863\u3002\u4e0b\u9762\u7684\u793a\u4f8b\u5c55\u793a\u4e86\u5982\u4f55\u4f7f\u7528 MIT Kerberos \u7684 <span class=\"application\">kadmin</span> \u5de5\u5177\u751f\u6210\u8be5\u6587\u4ef6\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>addprinc -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span> \u8ba4\u8bc1\u65b9\u6cd5\u652f\u6301\u4e0b\u5217\u8ba4\u8bc1\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/16/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/16/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u9664\u4e86\u8fd9\u4e9b\u53ef\u9488\u5bf9\u4e0d\u540c <code class=\"filename\">pg_hba.conf</code> \u9879\u5206\u522b\u8bbe\u7f6e\u7684\u9009\u9879\u4e4b\u5916\uff0c\u8fd8\u6709\u4e00\u4e2a\u670d\u52a1\u5668\u8303\u56f4\u7684\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/16/runtime-config-connection.html#GUC-KRB-CASEINS-USERS\">krb_caseins_users</a>\u3002\u5982\u679c\u5b83\u88ab\u8bbe\u4e3a\u771f\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u4e0e\u7528\u6237\u6620\u5c04\u6761\u76ee\u7684\u5339\u914d\u5c06\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002\u5982\u679c\u8bbe\u7f6e\u4e86 <code class=\"literal\">krb_realm</code>\uff0c\u5176\u5339\u914d\u4e5f\u540c\u6837\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002</p>\n</div>", "manual_path": "/docs/16/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/16/gssapi-auth.html", "method": "same-major semantic node", "sha256": "6050075d695d8ede26d3a984f5c4a42473e156e8d7e6e59f255b2d453aa3985c", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[13]", "#GSSAPI-AUTH/p[2]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[4]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/versions/16/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 21.6 for details. It can be used in conjunction with GSSAPI encryption.", "/versions/16/facts/0/label": "Method", "/versions/16/facts/1/label": "Configuration", "/versions/16/facts/2/label": "Inventory", "/versions/16/facts/2/value": "User-visible source authentication method", "/versions/16/tables/0/title": "Documented method options and alternatives", "/versions/16/tables/0/columns/0/label": "Option or term", "/versions/16/tables/0/columns/1/label": "Meaning", "/versions/16/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 21.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/16/tables/0/rows/1/description": "Allows mapping from client principals to database user names. See Section 21.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/16/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "006b0bb060309cc550de961c8eaf5d5415ea06515241d0aca0bfa29b6d24ea65"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "17": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "revision": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "catalog_fingerprint": "4bbe3ac77becd618478f66aec420a533e9017be356c5c1d51a4b17f0fd497c07"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "https://pg.center/docs/17/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 17 English manual", "sha256": "8ff2953089d8bb969deb356244f5fa7540fd521d0c0f004eef2019184d5e6478", "language": "en", "original_url": "/docs/17/gssapi-auth.html"}, {"url": "https://pg.center/docs/17/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 17 English manual", "sha256": "00c7a7c25d46aa1b2f24cd744cd4990ca4218cfafed2a4cab8c1dc1092090bba", "language": "en", "original_url": "/docs/17/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span>\u662f\u4e00\u79cd\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2743\" target=\"_top\">RFC 2743</a> \u4e2d\u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002<span class=\"productname\">PostgreSQL</span>\u652f\u6301<span class=\"productname\">GSSAPI</span>\u7528\u4e8e\u8ba4\u8bc1\u3001\u901a\u4fe1\u52a0\u5bc6\uff0c\u6216\u4e24\u8005\u517c\u800c\u6709\u4e4b\u3002<span class=\"productname\">GSSAPI</span>\u4e3a\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\u3002\u5982\u679c\u4f7f\u7528<span class=\"productname\">GSSAPI</span>\u52a0\u5bc6\u6216<acronym class=\"acronym\">SSL</acronym>\u52a0\u5bc6\uff0c\u6cbf\u6570\u636e\u5e93\u8fde\u63a5\u53d1\u9001\u7684\u6570\u636e\u5c06\u88ab\u52a0\u5bc6\uff1b\u5426\u5219\uff0c\u5c06\u4e0d\u4f1a\u88ab\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/17/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u5f53 <span class=\"productname\">GSSAPI</span> \u4f7f\u7528 <span class=\"productname\">Kerberos</span> \u65f6\uff0c\u5b83\u4f1a\u4f7f\u7528\u4e00\u4e2a\u6807\u51c6\u7684\u670d\u52a1\u4e3b\u4f53\uff08\u8ba4\u8bc1\u8eab\u4efd\uff09\u540d\u79f0\uff0c\u5176\u683c\u5f0f\u4e3a <code class=\"literal\"><em class=\"replaceable\"><code>servicename</code></em>/<em class=\"replaceable\"><code>hostname</code></em>@<em class=\"replaceable\"><code>realm</code></em></code>\u3002\u67d0\u4e2a\u5b89\u88c5\u5b9e\u9645\u4f7f\u7528\u7684\u4e3b\u4f53\u540d\uff08principal name\uff09\u4e0d\u4f1a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u786c\u7f16\u7801\u5728 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4e2d\uff1b\u76f8\u53cd\uff0c\u5b83\u662f\u5728\u670d\u52a1\u5668\u8bfb\u53d6\u7684 <em class=\"firstterm\">keytab</em> \u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\uff0c\u670d\u52a1\u5668\u636e\u6b64\u786e\u5b9a\u81ea\u5df1\u7684\u8eab\u4efd\u3002\u5982\u679c keytab \u6587\u4ef6\u4e2d\u5217\u51fa\u4e86\u591a\u4e2a\u4e3b\u4f53\uff0c\u670d\u52a1\u5668\u4f1a\u63a5\u53d7\u5176\u4e2d\u4efb\u610f\u4e00\u4e2a\u3002\u670d\u52a1\u5668\u7684 realm \u540d\u79f0\u662f\u670d\u52a1\u5668\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u5fc5\u987b\u77e5\u9053\u5b83\u6253\u7b97\u8fde\u63a5\u7684\u670d\u52a1\u5668\u4e3b\u4f53\u540d\u3002\u8be5\u4e3b\u4f53\u540d\u4e2d\u7684 <em class=\"replaceable\"><code>servicename</code></em> \u90e8\u5206\u901a\u5e38\u662f <code class=\"literal\">postgres</code>\uff0c\u4f46\u4e5f\u53ef\u4ee5\u901a\u8fc7 <span class=\"application\">libpq</span> \u7684\u8fde\u63a5\u53c2\u6570<a class=\"xref\" href=\"/docs/17/libpq-connect.html#LIBPQ-CONNECT-KRBSRVNAME\">krbsrvname</a>\u9009\u62e9\u5176\u4ed6\u503c\u3002<em class=\"replaceable\"><code>hostname</code></em> \u90e8\u5206\u5219\u662f <span class=\"application\">libpq</span> \u88ab\u544a\u77e5\u8981\u8fde\u63a5\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002realm \u540d\u79f0\u662f\u5ba2\u6237\u7aef\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u5ba2\u6237\u7aef\u4e5f\u4f1a\u6709\u4e00\u4e2a\u8868\u793a\u5176\u81ea\u8eab\u8eab\u4efd\u7684\u4e3b\u4f53\u540d\uff08\u5e76\u4e14\u5b83\u5fc5\u987b\u6301\u6709\u8be5\u4e3b\u4f53\u5bf9\u5e94\u7684\u6709\u6548\u7968\u636e\uff09\u3002\u8981\u4f7f\u7528 <span class=\"productname\">GSSAPI</span> \u8fdb\u884c\u8ba4\u8bc1\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u5fc5\u987b\u4e0e\u67d0\u4e2a <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u5173\u8054\u3002\u53ef\u4ee5\u4f7f\u7528 <code class=\"filename\">pg_ident.conf</code> \u914d\u7f6e\u6587\u4ef6\u5c06\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\uff1b\u4f8b\u5982\uff0c\u53ef\u4ee5\u628a <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a\u7b80\u5355\u7684 <code class=\"literal\">pgusername</code>\u3002\u53e6\u4e00\u79cd\u505a\u6cd5\u662f\u4e0d\u505a\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5728 <span class=\"productname\">PostgreSQL</span> \u4e2d\u628a\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u540d\u7528\u4f5c\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u4ec5\u901a\u8fc7\u53bb\u6389\u4e3b\u4f53\u540d\u79f0\u4e2d\u7684 realm\uff0c\u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u670d\u52a1\u5668 keytab \u6587\u4ef6\u7684\u4f4d\u7f6e\u7531\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/17/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u6307\u5b9a\u3002\u51fa\u4e8e\u5b89\u5168\u539f\u56e0\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u5355\u72ec\u4f7f\u7528\u4e00\u4e2a keytab\uff0c\u800c\u4e0d\u8981\u8ba9\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u7cfb\u7edf keytab \u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u670d\u52a1\u5668 keytab \u6587\u4ef6\u5bf9 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u53f7\u53ef\u8bfb\uff08\u5e76\u4e14\u6700\u597d\u53ea\u8bfb\u3001\u4e0d\u53ef\u5199\uff09\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/17/postgres-user.html\" title=\"18.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a018.1\u00a0\u8282</a>\uff09\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7528 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u89c1 Kerberos \u6587\u6863\u3002\u4e0b\u9762\u7684\u793a\u4f8b\u5c55\u793a\u4e86\u5982\u4f55\u4f7f\u7528 MIT Kerberos \u7684 <span class=\"application\">kadmin</span> \u5de5\u5177\u751f\u6210\u8be5\u6587\u4ef6\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>addprinc -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span> \u8ba4\u8bc1\u65b9\u6cd5\u652f\u6301\u4e0b\u5217\u8ba4\u8bc1\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/17/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/17/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u9664\u4e86\u8fd9\u4e9b\u53ef\u9488\u5bf9\u4e0d\u540c <code class=\"filename\">pg_hba.conf</code> \u9879\u5206\u522b\u8bbe\u7f6e\u7684\u9009\u9879\u4e4b\u5916\uff0c\u8fd8\u6709\u4e00\u4e2a\u670d\u52a1\u5668\u8303\u56f4\u7684\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/17/runtime-config-connection.html#GUC-KRB-CASEINS-USERS\">krb_caseins_users</a>\u3002\u5982\u679c\u5b83\u88ab\u8bbe\u4e3a\u771f\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u4e0e\u7528\u6237\u6620\u5c04\u6761\u76ee\u7684\u5339\u914d\u5c06\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002\u5982\u679c\u8bbe\u7f6e\u4e86 <code class=\"literal\">krb_realm</code>\uff0c\u5176\u5339\u914d\u4e5f\u540c\u6837\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002</p>\n</div>", "manual_path": "/docs/17/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/17/gssapi-auth.html", "method": "same-major semantic node", "sha256": "d8d78e357e46dfe93bcfd719fba4335d51bcad2b46da1fdc6084732f747a4b9f", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[13]", "#GSSAPI-AUTH/p[2]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[4]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/versions/17/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.6 for details. It can be used in conjunction with GSSAPI encryption.", "/versions/17/facts/0/label": "Method", "/versions/17/facts/1/label": "Configuration", "/versions/17/facts/2/label": "Inventory", "/versions/17/facts/2/value": "User-visible source authentication method", "/versions/17/tables/0/title": "Documented method options and alternatives", "/versions/17/tables/0/columns/0/label": "Option or term", "/versions/17/tables/0/columns/1/label": "Meaning", "/versions/17/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/17/tables/0/rows/1/description": "Allows mapping from client principals to database user names. See Section 20.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/17/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "e9d4d2791ee6f6c48f679cdf5b2b7d1de796929804d1b5ec5990173f9805829f"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "18": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 18 English manual", "sha256": "00da5d918d0d4f101749a389bcef7ae273436d43ddf22dcb5d38d2ec1d7c8735", "language": "en", "original_url": "/docs/18/gssapi-auth.html"}, {"url": "https://pg.center/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9", "language": "en", "original_url": "/docs/18/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span>\u662f\u4e00\u79cd\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2743\" target=\"_top\">RFC 2743</a> \u4e2d\u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002<span class=\"productname\">PostgreSQL</span>\u652f\u6301<span class=\"productname\">GSSAPI</span>\u7528\u4e8e\u8ba4\u8bc1\u3001\u901a\u4fe1\u52a0\u5bc6\uff0c\u6216\u4e24\u8005\u517c\u800c\u6709\u4e4b\u3002<span class=\"productname\">GSSAPI</span>\u4e3a\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\u3002\u5982\u679c\u4f7f\u7528<span class=\"productname\">GSSAPI</span>\u52a0\u5bc6\u6216<acronym class=\"acronym\">SSL</acronym>\u52a0\u5bc6\uff0c\u6cbf\u6570\u636e\u5e93\u8fde\u63a5\u53d1\u9001\u7684\u6570\u636e\u5c06\u88ab\u52a0\u5bc6\uff1b\u5426\u5219\uff0c\u5c06\u4e0d\u4f1a\u88ab\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u5f53 <span class=\"productname\">GSSAPI</span> \u4f7f\u7528 <span class=\"productname\">Kerberos</span> \u65f6\uff0c\u5b83\u4f1a\u4f7f\u7528\u4e00\u4e2a\u6807\u51c6\u7684\u670d\u52a1\u4e3b\u4f53\uff08\u8ba4\u8bc1\u8eab\u4efd\uff09\u540d\u79f0\uff0c\u5176\u683c\u5f0f\u4e3a <code class=\"literal\"><em class=\"replaceable\"><code>servicename</code></em>/<em class=\"replaceable\"><code>hostname</code></em>@<em class=\"replaceable\"><code>realm</code></em></code>\u3002\u67d0\u4e2a\u5b89\u88c5\u5b9e\u9645\u4f7f\u7528\u7684\u4e3b\u4f53\u540d\uff08principal name\uff09\u4e0d\u4f1a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u786c\u7f16\u7801\u5728 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4e2d\uff1b\u76f8\u53cd\uff0c\u5b83\u662f\u5728\u670d\u52a1\u5668\u8bfb\u53d6\u7684 <em class=\"firstterm\">keytab</em> \u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\uff0c\u670d\u52a1\u5668\u636e\u6b64\u786e\u5b9a\u81ea\u5df1\u7684\u8eab\u4efd\u3002\u5982\u679c keytab \u6587\u4ef6\u4e2d\u5217\u51fa\u4e86\u591a\u4e2a\u4e3b\u4f53\uff0c\u670d\u52a1\u5668\u4f1a\u63a5\u53d7\u5176\u4e2d\u4efb\u610f\u4e00\u4e2a\u3002\u670d\u52a1\u5668\u7684 realm \u540d\u79f0\u662f\u670d\u52a1\u5668\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u5fc5\u987b\u77e5\u9053\u5b83\u6253\u7b97\u8fde\u63a5\u7684\u670d\u52a1\u5668\u4e3b\u4f53\u540d\u3002\u8be5\u4e3b\u4f53\u540d\u4e2d\u7684 <em class=\"replaceable\"><code>servicename</code></em> \u90e8\u5206\u901a\u5e38\u662f <code class=\"literal\">postgres</code>\uff0c\u4f46\u4e5f\u53ef\u4ee5\u901a\u8fc7 <span class=\"application\">libpq</span> \u7684\u8fde\u63a5\u53c2\u6570<a class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-KRBSRVNAME\">krbsrvname</a>\u9009\u62e9\u5176\u4ed6\u503c\u3002<em class=\"replaceable\"><code>hostname</code></em> \u90e8\u5206\u5219\u662f <span class=\"application\">libpq</span> \u88ab\u544a\u77e5\u8981\u8fde\u63a5\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002realm \u540d\u79f0\u662f\u5ba2\u6237\u7aef\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u5ba2\u6237\u7aef\u4e5f\u4f1a\u6709\u4e00\u4e2a\u8868\u793a\u5176\u81ea\u8eab\u8eab\u4efd\u7684\u4e3b\u4f53\u540d\uff08\u5e76\u4e14\u5b83\u5fc5\u987b\u6301\u6709\u8be5\u4e3b\u4f53\u5bf9\u5e94\u7684\u6709\u6548\u7968\u636e\uff09\u3002\u8981\u4f7f\u7528 <span class=\"productname\">GSSAPI</span> \u8fdb\u884c\u8ba4\u8bc1\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u5fc5\u987b\u4e0e\u67d0\u4e2a <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u5173\u8054\u3002\u53ef\u4ee5\u4f7f\u7528 <code class=\"filename\">pg_ident.conf</code> \u914d\u7f6e\u6587\u4ef6\u5c06\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\uff1b\u4f8b\u5982\uff0c\u53ef\u4ee5\u628a <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a\u7b80\u5355\u7684 <code class=\"literal\">pgusername</code>\u3002\u53e6\u4e00\u79cd\u505a\u6cd5\u662f\u4e0d\u505a\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5728 <span class=\"productname\">PostgreSQL</span> \u4e2d\u628a\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u540d\u7528\u4f5c\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u4ec5\u901a\u8fc7\u53bb\u6389\u4e3b\u4f53\u540d\u79f0\u4e2d\u7684 realm\uff0c\u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u670d\u52a1\u5668 keytab \u6587\u4ef6\u7684\u4f4d\u7f6e\u7531\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/18/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u6307\u5b9a\u3002\u51fa\u4e8e\u5b89\u5168\u539f\u56e0\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u5355\u72ec\u4f7f\u7528\u4e00\u4e2a keytab\uff0c\u800c\u4e0d\u8981\u8ba9\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u7cfb\u7edf keytab \u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u670d\u52a1\u5668 keytab \u6587\u4ef6\u5bf9 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u53f7\u53ef\u8bfb\uff08\u5e76\u4e14\u6700\u597d\u53ea\u8bfb\u3001\u4e0d\u53ef\u5199\uff09\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/18/postgres-user.html\" title=\"18.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a018.1\u00a0\u8282</a>\uff09\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7528 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u89c1 Kerberos \u6587\u6863\u3002\u4e0b\u9762\u7684\u793a\u4f8b\u5c55\u793a\u4e86\u5982\u4f55\u4f7f\u7528 MIT Kerberos \u7684 <span class=\"application\">kadmin</span> \u5de5\u5177\u751f\u6210\u8be5\u6587\u4ef6\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>addprinc -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span> \u8ba4\u8bc1\u65b9\u6cd5\u652f\u6301\u4e0b\u5217\u8ba4\u8bc1\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u9664\u4e86\u8fd9\u4e9b\u53ef\u9488\u5bf9\u4e0d\u540c <code class=\"filename\">pg_hba.conf</code> \u9879\u5206\u522b\u8bbe\u7f6e\u7684\u9009\u9879\u4e4b\u5916\uff0c\u8fd8\u6709\u4e00\u4e2a\u670d\u52a1\u5668\u8303\u56f4\u7684\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/18/runtime-config-connection.html#GUC-KRB-CASEINS-USERS\">krb_caseins_users</a>\u3002\u5982\u679c\u5b83\u88ab\u8bbe\u4e3a\u771f\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u4e0e\u7528\u6237\u6620\u5c04\u6761\u76ee\u7684\u5339\u914d\u5c06\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002\u5982\u679c\u8bbe\u7f6e\u4e86 <code class=\"literal\">krb_realm</code>\uff0c\u5176\u5339\u914d\u4e5f\u540c\u6837\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002</p>\n</div>", "manual_path": "/docs/18/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/18/gssapi-auth.html", "method": "same-major semantic node", "sha256": "9d738f27e484913c783da4fab3912a12c933c2d71acac2667824242d9c6763f9", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[13]", "#GSSAPI-AUTH/p[2]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[4]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.6 for details. It can be used in conjunction with GSSAPI encryption.", "/versions/18/facts/0/label": "Method", "/versions/18/facts/1/label": "Configuration", "/versions/18/facts/2/label": "Inventory", "/versions/18/facts/2/value": "User-visible source authentication method", "/versions/18/tables/0/title": "Documented method options and alternatives", "/versions/18/tables/0/columns/0/label": "Option or term", "/versions/18/tables/0/columns/1/label": "Meaning", "/versions/18/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/18/tables/0/rows/1/description": "Allows mapping from client principals to database user names. See Section 20.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/18/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "f2983abaf29f5ca64050dbb361234b4bd69608ca59f4e4eddf1bdc3939c3efe1"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "19": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "revision": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "catalog_fingerprint": "62fbf1a3689dbe8bf7e6b3372cfe6fbf867581427b3858a94c8419b77a4d2d1d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "https://pg.center/docs/19/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 19 English manual", "sha256": "8b7d1169b27c1afaf1dffc8a1b3b43981e0463279df845e8f1a559ba776f00ce", "language": "en", "original_url": "/docs/19/gssapi-auth.html"}, {"url": "https://pg.center/docs/19/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 19 English manual", "sha256": "d05e9155d5388148c2c680ff208b62c6b3b0b1c30f302ada5ab4befec36c19b7", "language": "en", "original_url": "/docs/19/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span>\u662f\u4e00\u79cd\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2743\" target=\"_top\">RFC 2743</a> \u4e2d\u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002<span class=\"productname\">PostgreSQL</span>\u652f\u6301<span class=\"productname\">GSSAPI</span>\u7528\u4e8e\u8ba4\u8bc1\u3001\u901a\u4fe1\u52a0\u5bc6\uff0c\u6216\u4e24\u8005\u517c\u800c\u6709\u4e4b\u3002<span class=\"productname\">GSSAPI</span>\u4e3a\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\u3002\u5982\u679c\u4f7f\u7528<span class=\"productname\">GSSAPI</span>\u52a0\u5bc6\u6216<acronym class=\"acronym\">SSL</acronym>\u52a0\u5bc6\uff0c\u6cbf\u6570\u636e\u5e93\u8fde\u63a5\u53d1\u9001\u7684\u6570\u636e\u5c06\u88ab\u52a0\u5bc6\uff1b\u5426\u5219\uff0c\u5c06\u4e0d\u4f1a\u88ab\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/19/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u5f53 <span class=\"productname\">GSSAPI</span> \u4f7f\u7528 <span class=\"productname\">Kerberos</span> \u65f6\uff0c\u5b83\u4f1a\u4f7f\u7528\u4e00\u4e2a\u6807\u51c6\u7684\u670d\u52a1\u4e3b\u4f53\uff08\u8ba4\u8bc1\u8eab\u4efd\uff09\u540d\u79f0\uff0c\u5176\u683c\u5f0f\u4e3a <code class=\"literal\"><em class=\"replaceable\"><code>servicename</code></em>/<em class=\"replaceable\"><code>hostname</code></em>@<em class=\"replaceable\"><code>realm</code></em></code>\u3002\u67d0\u4e2a\u5b89\u88c5\u5b9e\u9645\u4f7f\u7528\u7684\u4e3b\u4f53\u540d\uff08principal name\uff09\u4e0d\u4f1a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u786c\u7f16\u7801\u5728 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4e2d\uff1b\u76f8\u53cd\uff0c\u5b83\u662f\u5728\u670d\u52a1\u5668\u8bfb\u53d6\u7684 <em class=\"firstterm\">keytab</em> \u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\uff0c\u670d\u52a1\u5668\u636e\u6b64\u786e\u5b9a\u81ea\u5df1\u7684\u8eab\u4efd\u3002\u5982\u679c keytab \u6587\u4ef6\u4e2d\u5217\u51fa\u4e86\u591a\u4e2a\u4e3b\u4f53\uff0c\u670d\u52a1\u5668\u4f1a\u63a5\u53d7\u5176\u4e2d\u4efb\u610f\u4e00\u4e2a\u3002\u670d\u52a1\u5668\u7684 realm \u540d\u79f0\u662f\u670d\u52a1\u5668\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u5fc5\u987b\u77e5\u9053\u5b83\u6253\u7b97\u8fde\u63a5\u7684\u670d\u52a1\u5668\u4e3b\u4f53\u540d\u3002\u8be5\u4e3b\u4f53\u540d\u4e2d\u7684 <em class=\"replaceable\"><code>servicename</code></em> \u90e8\u5206\u901a\u5e38\u662f <code class=\"literal\">postgres</code>\uff0c\u4f46\u4e5f\u53ef\u4ee5\u901a\u8fc7 <span class=\"application\">libpq</span> \u7684\u8fde\u63a5\u53c2\u6570<a class=\"xref\" href=\"/docs/19/libpq-connect.html#LIBPQ-CONNECT-KRBSRVNAME\">krbsrvname</a>\u9009\u62e9\u5176\u4ed6\u503c\u3002<em class=\"replaceable\"><code>hostname</code></em> \u90e8\u5206\u5219\u662f <span class=\"application\">libpq</span> \u88ab\u544a\u77e5\u8981\u8fde\u63a5\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002realm \u540d\u79f0\u662f\u5ba2\u6237\u7aef\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u5ba2\u6237\u7aef\u4e5f\u4f1a\u6709\u4e00\u4e2a\u8868\u793a\u5176\u81ea\u8eab\u8eab\u4efd\u7684\u4e3b\u4f53\u540d\uff08\u5e76\u4e14\u5b83\u5fc5\u987b\u6301\u6709\u8be5\u4e3b\u4f53\u5bf9\u5e94\u7684\u6709\u6548\u7968\u636e\uff09\u3002\u8981\u4f7f\u7528 <span class=\"productname\">GSSAPI</span> \u8fdb\u884c\u8ba4\u8bc1\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u5fc5\u987b\u4e0e\u67d0\u4e2a <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u5173\u8054\u3002\u53ef\u4ee5\u4f7f\u7528 <code class=\"filename\">pg_ident.conf</code> \u914d\u7f6e\u6587\u4ef6\u5c06\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\uff1b\u4f8b\u5982\uff0c\u53ef\u4ee5\u628a <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a\u7b80\u5355\u7684 <code class=\"literal\">pgusername</code>\u3002\u53e6\u4e00\u79cd\u505a\u6cd5\u662f\u4e0d\u505a\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5728 <span class=\"productname\">PostgreSQL</span> \u4e2d\u628a\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u540d\u7528\u4f5c\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u4ec5\u901a\u8fc7\u53bb\u6389\u4e3b\u4f53\u540d\u79f0\u4e2d\u7684 realm\uff0c\u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u670d\u52a1\u5668 keytab \u6587\u4ef6\u7684\u4f4d\u7f6e\u7531\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/19/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u6307\u5b9a\u3002\u51fa\u4e8e\u5b89\u5168\u539f\u56e0\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u5355\u72ec\u4f7f\u7528\u4e00\u4e2a keytab\uff0c\u800c\u4e0d\u8981\u8ba9\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u7cfb\u7edf keytab \u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u670d\u52a1\u5668 keytab \u6587\u4ef6\u5bf9 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u53f7\u53ef\u8bfb\uff08\u5e76\u4e14\u6700\u597d\u53ea\u8bfb\u3001\u4e0d\u53ef\u5199\uff09\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/19/postgres-user.html\" title=\"18.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a018.1\u00a0\u8282</a>\uff09\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7528 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u89c1 Kerberos \u6587\u6863\u3002\u4e0b\u9762\u7684\u793a\u4f8b\u5c55\u793a\u4e86\u5982\u4f55\u4f7f\u7528 MIT Kerberos \u7684 <span class=\"application\">kadmin</span> \u5de5\u5177\u751f\u6210\u8be5\u6587\u4ef6\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>addprinc -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span> \u8ba4\u8bc1\u65b9\u6cd5\u652f\u6301\u4e0b\u5217\u8ba4\u8bc1\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/19/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/19/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u9664\u4e86\u8fd9\u4e9b\u53ef\u9488\u5bf9\u4e0d\u540c <code class=\"filename\">pg_hba.conf</code> \u9879\u5206\u522b\u8bbe\u7f6e\u7684\u9009\u9879\u4e4b\u5916\uff0c\u8fd8\u6709\u4e00\u4e2a\u670d\u52a1\u5668\u8303\u56f4\u7684\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/19/runtime-config-connection.html#GUC-KRB-CASEINS-USERS\">krb_caseins_users</a>\u3002\u5982\u679c\u5b83\u88ab\u8bbe\u4e3a\u771f\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u4e0e\u7528\u6237\u6620\u5c04\u6761\u76ee\u7684\u5339\u914d\u5c06\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002\u5982\u679c\u8bbe\u7f6e\u4e86 <code class=\"literal\">krb_realm</code>\uff0c\u5176\u5339\u914d\u4e5f\u540c\u6837\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002</p>\n</div>", "manual_path": "/docs/19/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/19/gssapi-auth.html", "method": "same-major semantic node", "sha256": "cfadd4bf18ab0129430cf6efd0e841ffedbe7e7b9caac6fa5a8a632b5987dbdc", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[13]", "#GSSAPI-AUTH/p[2]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[4]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/versions/19/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.6 for details. It can be used in conjunction with GSSAPI encryption.", "/versions/19/facts/0/label": "Method", "/versions/19/facts/1/label": "Configuration", "/versions/19/facts/2/label": "Inventory", "/versions/19/facts/2/value": "User-visible source authentication method", "/versions/19/tables/0/title": "Documented method options and alternatives", "/versions/19/tables/0/columns/0/label": "Option or term", "/versions/19/tables/0/columns/1/label": "Meaning", "/versions/19/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/19/tables/0/rows/1/description": "Allows mapping from client principals to database user names. See Section 20.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/19/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "664e5d20119f5c97617f7d076eddfae74b725024588192a180188501cd966d14"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "20": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "revision": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "catalog_fingerprint": "398fbb9f262264053c02fbf79f88be0a6770c1473faa6ecd5931d6ec41b8258b", "source_snapshot_utc": "26-Sep-2026 20:22"}, "sources": [{"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "https://pg.center/docs/devel/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 20 English manual", "sha256": "cb2e8608aa069b2726adbd6d204ebfbc893a85e1f6d72fdd35e4a7175943e942", "language": "en", "original_url": "/docs/devel/gssapi-auth.html"}, {"url": "https://pg.center/docs/devel/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 20 English manual", "sha256": "cf2069461da3eec62f6fb4e3df8e46fd69ff4b3a2ad059eec355cee256d7996e", "language": "en", "original_url": "/docs/devel/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span>\u662f\u4e00\u79cd\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2743\" target=\"_top\">RFC 2743</a> \u4e2d\u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002<span class=\"productname\">PostgreSQL</span>\u652f\u6301<span class=\"productname\">GSSAPI</span>\u7528\u4e8e\u8ba4\u8bc1\u3001\u901a\u4fe1\u52a0\u5bc6\uff0c\u6216\u4e24\u8005\u517c\u800c\u6709\u4e4b\u3002<span class=\"productname\">GSSAPI</span>\u4e3a\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\u3002\u5982\u679c\u4f7f\u7528<span class=\"productname\">GSSAPI</span>\u52a0\u5bc6\u6216<acronym class=\"acronym\">SSL</acronym>\u52a0\u5bc6\uff0c\u6cbf\u6570\u636e\u5e93\u8fde\u63a5\u53d1\u9001\u7684\u6570\u636e\u5c06\u88ab\u52a0\u5bc6\uff1b\u5426\u5219\uff0c\u5c06\u4e0d\u4f1a\u88ab\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/devel/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u5f53 <span class=\"productname\">GSSAPI</span> \u4f7f\u7528 <span class=\"productname\">Kerberos</span> \u65f6\uff0c\u5b83\u4f1a\u4f7f\u7528\u4e00\u4e2a\u6807\u51c6\u7684\u670d\u52a1\u4e3b\u4f53\uff08\u8ba4\u8bc1\u8eab\u4efd\uff09\u540d\u79f0\uff0c\u5176\u683c\u5f0f\u4e3a <code class=\"literal\"><em class=\"replaceable\"><code>servicename</code></em>/<em class=\"replaceable\"><code>hostname</code></em>@<em class=\"replaceable\"><code>realm</code></em></code>\u3002\u67d0\u4e2a\u5b89\u88c5\u5b9e\u9645\u4f7f\u7528\u7684\u4e3b\u4f53\u540d\uff08principal name\uff09\u4e0d\u4f1a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u786c\u7f16\u7801\u5728 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4e2d\uff1b\u76f8\u53cd\uff0c\u5b83\u662f\u5728\u670d\u52a1\u5668\u8bfb\u53d6\u7684 <em class=\"firstterm\">keytab</em> \u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\uff0c\u670d\u52a1\u5668\u636e\u6b64\u786e\u5b9a\u81ea\u5df1\u7684\u8eab\u4efd\u3002\u5982\u679c keytab \u6587\u4ef6\u4e2d\u5217\u51fa\u4e86\u591a\u4e2a\u4e3b\u4f53\uff0c\u670d\u52a1\u5668\u4f1a\u63a5\u53d7\u5176\u4e2d\u4efb\u610f\u4e00\u4e2a\u3002\u670d\u52a1\u5668\u7684 realm \u540d\u79f0\u662f\u670d\u52a1\u5668\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u5fc5\u987b\u77e5\u9053\u5b83\u6253\u7b97\u8fde\u63a5\u7684\u670d\u52a1\u5668\u4e3b\u4f53\u540d\u3002\u8be5\u4e3b\u4f53\u540d\u4e2d\u7684 <em class=\"replaceable\"><code>servicename</code></em> \u90e8\u5206\u901a\u5e38\u662f <code class=\"literal\">postgres</code>\uff0c\u4f46\u4e5f\u53ef\u4ee5\u901a\u8fc7 <span class=\"application\">libpq</span> \u7684\u8fde\u63a5\u53c2\u6570<a class=\"xref\" href=\"/docs/devel/libpq-connect.html#LIBPQ-CONNECT-KRBSRVNAME\">krbsrvname</a>\u9009\u62e9\u5176\u4ed6\u503c\u3002<em class=\"replaceable\"><code>hostname</code></em> \u90e8\u5206\u5219\u662f <span class=\"application\">libpq</span> \u88ab\u544a\u77e5\u8981\u8fde\u63a5\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002realm \u540d\u79f0\u662f\u5ba2\u6237\u7aef\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u5ba2\u6237\u7aef\u4e5f\u4f1a\u6709\u4e00\u4e2a\u8868\u793a\u5176\u81ea\u8eab\u8eab\u4efd\u7684\u4e3b\u4f53\u540d\uff08\u5e76\u4e14\u5b83\u5fc5\u987b\u6301\u6709\u8be5\u4e3b\u4f53\u5bf9\u5e94\u7684\u6709\u6548\u7968\u636e\uff09\u3002\u8981\u4f7f\u7528 <span class=\"productname\">GSSAPI</span> \u8fdb\u884c\u8ba4\u8bc1\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u5fc5\u987b\u4e0e\u67d0\u4e2a <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u5173\u8054\u3002\u53ef\u4ee5\u4f7f\u7528 <code class=\"filename\">pg_ident.conf</code> \u914d\u7f6e\u6587\u4ef6\u5c06\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\uff1b\u4f8b\u5982\uff0c\u53ef\u4ee5\u628a <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a\u7b80\u5355\u7684 <code class=\"literal\">pgusername</code>\u3002\u53e6\u4e00\u79cd\u505a\u6cd5\u662f\u4e0d\u505a\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5728 <span class=\"productname\">PostgreSQL</span> \u4e2d\u628a\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u540d\u7528\u4f5c\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u4ec5\u901a\u8fc7\u53bb\u6389\u4e3b\u4f53\u540d\u79f0\u4e2d\u7684 realm\uff0c\u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u670d\u52a1\u5668 keytab \u6587\u4ef6\u7684\u4f4d\u7f6e\u7531\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/devel/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u6307\u5b9a\u3002\u51fa\u4e8e\u5b89\u5168\u539f\u56e0\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u5355\u72ec\u4f7f\u7528\u4e00\u4e2a keytab\uff0c\u800c\u4e0d\u8981\u8ba9\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u7cfb\u7edf keytab \u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u670d\u52a1\u5668 keytab \u6587\u4ef6\u5bf9 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u53f7\u53ef\u8bfb\uff08\u5e76\u4e14\u6700\u597d\u53ea\u8bfb\u3001\u4e0d\u53ef\u5199\uff09\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/devel/postgres-user.html\" title=\"18.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a018.1\u00a0\u8282</a>\uff09\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7528 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u89c1 Kerberos \u6587\u6863\u3002\u4e0b\u9762\u7684\u793a\u4f8b\u5c55\u793a\u4e86\u5982\u4f55\u4f7f\u7528 MIT Kerberos \u7684 <span class=\"application\">kadmin</span> \u5de5\u5177\u751f\u6210\u8be5\u6587\u4ef6\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>addprinc -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span> \u8ba4\u8bc1\u65b9\u6cd5\u652f\u6301\u4e0b\u5217\u8ba4\u8bc1\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/devel/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/devel/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u9664\u4e86\u8fd9\u4e9b\u53ef\u9488\u5bf9\u4e0d\u540c <code class=\"filename\">pg_hba.conf</code> \u9879\u5206\u522b\u8bbe\u7f6e\u7684\u9009\u9879\u4e4b\u5916\uff0c\u8fd8\u6709\u4e00\u4e2a\u670d\u52a1\u5668\u8303\u56f4\u7684\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/devel/runtime-config-connection.html#GUC-KRB-CASEINS-USERS\">krb_caseins_users</a>\u3002\u5982\u679c\u5b83\u88ab\u8bbe\u4e3a\u771f\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u4e0e\u7528\u6237\u6620\u5c04\u6761\u76ee\u7684\u5339\u914d\u5c06\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002\u5982\u679c\u8bbe\u7f6e\u4e86 <code class=\"literal\">krb_realm</code>\uff0c\u5176\u5339\u914d\u4e5f\u540c\u6837\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002</p>\n</div>", "manual_path": "/docs/devel/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/devel/gssapi-auth.html", "method": "same-major semantic node", "sha256": "71898d50a5be217d4a877ab14875a1a271a4aeb0de39966188caae65476680b1", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[13]", "#GSSAPI-AUTH/p[2]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[4]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/summary": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.6 for details. It can be used in conjunction with GSSAPI encryption.", "/category": "Authentication and access control", "/versions/20/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.6 for details. It can be used in conjunction with GSSAPI encryption.", "/versions/20/facts/0/label": "Method", "/versions/20/facts/1/label": "Configuration", "/versions/20/facts/2/label": "Inventory", "/versions/20/facts/2/value": "User-visible source authentication method", "/versions/20/tables/0/title": "Documented method options and alternatives", "/versions/20/tables/0/columns/0/label": "Option or term", "/versions/20/tables/0/columns/1/label": "Meaning", "/versions/20/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/20/tables/0/rows/1/description": "Allows mapping from client principals to database user names. See Section 20.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/20/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "8ec2e7a28b657cd331e8b40b9a62aa49593c908083470d1d6c0b2d7cde0bfdd2"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}}}, "snapshot": {"facts": [{"label": "\u65b9\u6cd5", "value": "gss"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/gssapi-auth.html", "path": "gssapi-auth.html", "label": "PostgreSQL 18 English manual", "sha256": "00da5d918d0d4f101749a389bcef7ae273436d43ddf22dcb5d38d2ec1d7c8735", "language": "en", "original_url": "/docs/18/gssapi-auth.html"}, {"url": "https://pg.center/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9", "language": "en", "original_url": "/docs/18/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "gss", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 GSSAPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e TCP/IP \u8fde\u63a5\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.6 \u8282\u3002\u53ef\u4e0e GSSAPI \u52a0\u5bc6\u7ed3\u5408\u4f7f\u7528\u3002"], "manual_html": "<div class=\"sect1\" id=\"GSSAPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.6.\u00a0GSSAPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span>\u662f\u4e00\u79cd\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc2743\" target=\"_top\">RFC 2743</a> \u4e2d\u5b9a\u4e49\u7684\u5b89\u5168\u8ba4\u8bc1\u884c\u4e1a\u6807\u51c6\u534f\u8bae\u3002<span class=\"productname\">PostgreSQL</span>\u652f\u6301<span class=\"productname\">GSSAPI</span>\u7528\u4e8e\u8ba4\u8bc1\u3001\u901a\u4fe1\u52a0\u5bc6\uff0c\u6216\u4e24\u8005\u517c\u800c\u6709\u4e4b\u3002<span class=\"productname\">GSSAPI</span>\u4e3a\u652f\u6301\u5b83\u7684\u7cfb\u7edf\u63d0\u4f9b\u81ea\u52a8\u8ba4\u8bc1\uff08\u5355\u70b9\u767b\u5f55\uff09\u3002\u8ba4\u8bc1\u672c\u8eab\u662f\u5b89\u5168\u7684\u3002\u5982\u679c\u4f7f\u7528<span class=\"productname\">GSSAPI</span>\u52a0\u5bc6\u6216<acronym class=\"acronym\">SSL</acronym>\u52a0\u5bc6\uff0c\u6cbf\u6570\u636e\u5e93\u8fde\u63a5\u53d1\u9001\u7684\u6570\u636e\u5c06\u88ab\u52a0\u5bc6\uff1b\u5426\u5219\uff0c\u5c06\u4e0d\u4f1a\u88ab\u52a0\u5bc6\u3002</p>\n<p lang=\"zh\">\u5f53\u7f16\u8bd1<span class=\"productname\">PostgreSQL</span>\u65f6\uff0cGSSAPI \u652f\u6301\u5fc5\u987b\u88ab\u542f\u7528\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u5f53 <span class=\"productname\">GSSAPI</span> \u4f7f\u7528 <span class=\"productname\">Kerberos</span> \u65f6\uff0c\u5b83\u4f1a\u4f7f\u7528\u4e00\u4e2a\u6807\u51c6\u7684\u670d\u52a1\u4e3b\u4f53\uff08\u8ba4\u8bc1\u8eab\u4efd\uff09\u540d\u79f0\uff0c\u5176\u683c\u5f0f\u4e3a <code class=\"literal\"><em class=\"replaceable\"><code>servicename</code></em>/<em class=\"replaceable\"><code>hostname</code></em>@<em class=\"replaceable\"><code>realm</code></em></code>\u3002\u67d0\u4e2a\u5b89\u88c5\u5b9e\u9645\u4f7f\u7528\u7684\u4e3b\u4f53\u540d\uff08principal name\uff09\u4e0d\u4f1a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u786c\u7f16\u7801\u5728 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u4e2d\uff1b\u76f8\u53cd\uff0c\u5b83\u662f\u5728\u670d\u52a1\u5668\u8bfb\u53d6\u7684 <em class=\"firstterm\">keytab</em> \u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\uff0c\u670d\u52a1\u5668\u636e\u6b64\u786e\u5b9a\u81ea\u5df1\u7684\u8eab\u4efd\u3002\u5982\u679c keytab \u6587\u4ef6\u4e2d\u5217\u51fa\u4e86\u591a\u4e2a\u4e3b\u4f53\uff0c\u670d\u52a1\u5668\u4f1a\u63a5\u53d7\u5176\u4e2d\u4efb\u610f\u4e00\u4e2a\u3002\u670d\u52a1\u5668\u7684 realm \u540d\u79f0\u662f\u670d\u52a1\u5668\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u8fde\u63a5\u65f6\uff0c\u5ba2\u6237\u7aef\u5fc5\u987b\u77e5\u9053\u5b83\u6253\u7b97\u8fde\u63a5\u7684\u670d\u52a1\u5668\u4e3b\u4f53\u540d\u3002\u8be5\u4e3b\u4f53\u540d\u4e2d\u7684 <em class=\"replaceable\"><code>servicename</code></em> \u90e8\u5206\u901a\u5e38\u662f <code class=\"literal\">postgres</code>\uff0c\u4f46\u4e5f\u53ef\u4ee5\u901a\u8fc7 <span class=\"application\">libpq</span> \u7684\u8fde\u63a5\u53c2\u6570<a class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-KRBSRVNAME\">krbsrvname</a>\u9009\u62e9\u5176\u4ed6\u503c\u3002<em class=\"replaceable\"><code>hostname</code></em> \u90e8\u5206\u5219\u662f <span class=\"application\">libpq</span> \u88ab\u544a\u77e5\u8981\u8fde\u63a5\u7684\u5b8c\u5168\u9650\u5b9a\u4e3b\u673a\u540d\u3002realm \u540d\u79f0\u662f\u5ba2\u6237\u7aef\u53ef\u8bbf\u95ee\u7684 Kerberos \u914d\u7f6e\u6587\u4ef6\u4e2d\u6307\u5b9a\u7684\u9996\u9009 realm\u3002</p>\n<p lang=\"zh\">\u5ba2\u6237\u7aef\u4e5f\u4f1a\u6709\u4e00\u4e2a\u8868\u793a\u5176\u81ea\u8eab\u8eab\u4efd\u7684\u4e3b\u4f53\u540d\uff08\u5e76\u4e14\u5b83\u5fc5\u987b\u6301\u6709\u8be5\u4e3b\u4f53\u5bf9\u5e94\u7684\u6709\u6548\u7968\u636e\uff09\u3002\u8981\u4f7f\u7528 <span class=\"productname\">GSSAPI</span> \u8fdb\u884c\u8ba4\u8bc1\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u5fc5\u987b\u4e0e\u67d0\u4e2a <span class=\"productname\">PostgreSQL</span> \u6570\u636e\u5e93\u7528\u6237\u540d\u5173\u8054\u3002\u53ef\u4ee5\u4f7f\u7528 <code class=\"filename\">pg_ident.conf</code> \u914d\u7f6e\u6587\u4ef6\u5c06\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\uff1b\u4f8b\u5982\uff0c\u53ef\u4ee5\u628a <code class=\"literal\">pgusername@realm</code> \u6620\u5c04\u4e3a\u7b80\u5355\u7684 <code class=\"literal\">pgusername</code>\u3002\u53e6\u4e00\u79cd\u505a\u6cd5\u662f\u4e0d\u505a\u4efb\u4f55\u6620\u5c04\uff0c\u76f4\u63a5\u5728 <span class=\"productname\">PostgreSQL</span> \u4e2d\u628a\u5b8c\u6574\u7684 <code class=\"literal\">username@realm</code> \u4e3b\u4f53\u540d\u7528\u4f5c\u89d2\u8272\u540d\u3002</p>\n<p lang=\"zh\">PostgreSQL \u8fd8\u652f\u6301\u4ec5\u901a\u8fc7\u53bb\u6389\u4e3b\u4f53\u540d\u79f0\u4e2d\u7684 realm\uff0c\u5c06\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u7528\u6237\u540d\u3002\u4fdd\u7559\u6b64\u65b9\u5f0f\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\uff0c\u5f3a\u70c8\u4e0d\u5efa\u8bae\u4f7f\u7528\uff0c\u56e0\u4e3a\u5b83\u65e0\u6cd5\u533a\u5206\u4e0d\u540c realm \u4e2d\u7684\u540c\u540d\u7528\u6237\u3002\u5c06 include_realm \u8bbe\u4e3a 0 \u5373\u53ef\u542f\u7528\u3002\u5728\u7b80\u5355\u7684\u5355 realm \u5b89\u88c5\u4e2d\uff0c\u5982\u679c\u540c\u65f6\u8bbe\u7f6e krb_realm \u53c2\u6570\uff0c\u4ee5\u68c0\u67e5\u4e3b\u4f53\u7684 realm \u4e0e\u5176\u503c\u5b8c\u5168\u4e00\u81f4\uff0c\u8fd9\u79cd\u505a\u6cd5\u4ecd\u7136\u5b89\u5168\uff1b\u4f46\u6bd4\u8d77\u5728 pg_ident.conf \u4e2d\u6307\u5b9a\u660e\u786e\u6620\u5c04\uff0c\u5b83\u7684\u80fd\u529b\u8f83\u5f31\u3002</p>\n<p lang=\"zh\">\u670d\u52a1\u5668 keytab \u6587\u4ef6\u7684\u4f4d\u7f6e\u7531\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/18/runtime-config-connection.html#GUC-KRB-SERVER-KEYFILE\">krb_server_keyfile</a>\u6307\u5b9a\u3002\u51fa\u4e8e\u5b89\u5168\u539f\u56e0\uff0c\u5efa\u8bae\u4e3a <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u5355\u72ec\u4f7f\u7528\u4e00\u4e2a keytab\uff0c\u800c\u4e0d\u8981\u8ba9\u670d\u52a1\u5668\u76f4\u63a5\u8bfb\u53d6\u7cfb\u7edf keytab \u6587\u4ef6\u3002\u8bf7\u786e\u4fdd\u670d\u52a1\u5668 keytab \u6587\u4ef6\u5bf9 <span class=\"productname\">PostgreSQL</span> \u670d\u52a1\u5668\u8d26\u53f7\u53ef\u8bfb\uff08\u5e76\u4e14\u6700\u597d\u53ea\u8bfb\u3001\u4e0d\u53ef\u5199\uff09\uff08\u53e6\u89c1<a class=\"xref\" href=\"/docs/18/postgres-user.html\" title=\"18.1.\u00a0PostgreSQL\u7528\u6237\u8d26\u6237\">\u7b2c\u00a018.1\u00a0\u8282</a>\uff09\u3002</p>\n<p lang=\"zh\">keytab \u6587\u4ef6\u7528 Kerberos \u8f6f\u4ef6\u751f\u6210\uff1b\u8be6\u89c1 Kerberos \u6587\u6863\u3002\u4e0b\u9762\u7684\u793a\u4f8b\u5c55\u793a\u4e86\u5982\u4f55\u4f7f\u7528 MIT Kerberos \u7684 <span class=\"application\">kadmin</span> \u5de5\u5177\u751f\u6210\u8be5\u6587\u4ef6\uff1a</p>\n<pre class=\"screen\"><code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>addprinc -randkey postgres/server.my.domain.org</code></strong>\n<code class=\"prompt\">kadmin% </code><strong class=\"userinput\"><code>ktadd -k krb5.keytab postgres/server.my.domain.org</code></strong>\n</pre>\n<p lang=\"zh\"><span class=\"productname\">GSSAPI</span> \u8ba4\u8bc1\u65b9\u6cd5\u652f\u6301\u4e0b\u5217\u8ba4\u8bc1\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u628a\u5ba2\u6237\u7aef\u4e3b\u4f53\u6620\u5c04\u4e3a\u6570\u636e\u5e93\u7528\u6237\u540d\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e GSSAPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u9664\u4e86\u8fd9\u4e9b\u53ef\u9488\u5bf9\u4e0d\u540c <code class=\"filename\">pg_hba.conf</code> \u9879\u5206\u522b\u8bbe\u7f6e\u7684\u9009\u9879\u4e4b\u5916\uff0c\u8fd8\u6709\u4e00\u4e2a\u670d\u52a1\u5668\u8303\u56f4\u7684\u914d\u7f6e\u53c2\u6570<a class=\"xref\" href=\"/docs/18/runtime-config-connection.html#GUC-KRB-CASEINS-USERS\">krb_caseins_users</a>\u3002\u5982\u679c\u5b83\u88ab\u8bbe\u4e3a\u771f\uff0c\u5ba2\u6237\u7aef\u4e3b\u4f53\u4e0e\u7528\u6237\u6620\u5c04\u6761\u76ee\u7684\u5339\u914d\u5c06\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002\u5982\u679c\u8bbe\u7f6e\u4e86 <code class=\"literal\">krb_realm</code>\uff0c\u5176\u5339\u914d\u4e5f\u540c\u6837\u4e0d\u533a\u5206\u5927\u5c0f\u5199\u3002</p>\n</div>", "manual_path": "/docs/18/gssapi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/18/gssapi-auth.html", "method": "same-major semantic node", "sha256": "9d738f27e484913c783da4fab3912a12c933c2d71acac2667824242d9c6763f9", "language": "zh", "matched_nodes": ["#GSSAPI-AUTH/div[0]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[1]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[3]", "#GSSAPI-AUTH/div[12]/dl[0]/dd[5]", "#GSSAPI-AUTH/p[11]", "#GSSAPI-AUTH/p[13]", "#GSSAPI-AUTH/p[2]", "#GSSAPI-AUTH/p[3]", "#GSSAPI-AUTH/p[4]", "#GSSAPI-AUTH/p[5]", "#GSSAPI-AUTH/p[6]", "#GSSAPI-AUTH/p[8]", "#GSSAPI-AUTH/p[9]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "Use GSSAPI to authenticate the user. This is only available for TCP/IP connections. See Section 20.6 for details. It can be used in conjunction with GSSAPI encryption.", "/versions/18/facts/0/label": "Method", "/versions/18/facts/1/label": "Configuration", "/versions/18/facts/2/label": "Inventory", "/versions/18/facts/2/value": "User-visible source authentication method", "/versions/18/tables/0/title": "Documented method options and alternatives", "/versions/18/tables/0/columns/0/label": "Option or term", "/versions/18/tables/0/columns/1/label": "Meaning", "/versions/18/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/18/tables/0/rows/1/description": "Allows mapping from client principals to database user names. See Section 20.2 for details. For a GSSAPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/18/tables/0/rows/2/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "f2983abaf29f5ca64050dbb361234b4bd69608ca59f4e4eddf1bdc3939c3efe1"}, "comparison_data": {"method": "gss", "documented_option_names": ["include_realm", "krb_realm", "map"]}, "comparison_hash": "c58b84e18bba9d75d595bab34b326eb6a8580a80636f79642c4af8843e7123cf", "manual_language": "zh"}, "comparison": {"left": "17", "right": "18", "status": "unchanged", "diff": ""}}