{"kind": "auth", "major": "18", "item": {"slug": "sspi", "name": "sspi", "name_zh": "", "category": "\u8eab\u4efd\u8ba4\u8bc1\u4e0e\u8bbf\u95ee\u63a7\u5236", "summary": "\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.7 \u8282\u3002", "aliases": [], "content_hash": "092c342c62890f15aef1ecdf7779258e44d0ca806348981c420ec891f219a33e", "versions": {"10": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "10.23", "major": "10", "channel": "historical", "revision": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9", "catalog_fingerprint": "691be281b476dde4374d7f805b2bacc2e75bdef40f1e9d3d42e91f97fe95cfd0"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, {"url": "https://pg.center/docs/10/auth-methods.html#SSPI-AUTH", "path": "auth-methods.html", "label": "PostgreSQL 10 English manual", "sha256": "856d36a3fdfe8c45a25832e49bd07e9b7480f2ff9a33e58ac7c392630149bc34", "language": "en", "original_url": "/docs/10/auth-methods.html#SSPI-AUTH"}, {"url": "https://pg.center/docs/10/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 10 English manual", "sha256": "04fed609a50e8fd3013ffebb83039c544d39b6c73a6c2b2e23cd7864a70b42da", "language": "en", "original_url": "/docs/10/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.3.4 \u8282\u3002"], "manual_html": "<div class=\"sect2\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h3 class=\"title\" lang=\"zh\"><span class=\"sect2\"><a href=\"/docs/10/auth-methods.html#SSPI-AUTH\">20.3.4. SSPI \u8ba4\u8bc1</a></span></h3>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u63d0\u4f9b\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u4f1a\u4ee5 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4f7f\u7528 SSPI\uff0c\u5c3d\u53ef\u80fd\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5426\u5219\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002\u53ea\u6709\u670d\u52a1\u5668\u548c\u5ba2\u6237\u7aef\u90fd\u8fd0\u884c <span class=\"productname\">Windows</span>\uff0c\u6216\u8005\u5728\u975e Windows \u5e73\u53f0\u4e0a\u53ef\u7528 <span class=\"productname\">GSSAPI</span> \u65f6\uff0c<span class=\"productname\">SSPI</span> \u8ba4\u8bc1\u624d\u80fd\u5de5\u4f5c\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/10/auth-methods.html#GSSAPI-AUTH\" title=\"20.3.3.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a020.3.3\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/10/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/10/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/10/auth-methods.html#SSPI-AUTH", "localization": {"status": "complete", "sources": [{"url": "/docs/10/auth-methods.html", "method": "same-major semantic node", "sha256": "128b4f29cf06d6bde5b9e357daacb6d538044ee392e4aece0e31c90b0a37b647", "language": "zh", "matched_nodes": ["#AUTH-METHODS/div[1]/dl[0]/dt[3]", "#AUTH-METHODS/div[5]/div[13]/dl[0]/dd[1]", "#AUTH-METHODS/div[5]/div[13]/dl[0]/dd[5]", "#AUTH-METHODS/div[6]/div[5]/dl[0]/dd[3]", "#AUTH-METHODS/div[6]/div[5]/dl[0]/dd[3]/p[0]", "#AUTH-METHODS/div[6]/div[5]/dl[0]/dd[3]/p[1]", "#AUTH-METHODS/div[6]/div[5]/dl[0]/dd[5]", "#AUTH-METHODS/div[6]/div[5]/dl[0]/dd[5]/p[0]", "#AUTH-METHODS/div[6]/div[5]/dl[0]/dd[5]/p[1]", "#AUTH-METHODS/div[6]/div[5]/dl[0]/dd[7]", "#AUTH-METHODS/div[6]/p[2]", "#AUTH-METHODS/div[6]/p[3]", "#AUTH-METHODS/div[6]/p[4]"]}], "language": "zh", "original_text": {"/versions/10/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 20.3.4 for details.", "/versions/10/facts/0/label": "Method", "/versions/10/facts/1/label": "Configuration", "/versions/10/facts/2/label": "Inventory", "/versions/10/facts/2/value": "User-visible source authentication method", "/versions/10/tables/0/title": "Documented method options and alternatives", "/versions/10/tables/0/columns/0/label": "Option or term", "/versions/10/tables/0/columns/1/label": "Meaning", "/versions/10/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/10/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/10/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/10/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For a SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/10/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "36fc48d5f04e472969df5d2ef12340cb9a0092253f90d409865506cad478e198"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "11": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "11.22", "major": "11", "channel": "historical", "revision": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0", "catalog_fingerprint": "8f21f4444b7f68923f4762af0eb7937fa2907026e91249483e79050de012c901"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, {"url": "https://pg.center/docs/11/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 11 English manual", "sha256": "39a38473d369fc90506a7fa68b1f9e350d45db3c72633f1d7828cd56fa64f8ee", "language": "en", "original_url": "/docs/11/sspi-auth.html"}, {"url": "https://pg.center/docs/11/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 11 English manual", "sha256": "5477c61a002171f5b4c462052d91231c405f39d89d825faf71e52fbae358eef7", "language": "en", "original_url": "/docs/11/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/11/gssapi-auth.html\" title=\"20.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a020.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/11/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/11/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/11/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/11/sspi-auth.html", "method": "same-major semantic node", "sha256": "b20d5ba58a3a6f4f1eb8f4b1aade4b4368852fa6b4b03e2d0dc75310b24e05d1", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/versions/11/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 20.7 for details.", "/versions/11/facts/0/label": "Method", "/versions/11/facts/1/label": "Configuration", "/versions/11/facts/2/label": "Inventory", "/versions/11/facts/2/value": "User-visible source authentication method", "/versions/11/tables/0/title": "Documented method options and alternatives", "/versions/11/tables/0/columns/0/label": "Option or term", "/versions/11/tables/0/columns/1/label": "Meaning", "/versions/11/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/11/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/11/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/11/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For a SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/11/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "c8e23af90537d1332c3f9d9a5ea87f4cdd5098e8e628b3ffe773b4a4397f055b"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "12": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "12.22", "major": "12", "channel": "historical", "revision": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b", "catalog_fingerprint": "9f857f4ee4875f9c7de6bfc9df4b757dec8b3a0bb88eadb519c7bd267bd56149"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, {"url": "https://pg.center/docs/12/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 12 English manual", "sha256": "b2dc76c7cf21bf06635ee39033ea8ef2346f51d2f2113b13fb32605df8128509", "language": "en", "original_url": "/docs/12/sspi-auth.html"}, {"url": "https://pg.center/docs/12/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 12 English manual", "sha256": "07e8cddcb38076c86dab95b72c4380a7a325f22401b5b7f9af5dd4931876f2cb", "language": "en", "original_url": "/docs/12/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/12/gssapi-auth.html\" title=\"20.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a020.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/12/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/12/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/12/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/12/sspi-auth.html", "method": "same-major semantic node", "sha256": "ec1558e63d28be703b4b01d2b2f544043d46a94f316ad5cfcafccaf8512831f0", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/versions/12/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 20.7 for details.", "/versions/12/facts/0/label": "Method", "/versions/12/facts/1/label": "Configuration", "/versions/12/facts/2/label": "Inventory", "/versions/12/facts/2/value": "User-visible source authentication method", "/versions/12/tables/0/title": "Documented method options and alternatives", "/versions/12/tables/0/columns/0/label": "Option or term", "/versions/12/tables/0/columns/1/label": "Meaning", "/versions/12/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/12/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/12/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/12/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For a SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/12/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "1c6dc405b4e21d1da18815bf8c3dae0173dd018bf70f8aeecf692dbea177e6ab"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "13": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "13.23", "major": "13", "channel": "historical", "revision": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6", "catalog_fingerprint": "c7015c845255c9d721c547c8ab9ef37825d332588c9691d982e6906b7d571002"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, {"url": "https://pg.center/docs/13/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 13 English manual", "sha256": "b40fd8c45d31d5e371680aa0e117de3ed322f0afb59efeab02ad4210eae9b306", "language": "en", "original_url": "/docs/13/sspi-auth.html"}, {"url": "https://pg.center/docs/13/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 13 English manual", "sha256": "3cc6ce851945cba450e6b26ecf9cae1efd3c03fb7b55e17876f4d9ea418a7c2e", "language": "en", "original_url": "/docs/13/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/13/gssapi-auth.html\" title=\"20.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a020.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/13/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/13/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/13/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/13/sspi-auth.html", "method": "same-major semantic node", "sha256": "0620bf99c7c1fcdf78b60fcbe196a5f1195f1089d2ee8b53692d6a5d77d3bf5b", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/versions/13/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 20.7 for details.", "/versions/13/facts/0/label": "Method", "/versions/13/facts/1/label": "Configuration", "/versions/13/facts/2/label": "Inventory", "/versions/13/facts/2/value": "User-visible source authentication method", "/versions/13/tables/0/title": "Documented method options and alternatives", "/versions/13/tables/0/columns/0/label": "Option or term", "/versions/13/tables/0/columns/1/label": "Meaning", "/versions/13/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/13/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/13/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/13/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For a SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/13/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "97c73f11716c369684dc028931bf6cec19ad0f7e2f799c09d959895d56f81454"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "14": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 21.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 21.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "14.24", "major": "14", "channel": "stable", "revision": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897", "catalog_fingerprint": "b272e6a82e4c46efda81c3a6a4cdf7de6a83dfff7f02f226a392fbe9acdd3adb"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, {"url": "https://pg.center/docs/14/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 14 English manual", "sha256": "ae425bfdc3aea83cb0d050f040d0b3c7ece4116825b7872d1edd6020294eb7d3", "language": "en", "original_url": "/docs/14/sspi-auth.html"}, {"url": "https://pg.center/docs/14/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 14 English manual", "sha256": "c9a75f04fd4a1069ea261ba061578a75c47a4b7e0bbf88761502fd4c19ccbc3f", "language": "en", "original_url": "/docs/14/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 21.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">21.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/14/gssapi-auth.html\" title=\"21.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a021.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/14/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/14/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/14/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/14/sspi-auth.html", "method": "same-major semantic node", "sha256": "381bc8eb78d2b7302945ab248867f301438b59a8bf4351ad87ba872ac41b5d8a", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/versions/14/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 21.7 for details.", "/versions/14/facts/0/label": "Method", "/versions/14/facts/1/label": "Configuration", "/versions/14/facts/2/label": "Inventory", "/versions/14/facts/2/value": "User-visible source authentication method", "/versions/14/tables/0/title": "Documented method options and alternatives", "/versions/14/tables/0/columns/0/label": "Option or term", "/versions/14/tables/0/columns/1/label": "Meaning", "/versions/14/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 21.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/14/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/14/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/14/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 21.2 for details. For an SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/14/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "b8805d3e969312b1d73abbcc634ad2f2723a04b053196688ecf32ae45ca518ba"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "15": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 21.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 21.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "15.19", "major": "15", "channel": "stable", "revision": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89", "catalog_fingerprint": "fefe3c425147a86defada190c9b0663cfe02caa1724f5dede93e46457572252d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, {"url": "https://pg.center/docs/15/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 15 English manual", "sha256": "17ab832ee3c62e43b823e42bef216c2a4b82b8df59a4bfbace33a543f7739b34", "language": "en", "original_url": "/docs/15/sspi-auth.html"}, {"url": "https://pg.center/docs/15/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 15 English manual", "sha256": "0470cd3eeb82cbc32d4b8b79e29f4427bdfd01f5bb15e6d9b7cee2f6dd2bba44", "language": "en", "original_url": "/docs/15/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 21.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">21.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/15/gssapi-auth.html\" title=\"21.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a021.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/15/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/15/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/15/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/15/sspi-auth.html", "method": "same-major semantic node", "sha256": "a9885b428bf529c759ae5c1eaa27c4475dd8edd32455352e6c8dbe05938783fc", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/versions/15/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 21.7 for details.", "/versions/15/facts/0/label": "Method", "/versions/15/facts/1/label": "Configuration", "/versions/15/facts/2/label": "Inventory", "/versions/15/facts/2/value": "User-visible source authentication method", "/versions/15/tables/0/title": "Documented method options and alternatives", "/versions/15/tables/0/columns/0/label": "Option or term", "/versions/15/tables/0/columns/1/label": "Meaning", "/versions/15/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 21.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/15/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/15/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/15/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 21.2 for details. For an SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/15/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "3ca5ea794331fdf41965cab27cc9a972432969132ee20a5324f3cbcdd4d40697"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "16": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 21.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 21.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "16.15", "major": "16", "channel": "stable", "revision": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed", "catalog_fingerprint": "fa133458dc8f52e15083b4f59b7a582e2e378b608d3ac5c53054df458a374e23"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, {"url": "https://pg.center/docs/16/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 16 English manual", "sha256": "51a343fa9add2da84f8926f4d16144e61552208b4c2a72c85eb2fa3524a36168", "language": "en", "original_url": "/docs/16/sspi-auth.html"}, {"url": "https://pg.center/docs/16/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 16 English manual", "sha256": "ccc5146375a184646d5992edbc693e12c0de4431a35141d6b56c8dd6b3c52132", "language": "en", "original_url": "/docs/16/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 21.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">21.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/16/gssapi-auth.html\" title=\"21.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a021.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/16/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/16/auth-username-maps.html\" title=\"21.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a021.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/16/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/16/sspi-auth.html", "method": "same-major semantic node", "sha256": "b1e3101c679af436681b4b8b0b81377453a71c05c026bc49d280013aef3d60f6", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/versions/16/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 21.7 for details.", "/versions/16/facts/0/label": "Method", "/versions/16/facts/1/label": "Configuration", "/versions/16/facts/2/label": "Inventory", "/versions/16/facts/2/value": "User-visible source authentication method", "/versions/16/tables/0/title": "Documented method options and alternatives", "/versions/16/tables/0/columns/0/label": "Option or term", "/versions/16/tables/0/columns/1/label": "Meaning", "/versions/16/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 21.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/16/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/16/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/16/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 21.2 for details. For an SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/16/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "c6ddb51c84eb33ecf4ef91b8e0e10f957af98646d2224a8ad958fd0b57fd8f8f"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "17": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "revision": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979", "catalog_fingerprint": "4bbe3ac77becd618478f66aec420a533e9017be356c5c1d51a4b17f0fd497c07"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "https://pg.center/docs/17/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 17 English manual", "sha256": "7105ac7595ea70518468e9a4e266927fbb2b8acde59fbb9673a1f5a41ee2510c", "language": "en", "original_url": "/docs/17/sspi-auth.html"}, {"url": "https://pg.center/docs/17/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 17 English manual", "sha256": "00c7a7c25d46aa1b2f24cd744cd4990ca4218cfafed2a4cab8c1dc1092090bba", "language": "en", "original_url": "/docs/17/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/17/gssapi-auth.html\" title=\"20.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a020.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/17/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/17/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/17/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/17/sspi-auth.html", "method": "same-major semantic node", "sha256": "a82a62f245d67b96e3f9ba986a183c6eee31064dbb12aaa40eba46bafc61a5d1", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/versions/17/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 20.7 for details.", "/versions/17/facts/0/label": "Method", "/versions/17/facts/1/label": "Configuration", "/versions/17/facts/2/label": "Inventory", "/versions/17/facts/2/value": "User-visible source authentication method", "/versions/17/tables/0/title": "Documented method options and alternatives", "/versions/17/tables/0/columns/0/label": "Option or term", "/versions/17/tables/0/columns/1/label": "Meaning", "/versions/17/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/17/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/17/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/17/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For an SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/17/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "9ae98ead0bef03b6c5ab866f3c07a569e05a0208a1f6bf7ea141999476f23d41"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "18": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 18 English manual", "sha256": "9ea88dc9d2eef123fe15041dd161acafa11c32ff992d125337c640727997cb55", "language": "en", "original_url": "/docs/18/sspi-auth.html"}, {"url": "https://pg.center/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9", "language": "en", "original_url": "/docs/18/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/gssapi-auth.html\" title=\"20.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a020.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/18/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/18/sspi-auth.html", "method": "same-major semantic node", "sha256": "15506f439a65120355be537c0d6cd0dfcdbbe3b58a59dd43f13266dfb2f12d83", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 20.7 for details.", "/versions/18/facts/0/label": "Method", "/versions/18/facts/1/label": "Configuration", "/versions/18/facts/2/label": "Inventory", "/versions/18/facts/2/value": "User-visible source authentication method", "/versions/18/tables/0/title": "Documented method options and alternatives", "/versions/18/tables/0/columns/0/label": "Option or term", "/versions/18/tables/0/columns/1/label": "Meaning", "/versions/18/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/18/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/18/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/18/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For an SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/18/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "57ad9a5d5d9c98feab051e7c55d80a4f62d606a1b48b22fe0fba2ad9bd135787"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "19": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "revision": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "catalog_fingerprint": "62fbf1a3689dbe8bf7e6b3372cfe6fbf867581427b3858a94c8419b77a4d2d1d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "https://pg.center/docs/19/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 19 English manual", "sha256": "60bd402e05dd99868ce1dcdd037eaff7115a41e887445398041fe387cf1d87a7", "language": "en", "original_url": "/docs/19/sspi-auth.html"}, {"url": "https://pg.center/docs/19/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 19 English manual", "sha256": "d05e9155d5388148c2c680ff208b62c6b3b0b1c30f302ada5ab4befec36c19b7", "language": "en", "original_url": "/docs/19/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/19/gssapi-auth.html\" title=\"20.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a020.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/19/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/19/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/19/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/19/sspi-auth.html", "method": "same-major semantic node", "sha256": "3875b73bde911862cf17ac26a0de2e013407c903fc55c7a5dfdb83aec3e7e875", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/versions/19/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 20.7 for details.", "/versions/19/facts/0/label": "Method", "/versions/19/facts/1/label": "Configuration", "/versions/19/facts/2/label": "Inventory", "/versions/19/facts/2/value": "User-visible source authentication method", "/versions/19/tables/0/title": "Documented method options and alternatives", "/versions/19/tables/0/columns/0/label": "Option or term", "/versions/19/tables/0/columns/1/label": "Meaning", "/versions/19/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/19/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/19/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/19/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For an SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/19/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "6636538292d9ffc82ed1534d4f4dd91fd8a52373c5bcd96270706dbe21531ee1"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "20": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "revision": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "catalog_fingerprint": "398fbb9f262264053c02fbf79f88be0a6770c1473faa6ecd5931d6ec41b8258b", "source_snapshot_utc": "26-Sep-2026 20:22"}, "sources": [{"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "https://pg.center/docs/devel/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 20 English manual", "sha256": "26232e57d5f9c6a90eb77bd1f834d2663999259f2a418f570b6dae357139ff32", "language": "en", "original_url": "/docs/devel/sspi-auth.html"}, {"url": "https://pg.center/docs/devel/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 20 English manual", "sha256": "cf2069461da3eec62f6fb4e3df8e46fd69ff4b3a2ad059eec355cee256d7996e", "language": "en", "original_url": "/docs/devel/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/devel/gssapi-auth.html\" title=\"20.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a020.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/devel/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/devel/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/devel/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/devel/sspi-auth.html", "method": "same-major semantic node", "sha256": "7b871d93307aac53fe8ceb0851bf0d5a80a95ca108e1def9d5ea7456cb9a09a9", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/summary": "Use SSPI to authenticate the user. This is only available on Windows. See Section 20.7 for details.", "/category": "Authentication and access control", "/versions/20/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 20.7 for details.", "/versions/20/facts/0/label": "Method", "/versions/20/facts/1/label": "Configuration", "/versions/20/facts/2/label": "Inventory", "/versions/20/facts/2/value": "User-visible source authentication method", "/versions/20/tables/0/title": "Documented method options and alternatives", "/versions/20/tables/0/columns/0/label": "Option or term", "/versions/20/tables/0/columns/1/label": "Meaning", "/versions/20/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/20/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/20/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/20/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For an SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/20/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "bf929f39ebb99c5e28bf4bff641d659c8649e52e3a9959f8690d3dc8a4ab3916"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}}}, "snapshot": {"facts": [{"label": "\u65b9\u6cd5", "value": "sspi"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "include_realm", "description": "\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08 \u7b2c 20.2 \u8282 \uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 krb_realm \u3002\u5efa\u8bae\u5c06 include_realm \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 pg_ident.conf \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 PostgreSQL \u7528\u6237\u540d\u3002"}, {"name": "compat_realm", "description": "\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 include_realm \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002 \u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002"}, {"name": "upn_username", "description": "\u5982\u679c\u6b64\u9009\u9879\u4e0e compat_realm \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002 \u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c libpq \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f libpq \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 username@EXAMPLE.COM \uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 username/hostbased@EXAMPLE.COM \uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f username@EXAMPLE.COM \uff08\u6216 username/hostbased@EXAMPLE.COM \uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 include_realm \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f username \uff08\u6216 username/hostbased \uff09\u3002"}, {"name": "krb_realm", "description": "\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/sspi-auth.html", "path": "sspi-auth.html", "label": "PostgreSQL 18 English manual", "sha256": "9ea88dc9d2eef123fe15041dd161acafa11c32ff992d125337c640727997cb55", "language": "en", "original_url": "/docs/18/sspi-auth.html"}, {"url": "https://pg.center/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9", "language": "en", "original_url": "/docs/18/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "sspi", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528 SSPI \u8ba4\u8bc1\u7528\u6237\uff0c\u4ec5\u9002\u7528\u4e8e Windows\u3002\u8be6\u60c5\u53c2\u89c1\u7b2c 20.7 \u8282\u3002"], "manual_html": "<div class=\"sect1\" id=\"SSPI-AUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.7.\u00a0SSPI \u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u662f\u4e00\u79cd\u7528\u4e8e\u5b89\u5168\u8ba4\u8bc1\u548c\u5355\u70b9\u767b\u5f55\u7684 <span class=\"productname\">Windows</span> \u6280\u672f\u3002<span class=\"productname\">PostgreSQL</span> \u5c06\u5728 <code class=\"literal\">negotiate</code> \u6a21\u5f0f\u4e0b\u4f7f\u7528 SSPI\uff0c\u8be5\u6a21\u5f0f\u4f1a\u5728\u53ef\u80fd\u65f6\u4f7f\u7528 <span class=\"productname\">Kerberos</span>\uff0c\u5e76\u5728\u5176\u4ed6\u60c5\u51b5\u4e0b\u81ea\u52a8\u56de\u9000\u5230 <span class=\"productname\">NTLM</span>\u3002<span class=\"productname\">SSPI</span> \u548c <span class=\"productname\">GSSAPI</span> \u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u662f\u53ef\u4e92\u64cd\u4f5c\u7684\uff0c\u4f8b\u5982\uff0c<span class=\"productname\">SSPI</span> \u5ba2\u6237\u7aef\u53ef\u4ee5\u5411 <span class=\"productname\">GSSAPI</span> \u670d\u52a1\u5668\u5b8c\u6210\u8ba4\u8bc1\u3002\u5efa\u8bae\u5728 Windows \u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e0a\u4f7f\u7528 <span class=\"productname\">SSPI</span>\uff0c\u5728\u975e Windows \u5e73\u53f0\u4e0a\u4f7f\u7528 <span class=\"productname\">GSSAPI</span>\u3002</p>\n<p lang=\"zh\">\u5f53\u4f7f\u7528<span class=\"productname\">Kerberos</span>\u8ba4\u8bc1\u65f6\uff0c<span class=\"productname\">SSPI</span>\u548c<span class=\"productname\">GSSAPI</span>\u7684\u5de5\u4f5c\u65b9\u5f0f\u76f8\u540c\uff0c\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/gssapi-auth.html\" title=\"20.6.\u00a0GSSAPI \u8ba4\u8bc1\">\u7b2c\u00a020.6\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\"><span class=\"productname\">SSPI</span> \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">include_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u5728\u901a\u8fc7\u7528\u6237\u540d\u6620\u5c04\uff08<a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\uff09\u4e4b\u524d\uff0c\u4f1a\u5148\u4ece\u5df2\u8ba4\u8bc1\u7528\u6237\u7684\u4e3b\u4f53\u540d\u4e2d\u53bb\u6389 realm \u540d\u79f0\u3002\u4e0d\u5efa\u8bae\u8fd9\u6837\u505a\uff1b\u5b83\u4e3b\u8981\u662f\u4e3a\u4e86\u5411\u540e\u517c\u5bb9\u800c\u4fdd\u7559\u7684\uff0c\u56e0\u4e3a\u5728\u591a realm \u73af\u5883\u4e2d\u8fd9\u5e76\u4e0d\u5b89\u5168\uff0c\u9664\u975e\u540c\u65f6\u4f7f\u7528\u4e86 <code class=\"literal\">krb_realm</code>\u3002\u5efa\u8bae\u5c06 <code class=\"literal\">include_realm</code> \u4fdd\u6301\u4e3a\u9ed8\u8ba4\u503c\uff081\uff09\uff0c\u5e76\u5728 <code class=\"filename\">pg_ident.conf</code> \u4e2d\u63d0\u4f9b\u663e\u5f0f\u6620\u5c04\uff0c\u628a\u4e3b\u4f53\u540d\u8f6c\u6362\u6210 <span class=\"productname\">PostgreSQL</span> \u7528\u6237\u540d\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">compat_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u8bbe\u4e3a 1\uff0c\u5219\u4f1a\u5728 <code class=\"literal\">include_realm</code> \u9009\u9879\u4e2d\u4f7f\u7528\u57df\u7684 SAM \u517c\u5bb9\u540d\u79f0\uff08\u4e5f\u79f0\u4e3a NetBIOS \u540d\u79f0\uff09\u3002\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002\u5982\u679c\u8bbe\u4e3a 0\uff0c\u5219\u4f1a\u4f7f\u7528 Kerberos \u7528\u6237\u4e3b\u4f53\u540d\u4e2d\u7684\u771f\u5b9e realm \u540d\u79f0\u3002</p>\n<p lang=\"zh\">\u53ea\u6709\u5f53\u670d\u52a1\u5668\u8fd0\u884c\u5728\u57df\u8d26\u53f7\uff08\u5305\u62ec\u57df\u6210\u5458\u7cfb\u7edf\u4e0a\u7684\u865a\u62df\u670d\u52a1\u8d26\u53f7\uff09\u4e0b\uff0c\u5e76\u4e14\u6240\u6709\u901a\u8fc7 SSPI \u8ba4\u8bc1\u7684\u5ba2\u6237\u7aef\u4e5f\u90fd\u4f7f\u7528\u57df\u8d26\u53f7\u65f6\uff0c\u624d\u53ef\u7981\u7528\u6b64\u9009\u9879\uff1b\u5426\u5219\uff0c\u7981\u7528\u6b64\u9009\u9879\u4f1a\u5bfc\u81f4\u8ba4\u8bc1\u5931\u8d25\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">upn_username</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5982\u679c\u6b64\u9009\u9879\u4e0e <code class=\"literal\">compat_realm</code> \u4e00\u8d77\u542f\u7528\uff0c\u5219\u8ba4\u8bc1\u65f6\u4f1a\u4f7f\u7528 Kerberos UPN \u4e2d\u7684\u7528\u6237\u540d\u3002\u5982\u679c\u7981\u7528\u5b83\uff08\u9ed8\u8ba4\u503c\uff09\uff0c\u5219\u4f7f\u7528 SAM \u517c\u5bb9\u7528\u6237\u540d\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5bf9\u65b0\u5efa\u7528\u6237\u8d26\u53f7\u800c\u8a00\uff0c\u8fd9\u4e24\u4e2a\u540d\u79f0\u662f\u76f8\u540c\u7684\u3002</p>\n<p lang=\"zh\">\u6ce8\u610f\uff0c\u5982\u679c\u6ca1\u6709\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\uff0c<span class=\"application\">libpq</span> \u4f1a\u4f7f\u7528 SAM \u517c\u5bb9\u540d\u79f0\u3002\u5982\u679c\u4f60\u4f7f\u7528\u7684\u662f <span class=\"application\">libpq</span> \u6216\u57fa\u4e8e\u5b83\u7684\u9a71\u52a8\uff0c\u5e94\u5f53\u4fdd\u6301\u8be5\u9009\u9879\u4e3a\u7981\u7528\u72b6\u6001\uff0c\u6216\u8005\u5728\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u663e\u5f0f\u6307\u5b9a\u7528\u6237\u540d\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728\u7cfb\u7edf\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u8fdb\u884c\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5bf9\u4e8e SSPI/Kerberos \u4e3b\u4f53\uff0c\u4f8b\u5982 <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216\u8005\u8f83\u5c11\u89c1\u7684 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u7528\u4e8e\u6620\u5c04\u7684\u7528\u6237\u540d\u5206\u522b\u662f <code class=\"literal\">username@EXAMPLE.COM</code>\uff08\u6216 <code class=\"literal\">username/hostbased@EXAMPLE.COM</code>\uff09\uff0c\u9664\u975e\u5df2\u7ecf\u5c06 <code class=\"literal\">include_realm</code> \u8bbe\u4e3a 0\uff1b\u5728\u90a3\u79cd\u60c5\u51b5\u4e0b\uff0c\u6620\u5c04\u65f6\u89c6\u4e3a\u7cfb\u7edf\u7528\u6237\u540d\u7684\u662f <code class=\"literal\">username</code>\uff08\u6216 <code class=\"literal\">username/hostbased</code>\uff09\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">krb_realm</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u8bbe\u7f6e\u7528\u4e8e\u5339\u914d\u7528\u6237\u4e3b\u4f53\u540d\u7684 realm\u3002\u5982\u679c\u8bbe\u7f6e\u4e86\u8be5\u53c2\u6570\uff0c\u5219\u53ea\u63a5\u53d7\u6765\u81ea\u8be5 realm \u7684\u7528\u6237\uff1b\u5982\u679c\u672a\u8bbe\u7f6e\uff0c\u5219\u5141\u8bb8\u6765\u81ea\u4efb\u610f realm \u7684\u7528\u6237\u8fde\u63a5\uff0c\u4f46\u4ecd\u53d7\u5df2\u6267\u884c\u7684\u7528\u6237\u540d\u6620\u5c04\u7ea6\u675f\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/18/sspi-auth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/18/sspi-auth.html", "method": "same-major semantic node", "sha256": "15506f439a65120355be537c0d6cd0dfcdbbe3b58a59dd43f13266dfb2f12d83", "language": "zh", "matched_nodes": ["#SSPI-AUTH/div[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[3]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[0]", "#SSPI-AUTH/div[5]/dl[0]/dd[5]/p[1]", "#SSPI-AUTH/div[5]/dl[0]/dd[7]", "#SSPI-AUTH/div[5]/dl[0]/dd[9]", "#SSPI-AUTH/p[2]", "#SSPI-AUTH/p[3]", "#SSPI-AUTH/p[4]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "Use SSPI to authenticate the user. This is only available on Windows. See Section 20.7 for details.", "/versions/18/facts/0/label": "Method", "/versions/18/facts/1/label": "Configuration", "/versions/18/facts/2/label": "Inventory", "/versions/18/facts/2/value": "User-visible source authentication method", "/versions/18/tables/0/title": "Documented method options and alternatives", "/versions/18/tables/0/columns/0/label": "Option or term", "/versions/18/tables/0/columns/1/label": "Meaning", "/versions/18/tables/0/rows/0/description": "If set to 0, the realm name from the authenticated user principal is stripped off before being passed through the user name mapping ( Section 20.2 ). This is discouraged and is primarily available for backwards compatibility, as it is not secure in multi-realm environments unless krb_realm is also used. It is recommended to leave include_realm set to the default (1) and to provide an explicit mapping in pg_ident.conf to convert principal names to PostgreSQL user names.", "/versions/18/tables/0/rows/1/description": "If set to 1, the domain's SAM-compatible name (also known as the NetBIOS name) is used for the include_realm option. This is the default. If set to 0, the true realm name from the Kerberos user principal name is used. Do not disable this option unless your server runs under a domain account (this includes virtual service accounts on a domain member system) and all clients authenticating through SSPI are also using domain accounts, or authentication will fail.", "/versions/18/tables/0/rows/2/description": "If this option is enabled along with compat_realm , the user name from the Kerberos UPN is used for authentication. If it is disabled (the default), the SAM-compatible user name is used. By default, these two names are identical for new user accounts. Note that libpq uses the SAM-compatible name if no explicit user name is specified. If you use libpq or a driver based on it, you should leave this option disabled or explicitly specify user name in the connection string.", "/versions/18/tables/0/rows/3/description": "Allows for mapping between system and database user names. See Section 20.2 for details. For an SSPI/Kerberos principal, such as username@EXAMPLE.COM (or, less commonly, username/hostbased@EXAMPLE.COM ), the user name used for mapping is username@EXAMPLE.COM (or username/hostbased@EXAMPLE.COM , respectively), unless include_realm has been set to 0, in which case username (or username/hostbased ) is what is seen as the system user name when mapping.", "/versions/18/tables/0/rows/4/description": "Sets the realm to match user principal names against. If this parameter is set, only users of that realm will be accepted. If it is not set, users of any realm can connect, subject to whatever user name mapping is done."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "57ad9a5d5d9c98feab051e7c55d80a4f62d606a1b48b22fe0fba2ad9bd135787"}, "comparison_data": {"method": "sspi", "documented_option_names": ["compat_realm", "include_realm", "krb_realm", "map", "upn_username"]}, "comparison_hash": "0220f8a01c511536c8f908389cce9eb03bab3d3ab8ba3aa2bd8f685651f29377", "manual_language": "zh"}, "comparison": {"left": "17", "right": "18", "status": "unchanged", "diff": ""}}