requirepeer
指定服务器的操作系统用户名,例如 requirepeer=postgres。建立 Unix 域套接字连接时,如果设置了此参数,客户端会在连接开始时检查服务器进程是否以指定用户运行;不符则报错并中止连接。此参数可提供类似于 TCP/IP 连接中 SSL 证书所提供的服务器身份认证。如果 Unix 域套接字位于 /tmp 等所有人可写的位置,任何用户都可能在那里启动监听服务器;使用此参数可确保连接的是可信用户运行的服务器。仅在实现了 peer 认证方法的平台上支持此选项,见第 20.9 节。
当前查看 PostgreSQL 18.6。
说明
指定服务器的操作系统用户名,例如 requirepeer=postgres。建立 Unix 域套接字连接时,如果设置了此参数,客户端会在连接开始时检查服务器进程是否以指定用户运行;不符则报错并中止连接。此参数可提供类似于 TCP/IP 连接中 SSL 证书所提供的服务器身份认证。如果 Unix 域套接字位于 /tmp 等所有人可写的位置,任何用户都可能在那里启动监听服务器;使用此参数可确保连接的是可信用户运行的服务器。仅在实现了 peer 认证方法的平台上支持此选项,见第 20.9 节。
- 客户端库
- libpq 18.6
- 手册定义
- 手册已记载
- 源码中的环境变量回退
- PGREQUIREPEER
- 编译时回退表达式
- NULL
用法
requirepeer默认值解析与服务文件优先级
以下环境变量可用于选择连接参数的默认值,供 PQconnectdb 、 PQsetdbLogin 和 PQsetdb 在调用代码未直接指定参数值时使用。例如,这样可以避免在简单的客户端应用程序中硬编码数据库连接信息。
服务名称可以在每个用户的服务文件或系统范围的文件中定义。如果同一个服务名称存在于用户文件和系统文件中,则用户文件优先。默认情况下,每个用户的服务文件名为 ~/.pg_service.conf 。在Microsoft Windows上,它的名称为 %APPDATA%\postgresql\.pg_service.conf (其中 %APPDATA% 指用户配置文件夹中的应用数据子目录)。可以通过设置环境变量 PGSERVICEFILE 来指定不同的文件名。系统范围的文件名为 pg_service.conf 。默认情况下,在 PostgreSQL 安装的 etc 目录中寻找(使用 pg_config --sysconfdir 来准确识别此目录)。可以通过设置环境变量 PGSYSCONFDIR 来指定另一个目录,但不能指定不同的文件名。
从服务文件中获取的连接参数会与其他来源的参数合并。服务文件中的设置会覆盖相应的环境变量,而连接字符串中直接给出的值又会覆盖服务文件中的设置。例如,使用上述服务文件时,连接字符串 service=mydb port=5434 将使用主机 somehost 、端口 5434 、用户 admin ,以及由环境变量或内置默认值设置的其他参数。
环境变量证据
PGREQUIREPEER 的行为与 requirepeer 连接参数相同。
环境变量回退
| 变量 | 手册记载的行为 |
|---|---|
| PGREQUIREPEER | PGREQUIREPEER 的行为与 requirepeer 连接参数相同。 |
手册定义
requirepeer-
指定服务器的操作系统用户名,例如 requirepeer=postgres。建立 Unix 域套接字连接时,如果设置了此参数,客户端会在连接开始时检查服务器进程是否以指定用户运行;不符则报错并中止连接。此参数可提供类似于 TCP/IP 连接中 SSL 证书所提供的服务器身份认证。如果 Unix 域套接字位于 /tmp 等所有人可写的位置,任何用户都可能在那里启动监听服务器;使用此参数可确保连接的是可信用户运行的服务器。仅在实现了 peer 认证方法的平台上支持此选项,见第 20.9 节。
相关条目
文档与源码
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
来源构建
- 版本
- 18.6
- 构建
- https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
- 来源指纹
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
版本比较
PostgreSQL 16 → 17: 属性变化。
以下差异保留原始字段名与英文源描述。
--- PostgreSQL 16
+++ PostgreSQL 17
@@ -1,7 +1,7 @@
{
"compiled_default_expression": "NULL",
"default_evidence": [],
- "definition": "This parameter specifies the operating-system user name of the server, for example requirepeer=postgres . When making a Unix-domain socket connection, if this parameter is set, the client checks at the beginning of the connection that the server process is running under the specified user name; if it is not, the connection is aborted with an error. This parameter can be used to provide server authentication similar to that available with SSL certificates on TCP/IP connections. (Note that if the Unix-domain socket is in /tmp or another publicly writable location, any user could start a server listening there. Use this parameter to ensure that you are connected to a server run by a trusted user.) This option is only supported on platforms for which the peer authentication method is implemented; see Section 21.9 .",
+ "definition": "This parameter specifies the operating-system user name of the server, for example requirepeer=postgres . When making a Unix-domain socket connection, if this parameter is set, the client checks at the beginning of the connection that the server process is running under the specified user name; if it is not, the connection is aborted with an error. This parameter can be used to provide server authentication similar to that available with SSL certificates on TCP/IP connections. (Note that if the Unix-domain socket is in /tmp or another publicly writable location, any user could start a server listening there. Use this parameter to ensure that you are connected to a server run by a trusted user.) This option is only supported on platforms for which the peer authentication method is implemented; see Section 20.9 .",
"documented": true,
"environment": "PGREQUIREPEER",
"keyword": "requirepeer"
比较已记录的接口与属性,排除来源指纹和构建元数据。某个样本中没有记录,不能据此判断实际引入或移除的版本。
相关条目
导出 JSON · 返回连接参数 · 收录范围为 PostgreSQL 10 至 20;最早采样版本不一定是实际引入版本。