↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 连接参数 / 身份认证

require_auth

指定客户端要求服务器采用的认证方法。如果服务器没有使用所要求的方法来认证客户端,或者服务器没有完整完成认证握手,则连接将失败。也可以提供一个以逗号分隔的方法列表,此时服务器必须恰好使用其中一种方法,连接才会成功。默认情况下接受任意认证方法,并且服务器也可以完全跳过认证。

当前查看 PostgreSQL 18.6。

说明

指定客户端要求服务器采用的认证方法。如果服务器没有使用所要求的方法来认证客户端,或者服务器没有完整完成认证握手,则连接将失败。也可以提供一个以逗号分隔的方法列表,此时服务器必须恰好使用其中一种方法,连接才会成功。默认情况下接受任意认证方法,并且服务器也可以完全跳过认证。

客户端库
libpq 18.6
手册定义
手册已记载
源码中的环境变量回退
PGREQUIREAUTH
编译时回退表达式
NULL

用法

require_auth

默认值解析与服务文件优先级

以下环境变量可用于选择连接参数的默认值,供 PQconnectdb 、 PQsetdbLogin 和 PQsetdb 在调用代码未直接指定参数值时使用。例如,这样可以避免在简单的客户端应用程序中硬编码数据库连接信息。

服务名称可以在每个用户的服务文件或系统范围的文件中定义。如果同一个服务名称存在于用户文件和系统文件中,则用户文件优先。默认情况下,每个用户的服务文件名为 ~/.pg_service.conf 。在Microsoft Windows上,它的名称为 %APPDATA%\postgresql\.pg_service.conf (其中 %APPDATA% 指用户配置文件夹中的应用数据子目录)。可以通过设置环境变量 PGSERVICEFILE 来指定不同的文件名。系统范围的文件名为 pg_service.conf 。默认情况下,在 PostgreSQL 安装的 etc 目录中寻找(使用 pg_config --sysconfdir 来准确识别此目录)。可以通过设置环境变量 PGSYSCONFDIR 来指定另一个目录,但不能指定不同的文件名。

从服务文件中获取的连接参数会与其他来源的参数合并。服务文件中的设置会覆盖相应的环境变量,而连接字符串中直接给出的值又会覆盖服务文件中的设置。例如,使用上述服务文件时,连接字符串 service=mydb port=5434 将使用主机 somehost 、端口 5434 、用户 admin ,以及由环境变量或内置默认值设置的其他参数。

环境变量证据

PGREQUIREAUTH 的行为与 require_auth 连接参数相同。

环境变量回退

变量手册记载的行为
PGREQUIREAUTHPGREQUIREAUTH 的行为与 require_auth 连接参数相同。

手册定义

require_auth

指定客户端要求服务器采用的认证方法。如果服务器没有使用所要求的方法来认证客户端,或者服务器没有完整完成认证握手,则连接将失败。也可以提供一个以逗号分隔的方法列表,此时服务器必须恰好使用其中一种方法,连接才会成功。默认情况下接受任意认证方法,并且服务器也可以完全跳过认证。

可以在方法名前加上!前缀以表示否定,此时服务器不得尝试所列方法;除此之外,任何其他方法都可接受,并且服务器也可以完全不认证客户端。如果提供的是逗号分隔列表,服务器不得尝试其中任何一个被否定的方法。否定形式和非否定形式不能在同一设置中混用。

最后还有一种特殊情况:none方法要求服务器不使用认证质询。(它也可以被否定,用来要求必须进行某种认证。)

可指定的方法如下:

password

服务器必须请求明文密码认证。

md5

服务器必须请求 MD5 hash 密码认证。

警告

对 MD5 加密密码的支持已弃用,并将在PostgreSQL的未来版本中移除。迁移到其他密码类型的详细信息见第 20.5 节。

gss

服务器必须通过 GSSAPI 请求 Kerberos 握手,或建立 GSS 加密通道,另见 gssencmode。

sspi

服务器必须请求 Windows SSPI 认证。

scram-sha-256

服务器必须与客户端成功完成一次 SCRAM-SHA-256 认证交换。

oauth

服务器必须向客户端请求 OAuth Bearer 令牌。

none

服务器不得提示客户端执行认证交换。(这并不禁止通过 TLS 进行客户端证书认证,也不禁止通过 GSS 自身的加密传输进行 GSS 认证。)

相关条目

文档与源码

来源构建
版本
18.6
构建
https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
来源指纹
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8

版本比较

PostgreSQL 15 → 16: 新增收录。

以下差异保留原始字段名与英文源描述。

--- PostgreSQL 15
+++ PostgreSQL 16
@@ -1 +1,10 @@
-该版未收录
+{
+  "compiled_default_expression": "NULL",
+  "default_evidence": [
+    "Specifies the authentication method that the client requires from the server. If the server does not use the required method to authenticate the client, or if the authentication handshake is not fully completed by the server, the connection will fail. A comma-separated list of methods may also be provided, of which the server must use exactly one in order for the connection to succeed. By default, any authentication method is accepted, and the server is free to skip authentication altogether."
+  ],
+  "definition": "Specifies the authentication method that the client requires from the server. If the server does not use the required method to authenticate the client, or if the authentication handshake is not fully completed by the server, the connection will fail. A comma-separated list of methods may also be provided, of which the server must use exactly one in order for the connection to succeed. By default, any authentication method is accepted, and the server is free to skip authentication altogether. Methods may be negated with the addition of a ! prefix, in which case the server must not attempt the listed method; any other method is accepted, and the server is free not to authenticate the client at all. If a comma-separated list is provided, the server may not attempt any of the listed negated methods. Negated and non-negated forms may not be combined in the same setting. As a final special case, the none method requires the server not to use an authentication challenge. (It may also be negated, to require some form of authentication.) The following methods may be specified: password The server must request plaintext password authentication. md5 The server must request MD5 hashed password authentication. gss The server must either request a Kerberos handshake via GSSAPI or establish a GSS -encrypted channel (see also gssencmode ). sspi The server must request Windows SSPI authentication. scram-sha-256 The server must successfully complete a SCRAM-SHA-256 authentication exchange with the client. none The server must not prompt the client for an authentication exchange. (This does not prohibit client certificate authentication via TLS, nor GSS authentication via its encrypted transport.)",
+  "documented": true,
+  "environment": "PGREQUIREAUTH",
+  "keyword": "require_auth"
+}

比较已记录的接口与属性,排除来源指纹和构建元数据。某个样本中没有记录,不能据此判断实际引入或移除的版本。

相关条目

导出 JSON · 返回连接参数 · 收录范围为 PostgreSQL 16 至 20;最早采样版本不一定是实际引入版本。