"Kaiting Chen" <kaitocr...@gmail.com> writes: > From this pg_hba configuration as the user 'kaiting.chen' is not in role > 'service' the second entry in the table should be skipped and he should > authenticate via GSSAPI. However this does not happen.
I believe the definition of "in role" we use here is "has the privileges of role". Since kaiting.chen is a superuser, all privilege tests will succeed for him, including that one. IOW, a superuser is automatically a member of every role. This isn't a bug. regards, tom lane -- Sent via pgsql-bugs mailing list (pgsql-bugs@postgresql.org) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-bugs