# PostgreSQL authenticaion

**URL:** https://discuss.tryton.org/t/postgresql-authenticaion/7824
**Category:** System Administrator
**Created:** [September 10, 2024, 12:45am UTC](https://discuss.tryton.org/t/postgresql-authenticaion/7824 "2024-09-10T00:45:45Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![cjm51213](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/cjm51213/32/3084_2.png) [@cjm51213](https://discuss.tryton.org/u/cjm51213)
#### Post date: [September 10, 2024, 12:45am UTC](https://discuss.tryton.org/t/postgresql-authenticaion/7824/1 "2024-09-10T00:45:45Z")

</div>

Hi Folks,

I am a QuickBooks refugee, which has no bearing on my question.

PostgreSQL apparently has two mutually exclusive authentication modes – “Peer” and “Password”. PostgreSQL installs under the assumption that “Peer” is the correct choice. This apparently means that access is granted based on your OS username. From my review of /etc/tryton.conf, I believe that Tryton expects to be able to authenticate with “Password”.

So:

1. Does Tryton expect to use “password” authentication?
2. Can Tryton use “Peer” authentication?

Thanks for the help,

Chris.

---

<div class="post-metadata">

### Author: ![dotbit](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/dotbit/32/2093_2.png) [@dotbit](https://discuss.tryton.org/u/dotbit)
#### Post date: [September 10, 2024, 5:47am UTC](https://discuss.tryton.org/t/postgresql-authenticaion/7824/2 "2024-09-10T05:47:16Z")

</div>

A `trusted` user in pg\_hba.conf, and no password in trytond.conf works, just tested.  
I use psql to test. As the trusted user, if psql connects to the database, then peer auth works.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [September 10, 2024, 7:01am UTC](https://discuss.tryton.org/t/postgresql-authenticaion/7824/3 "2024-09-10T07:01:15Z")

</div>

In addition, the user must be created in PostgreSQL using the same name as the username on the OS using [`createuser`](https://www.postgresql.org/docs/current/app-createuser.html). This must be executed as the OS user running PostgreSQL (usually `postgres`).

---

<div class="post-metadata">

### Author: ![cjm51213](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/cjm51213/32/3084_2.png) [@cjm51213](https://discuss.tryton.org/u/cjm51213)
#### Post date: [September 10, 2024, 4:01pm UTC](https://discuss.tryton.org/t/postgresql-authenticaion/7824/4 "2024-09-10T16:01:49Z")

</div>

Hi Follks,

I have learned much about PostgreSQL, but apparently not enough. I have a user (role) tryton as demonstrated by “\du” in psql. I have a database “tryton” as demonstrated by “\l” in psql. It is owned by Tryton. I have granted user “tryton” all privileges on database “tryton”. I am permitting BOTH peer and password authentication in pg\_hba.conf.

My research indicates that:

> local all all peer  
> local all all md5

is a valid pg\_hba.conf

I can “su - tryton” and transact as user “tryton”. This is clearly “peer” authentication. I cannot, as root, “psql -U tryton -W”. This is clearly “password” authentication. The error message indicates a failure of **peer** authentication.

So, I clearly have PostgreSQL misconfigured.

I’m not sure where to look next.

Thanks for the help.

Chris.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [September 10, 2024, 4:14pm UTC](https://discuss.tryton.org/t/postgresql-authenticaion/7824/5 "2024-09-10T16:14:10Z")

</div>

> [@cjm51213](#):
>
> I can “su - tryton” and transact as user “tryton”. This is clearly “peer” authentication. I cannot, as root, “psql -U tryton -W”. This is clearly “password” authentication. The error message indicates a failure of **peer** authentication.

So the password you type is wrong.

---

<div class="post-metadata">

### Author: ![cjm51213](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/cjm51213/32/3084_2.png) [@cjm51213](https://discuss.tryton.org/u/cjm51213)
#### Post date: [September 10, 2024, 4:31pm UTC](https://discuss.tryton.org/t/postgresql-authenticaion/7824/6 "2024-09-10T16:31:58Z")

</div>

Hi Ced,

No, I’m pretty sure it is correct. It is a development installation for now, so everything uses the same throw-away password. It is unlikely that I have mistyped it hundreds of times. And it is the same for any place a password is required.

However, I have clearly made at least one mistake, which has no bearing on the question before me, but does advance the problem. I forgot “–all” on the “trytond-admin” command. So, now I have a valid database, and I am able to get to the “password challenge” on the tryton client.

I still have PostgreSQL authentication issues, but those are not Tryton problems, and I’ll take them to a different forum.

Thanks for the help,

Chris.

P.S.: How do I mark this thread “closed”?

---

<div class="post-metadata">

### Author: ![system](https://discuss-cdn.tryton.org/uploads/default/original/1X/c6f8ec0a40525cdcd50058c734283450a4b3d38b.png) [@system](https://discuss.tryton.org/u/system)
#### Post date: [September 11, 2024, 4:32am UTC](https://discuss.tryton.org/t/postgresql-authenticaion/7824/7 "2024-09-11T04:32:08Z")

</div>

This topic was automatically closed 12 hours after the last reply. New replies are no longer allowed.
