Wiki / Connection Parameters / TLS
sslcertmode
This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:
Reading PostgreSQL 18.6.
Description
This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:
- Client library
- libpq 18.6
- Manual definition
- Documented
- Source environment fallback
- PGSSLCERTMODE
- Compiled fallback expression
- NULL
Usage
sslcertmodeDefault resolution and service-file precedence
The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.
Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\postgresql\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .
Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.
Environment variable evidence
PGSSLCERTMODE behaves the same as the sslcertmode connection parameter.
Environment fallback
| Variable | Documented behavior |
|---|---|
| PGSSLCERTMODE | PGSSLCERTMODE behaves the same as the sslcertmode connection parameter. |
Manual definition
sslcertmode-
This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:
disable-
A client certificate is never sent, even if one is available (default location or provided via sslcert).
allow(default)-
A certificate may be sent, if the server requests one and the client has one to send.
require-
The server must request a certificate. The connection will fail if the client does not send a certificate and the server successfully authenticates the client anyway.
Note
sslcertmode=requiredoesn't add any additional security, since there is no guarantee that the server is validating the certificate correctly; PostgreSQL servers generally request TLS certificates from clients whether they validate them or not. The option may be useful when troubleshooting more complicated TLS setups.
Related entries
Documentation and source
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
Source build
- Version
- 18.6
- Build
- https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
- Source fingerprint
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
Compare versions
PostgreSQL 15 → 16: added.
--- PostgreSQL 15
+++ PostgreSQL 16
@@ -1 +1,10 @@
-Not recorded in this version
+{
+ "compiled_default_expression": "NULL",
+ "default_evidence": [
+ "A client certificate is never sent, even if one is available (default location or provided via sslcert )."
+ ],
+ "definition": "This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes: disable A client certificate is never sent, even if one is available (default location or provided via sslcert ). allow (default) A certificate may be sent, if the server requests one and the client has one to send. require The server must request a certificate. The connection will fail if the client does not send a certificate and the server successfully authenticates the client anyway. Note sslcertmode=require doesn't add any additional security, since there is no guarantee that the server is validating the certificate correctly; PostgreSQL servers generally request TLS certificates from clients whether they validate them or not. The option may be useful when troubleshooting more complicated TLS setups.",
+ "documented": true,
+ "environment": "PGSSLCERTMODE",
+ "keyword": "sslcertmode"
+}
Compares recorded interfaces and attributes. Source fingerprints and build metadata are excluded; an absent sample is not proof of the introduction or removal release.
Related entries
Export JSON · Back to Connection Parameters · Recorded in PostgreSQL 16 through 20; the first sample is not necessarily its introduction.