{"kind": "conn", "major": "18", "item": {"slug": "sslrootcert", "name": "sslrootcert", "name_zh": "", "category": "TLS", "summary": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "aliases": ["PGSSLROOTCERT", "sslrootcert"], "content_hash": "2c0994dd3adb475606af3a64a82b143300b1afbbed3991668e7d174975c9261b", "versions": {"10": {"facts": [{"label": "Client library", "value": "libpq 10.23"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/10/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/10/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/10/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/10/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "10.23", "major": "10", "channel": "historical", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/10/postgresql-10-A4.pdf", "bytes": 12631706, "pages": 2591, "sha256": "34497ab9efb45c5bdf1bd11b9016b5451354feb462fa029cf74557a5fa5fbbc1", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/10/postgresql-10-US.pdf", "bytes": 12531684, "pages": 2724, "sha256": "429cc7133ddf4f97c560aa466dc9caea4b718721a8321e293357037cf0af4733", "built_at": "2026-09-26"}}, "tree": "10", "index": "index.html", "major": "10", "pages": 1085, "release": "10.23", "source_url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "svg_assets": 0, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, "revision": "f9301feba91e2e2566038a36b8cee0e4402db68989538f88670fddd20b1f78ea", "evidence_kind": "English manual and source declarations", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, "sources": [{"url": "/docs/10/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "10.23 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "153ad57ac835922140534bebdbfc61776676beddc59f85c240e039721e514699"}, {"url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "10.23 libpq connection option declarations", "sha256": "de8b800e515b3bf4dfe66cafcdfbb34133ec7c5848f255eabb2a1d4c0855d214", "archive_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, {"url": "/docs/10/libpq-envars.html", "file": "libpq-envars.html", "label": "10.23 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "241a428dcfcac6131f39c8d9f1f178fa15a8ebe331381fe738f1ceb12ca22c54"}, {"url": "/docs/10/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "10.23 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "9b317c875bed047e3baba0da1777c71257c0d4a636392624f4e4f3c3337b0912"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/10/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span></dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "compiled_default_expression": "NULL"}, "comparison_hash": "2a8c30b93a66bbe5193882acb1cc8def71964ef9783d55a2df8a8594384133f7", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "11": {"facts": [{"label": "Client library", "value": "libpq 11.22"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/11/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/11/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/11/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/11/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "11.22", "major": "11", "channel": "historical", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/11/postgresql-11-A4.pdf", "bytes": 13057499, "pages": 2732, "sha256": "41d75855e610d0d9b8802b87dc5b080bef8d7e91c7cf69401fbf8d3cf801b4b5", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/11/postgresql-11-US.pdf", "bytes": 12961189, "pages": 2883, "sha256": "6a8899ef36935a5b7ed2b436207564a567a4ef1eb1c2200195876b8de4d4fa30", "built_at": "2026-09-26"}}, "tree": "11", "index": "index.html", "major": "11", "pages": 1125, "release": "11.22", "source_url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "svg_assets": 0, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, "revision": "53315ddaf3b3f9e6669fd1edc096bbb2cd4a65ea3e836c89e542b43af9ba3a7f", "evidence_kind": "English manual and source declarations", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, "sources": [{"url": "/docs/11/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "11.22 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "51609c4e32eec49656c45de2c14a8ad69e10c9b3300bc9c57658857fcee1d824"}, {"url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "11.22 libpq connection option declarations", "sha256": "89673096491d2ff370af0e614e035336cba52c14107a4ea22bb0ed234fa1c684", "archive_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, {"url": "/docs/11/libpq-envars.html", "file": "libpq-envars.html", "label": "11.22 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "0012607dbb5e04e9ed34fd34a0eb8de14f0a6f5cb07fe95ca868fb2fddf426b5"}, {"url": "/docs/11/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "11.22 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "c0f63b0b0757a3ca6f35c8f6617ee3850d5536c11fabc4fa747ad18467a26f6f"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/11/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span></dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "compiled_default_expression": "NULL"}, "comparison_hash": "2a8c30b93a66bbe5193882acb1cc8def71964ef9783d55a2df8a8594384133f7", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "12": {"facts": [{"label": "Client library", "value": "libpq 12.22"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/12/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/12/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/12/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/12/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "12.22", "major": "12", "channel": "historical", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/12/postgresql-12-A4.pdf", "bytes": 13424351, "pages": 2803, "sha256": "7422cf53fd1939e7a3d2925231a88b0330e468afa5393627cac0ff86158a0621", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/12/postgresql-12-US.pdf", "bytes": 13322565, "pages": 2958, "sha256": "51f3b04e72907fc38512685946223452ea65f84419c60c66241dfa3396035e77", "built_at": "2026-09-26"}}, "tree": "12", "index": "index.html", "major": "12", "pages": 1131, "release": "12.22", "source_url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "svg_assets": 2, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, "revision": "7a827e97cbfacd7febff75f34443e2043e40723de5b6d8c9d81a9430b65a37e4", "evidence_kind": "English manual and source declarations", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, "sources": [{"url": "/docs/12/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "12.22 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "600a43dc93518d62d1c83c8b09d4b695bf1a04e4a5a58b239dc9aa287e83f3d2"}, {"url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "12.22 libpq connection option declarations", "sha256": "c7b1ad8e03dd5655cabab7572b0a3dc3c9d0f8f1646a5d03a92cd4edbb1d021b", "archive_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, {"url": "/docs/12/libpq-envars.html", "file": "libpq-envars.html", "label": "12.22 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "e4c92c7bbed845b27426c607f96d549f30096a977454ed19608451a26bfb93cb"}, {"url": "/docs/12/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "12.22 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "dc1adeb371e8a783b184c80e9708982e1e44a9da311604009643b12cb41a600c"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/12/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span></dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "compiled_default_expression": "NULL"}, "comparison_hash": "2a8c30b93a66bbe5193882acb1cc8def71964ef9783d55a2df8a8594384133f7", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "13": {"facts": [{"label": "Client library", "value": "libpq 13.23"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/13/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/13/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/13/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/13/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "13.23", "major": "13", "channel": "historical", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/13/postgresql-13-A4.pdf", "bytes": 13843239, "pages": 2826, "sha256": "171cc09f90936dbc1cbd503a98ff07ae72ea58ab9771ff051313f1217737799c", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/13/postgresql-13-US.pdf", "bytes": 13739572, "pages": 2984, "sha256": "48d09c6e197d9db4220f41afe83efe848a8661b1b168d3b89419751ecaf6c24d", "built_at": "2026-09-26"}}, "tree": "13", "index": "index.html", "major": "13", "pages": 1139, "release": "13.23", "source_url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "svg_assets": 3, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, "revision": "614ee3133270254e476c118cdf6f72af78d4e4b8bbd9b28ed9ab1e14e4e9c0f6", "evidence_kind": "English manual and source declarations", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, "sources": [{"url": "/docs/13/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "13.23 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "2e9c70e9aed0c3850c1af1c7680be465582020bb8c2dfcb009fb9ffe3cd194b6"}, {"url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "13.23 libpq connection option declarations", "sha256": "406a116bf54e8afc41f76cf0ad669713e981140c9940b54afad98e7393467e9d", "archive_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, {"url": "/docs/13/libpq-envars.html", "file": "libpq-envars.html", "label": "13.23 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "1125e5a919204ff2f54691c1558a08efd818f206f6175cadba3cf6cbc17679bb"}, {"url": "/docs/13/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "13.23 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "d31c36b3039250e7d190706f7b777328c01980795deb0440063c4bfcef125794"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/13/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span></dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "compiled_default_expression": "NULL"}, "comparison_hash": "2a8c30b93a66bbe5193882acb1cc8def71964ef9783d55a2df8a8594384133f7", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "14": {"facts": [{"label": "Client library", "value": "libpq 14.24"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/14/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/14/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/14/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/14/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "14.24", "major": "14", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/14/postgresql-14-A4.pdf", "bytes": 14354704, "pages": 2944, "sha256": "8bc6b9dd7b246888bb77f0a5e8c39a2eae52e9926569832669c7d1600becb27c", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/14/postgresql-14-US.pdf", "bytes": 14242178, "pages": 3102, "sha256": "b7ecb5a5f62d8b9f73a69e25a7d26ba285373bc53168a553bff7b77955506db4", "built_at": "2026-09-26"}}, "tree": "14", "index": "index.html", "major": "14", "pages": 1158, "release": "14.24", "source_url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "svg_assets": 3, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, "revision": "588700d46356d8837c77c7c0a4e71e645fe6535983b8f1830aa8f2e4e41c40ae", "evidence_kind": "English manual and source declarations", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, "sources": [{"url": "/docs/14/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "14.24 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "4cacc729dd3093cfa7b6528d9a22800392070b8eba1106da9a3d540629ae98a8"}, {"url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "14.24 libpq connection option declarations", "sha256": "8dbe7c41927bd93713fce72495616fab20f888775fc95c01a6f2f710087caff7", "archive_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, {"url": "/docs/14/libpq-envars.html", "file": "libpq-envars.html", "label": "14.24 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "0222834e8076ac3a09545133c2a98dbfdd094dc589bcea847934931d1903a76f"}, {"url": "/docs/14/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "14.24 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "0208611ef07704d22d30b69db7132fb062f8caf3a3bd38a77f23c3696a447cb9"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/14/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span></dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "compiled_default_expression": "NULL"}, "comparison_hash": "2a8c30b93a66bbe5193882acb1cc8def71964ef9783d55a2df8a8594384133f7", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "15": {"facts": [{"label": "Client library", "value": "libpq 15.19"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/15/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/15/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/15/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/15/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "15.19", "major": "15", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/15/postgresql-15-A4.pdf", "bytes": 14609140, "pages": 2987, "sha256": "66228564a4d16efb47d6a914085716ecfe22ca1566db56bc7c3d82f790646d72", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/15/postgresql-15-US.pdf", "bytes": 14495690, "pages": 3153, "sha256": "645a498c2390d47a6223ec74770631185807a19c484edb0fc5a295d9f460bc02", "built_at": "2026-09-26"}}, "tree": "15", "index": "index.html", "major": "15", "pages": 1168, "release": "15.19", "source_url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "svg_assets": 3, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, "revision": "6af958c6520151fc7697d56e0616b03fb00522c4568158674d452ae0644ba545", "evidence_kind": "English manual and source declarations", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, "sources": [{"url": "/docs/15/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "15.19 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "64a9c015aa67f085bd343fc47439d7a15fd8b6583b0d6f3cf94d7bb94b6f544a"}, {"url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "15.19 libpq connection option declarations", "sha256": "63bd4ab01b7161916c0a86a4510f36d287c3ef4e78910568cde611bb925dd9f2", "archive_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, {"url": "/docs/15/libpq-envars.html", "file": "libpq-envars.html", "label": "15.19 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "2744c085549e5c53c9cde2147b57b93387276297bb0f545bdf7838595878100d"}, {"url": "/docs/15/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "15.19 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "7081175cdd79775d0be65f2af8751f386ea5a006c3f185699be5f7bd1097321b"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/15/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span></dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "compiled_default_expression": "NULL"}, "comparison_hash": "2a8c30b93a66bbe5193882acb1cc8def71964ef9783d55a2df8a8594384133f7", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "16": {"facts": [{"label": "Client library", "value": "libpq 16.15"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/16/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/16/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/16/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/16/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "16.15", "major": "16", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/16/postgresql-16-A4.pdf", "bytes": 15282337, "pages": 3055, "sha256": "4bb6c1f63deedac98736d8c4c7bc0fad0ac24e85b07e21ee10411872f06afd06", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/16/postgresql-16-US.pdf", "bytes": 15164148, "pages": 3220, "sha256": "5b6b6166c89991199e144bb0ae34c17a5f29826251dbf19db1abc0df3a3e771b", "built_at": "2026-09-26"}}, "tree": "16", "index": "index.html", "major": "16", "pages": 1169, "release": "16.15", "source_url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "svg_assets": 3, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, "revision": "3c21e58b35318021716440e67bb8bafd392b6a2b965a244d90e9e33c99e0bdef", "evidence_kind": "English manual and source declarations", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, "sources": [{"url": "/docs/16/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "16.15 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "a88a6c8f0e2229b1e469ca3fcf95d6cba163af369f2c232c04c07ba0a5b64242"}, {"url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "16.15 libpq connection option declarations", "sha256": "ccc43473f7a01820f1ef625a8704548db03499bdee02ef943adbd1329f17f9e7", "archive_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, {"url": "/docs/16/libpq-envars.html", "file": "libpq-envars.html", "label": "16.15 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "2dd3190c2f6b9e0d3051b7cc325bb30dad84b29e53035680aa622409ad00fe28"}, {"url": "/docs/16/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "16.15 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "d636639599c1db7c0eb9da6c188abfbf7c590bb2ae9367e7fff05863bb9bd0db"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/16/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span> </dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n<p>The special value <code class=\"literal\">system</code> may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For <span class=\"productname\">OpenSSL</span> in particular, the locations may be further modified by the <code class=\"envar\">SSL_CERT_DIR</code> and <code class=\"envar\">SSL_CERT_FILE</code> environment variables.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When using <code class=\"literal\">sslrootcert=system</code>, the default <code class=\"literal\">sslmode</code> is changed to <code class=\"literal\">verify-full</code>, and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering <code class=\"literal\">verify-ca</code> and all weaker modes useless.</p>\n<p>The magic <code class=\"literal\">system</code> value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like <code class=\"literal\">sslrootcert=./system</code> instead.</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt . The special value system may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For OpenSSL in particular, the locations may be further modified by the SSL_CERT_DIR and SSL_CERT_FILE environment variables. Note When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless. The magic system value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like sslrootcert=./system instead.", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "compiled_default_expression": "NULL"}, "comparison_hash": "cfaf4586de024c51c1f0e01892077feddab5b492ce218160353456e11a6799e1", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "17": {"facts": [{"label": "Client library", "value": "libpq 17.11"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/17/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/17/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/17/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/17/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/17/postgresql-17-A4.pdf", "bytes": 15521293, "pages": 3099, "sha256": "1991354df0dc89e70ec39328c28988ef8b19c6a93671dab3893650b63e9f4e36", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/17/postgresql-17-US.pdf", "bytes": 15398150, "pages": 3270, "sha256": "07696c8f38abf31babf22d2db337093936e7c472d2af36d050b000c49bbcf52c", "built_at": "2026-09-26"}}, "tree": "17", "index": "index.html", "major": "17", "pages": 1143, "release": "17.11", "source_url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, "revision": "58419c9b0dd42cb34c8d53695bb025a7e582edf55ccd4c5bcb1c2c7c71a37487", "evidence_kind": "English manual and source declarations", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, "sources": [{"url": "/docs/17/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "17.11 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "7f15cf88e7854d7e92b57bdcb85ce566543eee5783ebc8eb2972cd6aaca8e7a1"}, {"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "17.11 libpq connection option declarations", "sha256": "9c189446b1b18faf81823636067c9cf9fb01215bdae5b036cc3bb0ebc84971a2", "archive_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "/docs/17/libpq-envars.html", "file": "libpq-envars.html", "label": "17.11 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "48fb76414267a67473ccb901e64320de2e73fb0dc8ade8fcea38edf3628d2c21"}, {"url": "/docs/17/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "17.11 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "1447c3836f348d6d0ea59ab68fe17ef604eb913938eed81c1e2cb081a36e2d8d"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/17/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span> </dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n<p>The special value <code class=\"literal\">system</code> may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For <span class=\"productname\">OpenSSL</span> in particular, the locations may be further modified by the <code class=\"envar\">SSL_CERT_DIR</code> and <code class=\"envar\">SSL_CERT_FILE</code> environment variables.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When using <code class=\"literal\">sslrootcert=system</code>, the default <code class=\"literal\">sslmode</code> is changed to <code class=\"literal\">verify-full</code>, and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering <code class=\"literal\">verify-ca</code> and all weaker modes useless.</p>\n<p>The magic <code class=\"literal\">system</code> value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like <code class=\"literal\">sslrootcert=./system</code> instead.</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt . The special value system may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For OpenSSL in particular, the locations may be further modified by the SSL_CERT_DIR and SSL_CERT_FILE environment variables. Note When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless. The magic system value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like sslrootcert=./system instead.", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "compiled_default_expression": "NULL"}, "comparison_hash": "cfaf4586de024c51c1f0e01892077feddab5b492ce218160353456e11a6799e1", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "18": {"facts": [{"label": "Client library", "value": "libpq 18.6"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/18/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/18/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/18/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/18/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/18/postgresql-18-A4.pdf", "bytes": 15865106, "pages": 3154, "sha256": "19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/18/postgresql-18-US.pdf", "bytes": 15748059, "pages": 3328, "sha256": "facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319", "built_at": "2026-09-26"}}, "tree": "18", "index": "index.html", "major": "18", "pages": 1148, "release": "18.6", "source_url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "revision": "ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8", "evidence_kind": "English manual and source declarations", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "sources": [{"url": "/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "18.6 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f"}, {"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "18.6 libpq connection option declarations", "sha256": "44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5", "archive_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/libpq-envars.html", "file": "libpq-envars.html", "label": "18.6 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363"}, {"url": "/docs/18/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "18.6 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/18/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span> </dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n<p>The special value <code class=\"literal\">system</code> may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For <span class=\"productname\">OpenSSL</span> in particular, the locations may be further modified by the <code class=\"envar\">SSL_CERT_DIR</code> and <code class=\"envar\">SSL_CERT_FILE</code> environment variables.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When using <code class=\"literal\">sslrootcert=system</code>, the default <code class=\"literal\">sslmode</code> is changed to <code class=\"literal\">verify-full</code>, and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering <code class=\"literal\">verify-ca</code> and all weaker modes useless.</p>\n<p>The magic <code class=\"literal\">system</code> value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like <code class=\"literal\">sslrootcert=./system</code> instead.</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt . The special value system may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For OpenSSL in particular, the locations may be further modified by the SSL_CERT_DIR and SSL_CERT_FILE environment variables. Note When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless. The magic system value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like sslrootcert=./system instead.", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "compiled_default_expression": "NULL"}, "comparison_hash": "cfaf4586de024c51c1f0e01892077feddab5b492ce218160353456e11a6799e1", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "19": {"facts": [{"label": "Client library", "value": "libpq 19beta4"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/19/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/19/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/19/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/19/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/19/postgresql-19-A4.pdf", "bytes": 16064841, "pages": 3052, "sha256": "4dd099e4125c591128fc5f3ebd02178dc24781f9e5ae629f96d67c4c8547427b", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/19/postgresql-19-US.pdf", "bytes": 15974616, "pages": 3225, "sha256": "61971fa857f0956d47341a0388fa6af9ae10acf691d4b2fc009007d384b0342b", "built_at": "2026-09-26"}}, "tree": "19", "index": "index.html", "major": "19", "pages": 1155, "release": "19beta4", "source_url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "svg_assets": 5, "source_mode": "en SGML built with pinned official archive", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, "revision": "1bbbbf4133d426f0e4304010688d2984c30fb67df0cc3a61b3e37eb3f6f37833", "evidence_kind": "English manual and source declarations", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, "sources": [{"url": "/docs/19/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "19beta4 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "14917417235a95d969bf3642c347dea7ae548c5f73b0dd00991a580ebcfbb47e"}, {"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "19beta4 libpq connection option declarations", "sha256": "ae8005372c570ff47a4922c942238653a034f01f9db40c9e0f57cb48915ffd98", "archive_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "/docs/19/libpq-envars.html", "file": "libpq-envars.html", "label": "19beta4 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d8f0afee19bae6323942ea5415649fbd66e3880fe8c8415350fcf3915f7c7047"}, {"url": "/docs/19/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "19beta4 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "4c858fe55701d703cc00e7adf55eeac09cafcfdc37929b8e23ccf8ba42af9f98"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/19/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span> </dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n<p>The special value <code class=\"literal\">system</code> may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For <span class=\"productname\">OpenSSL</span> in particular, the locations may be further modified by the <code class=\"envar\">SSL_CERT_DIR</code> and <code class=\"envar\">SSL_CERT_FILE</code> environment variables.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When using <code class=\"literal\">sslrootcert=system</code>, the default <code class=\"literal\">sslmode</code> is changed to <code class=\"literal\">verify-full</code>, and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering <code class=\"literal\">verify-ca</code> and all weaker modes useless.</p>\n<p>The magic <code class=\"literal\">system</code> value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like <code class=\"literal\">sslrootcert=./system</code> instead.</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt . The special value system may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For OpenSSL in particular, the locations may be further modified by the SSL_CERT_DIR and SSL_CERT_FILE environment variables. Note When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless. The magic system value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like sslrootcert=./system instead.", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "compiled_default_expression": "NULL"}, "comparison_hash": "cfaf4586de024c51c1f0e01892077feddab5b492ce218160353456e11a6799e1", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "20": {"facts": [{"label": "Client library", "value": "libpq 20devel"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/devel/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/devel/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/devel/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/devel/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/20/postgresql-20-A4.pdf", "bytes": 16030631, "pages": 3052, "sha256": "bd5d82c0ce38fc18f92a0447818a91a193a261776bca1c37564bf9a683e177d0", "built_at": "2026-09-28"}, "US": {"url": "/files/documentation/pdf/20/postgresql-20-US.pdf", "bytes": 15936613, "pages": 3223, "sha256": "d97d9e0db479a02f4234b175f50fcad70c3661619afc8d6df9b9437882e3c299", "built_at": "2026-09-28"}}, "tree": "0", "index": "index.html", "major": "20", "pages": 1156, "release": "20devel", "source_url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "svg_assets": 6, "source_mode": "en SGML built with pinned official archive", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_snapshot_utc": "26-Sep-2026 20:22"}, "revision": "2eba5e0fd4c3bffb2803247b6cd537878e9d6ee5a6dfbe3c50ece8b421b80918", "evidence_kind": "English manual and source declarations", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, "sources": [{"url": "/docs/devel/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "20devel English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "eeb28ce798c0f99c3581400b4baaae7687ee5d4176fcb9f5d2fd28809282d48f"}, {"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "20devel libpq connection option declarations", "sha256": "d6eab6e2f37054b32a7ee7039b53beae603316f8ec3f0a14716061e042fc4aa1", "archive_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "/docs/devel/libpq-envars.html", "file": "libpq-envars.html", "label": "20devel English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "7c49cf204e26ea86654491db5ea06c4f558c670e2e60a60b1dbf708ce682accc"}, {"url": "/docs/devel/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "20devel English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "a1ccd63a6e307a5541d58eabd57be5b467dff2480770838ec9b6a59a3ef110dc"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/devel/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span> </dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n<p>The special value <code class=\"literal\">system</code> may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For <span class=\"productname\">OpenSSL</span> in particular, the locations may be further modified by the <code class=\"envar\">SSL_CERT_DIR</code> and <code class=\"envar\">SSL_CERT_FILE</code> environment variables.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When using <code class=\"literal\">sslrootcert=system</code>, the default <code class=\"literal\">sslmode</code> is changed to <code class=\"literal\">verify-full</code>, and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering <code class=\"literal\">verify-ca</code> and all weaker modes useless.</p>\n<p>The magic <code class=\"literal\">system</code> value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like <code class=\"literal\">sslrootcert=./system</code> instead.</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt . The special value system may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For OpenSSL in particular, the locations may be further modified by the SSL_CERT_DIR and SSL_CERT_FILE environment variables. Note When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless. The magic system value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like sslrootcert=./system instead.", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "compiled_default_expression": "NULL"}, "comparison_hash": "cfaf4586de024c51c1f0e01892077feddab5b492ce218160353456e11a6799e1", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}}}, "snapshot": {"facts": [{"label": "Client library", "value": "libpq 18.6"}, {"label": "Manual definition", "value": "Documented"}, {"label": "Source environment fallback", "value": "PGSSLROOTCERT"}, {"label": "Compiled fallback expression", "value": "NULL"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/18/libpq-envars.html", "text": "PGSSLROOTCERT"}, "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "title": "Environment fallback", "columns": [{"key": "name", "label": "Variable"}, {"key": "description", "label": "Documented behavior"}]}], "keyword": "sslrootcert", "related": [{"url": "/docs/18/libpq-pgservice.html", "label": "Connection service file"}, {"url": "/docs/18/libpq-pgpass.html", "label": "Password file"}, {"url": "/docs/18/libpq-envars.html", "label": "All libpq environment variables"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/18/postgresql-18-A4.pdf", "bytes": 15865106, "pages": 3154, "sha256": "19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/18/postgresql-18-US.pdf", "bytes": 15748059, "pages": 3328, "sha256": "facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319", "built_at": "2026-09-26"}}, "tree": "18", "index": "index.html", "major": "18", "pages": 1148, "release": "18.6", "source_url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "revision": "ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8", "evidence_kind": "English manual and source declarations", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "sources": [{"url": "/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "file": "libpq-connect.html", "label": "18.6 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLROOTCERT", "sha256": "c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f"}, {"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "18.6 libpq connection option declarations", "sha256": "44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5", "archive_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "/docs/18/libpq-envars.html", "file": "libpq-envars.html", "label": "18.6 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363"}, {"url": "/docs/18/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "18.6 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7"}], "sections": [{"title": "Default resolution and service-file precedence", "paragraphs": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, {"title": "Environment variable evidence", "paragraphs": ["PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."]}], "signature": "sslrootcert", "documented": true, "description": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."], "environment": [{"name": "PGSSLROOTCERT", "source_url": "/docs/18/libpq-envars.html", "description": "PGSSLROOTCERT behaves the same as the sslrootcert connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLROOTCERT\"><span class=\"term\"><code class=\"literal\">sslrootcert</code></span> </dt><dd>\n<p>This parameter specifies the name of a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is <code class=\"filename\">~/.postgresql/root.crt</code>.</p>\n<p>The special value <code class=\"literal\">system</code> may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For <span class=\"productname\">OpenSSL</span> in particular, the locations may be further modified by the <code class=\"envar\">SSL_CERT_DIR</code> and <code class=\"envar\">SSL_CERT_FILE</code> environment variables.</p>\n<div class=\"note\">\n<h3 class=\"title\">Note</h3>\n<p>When using <code class=\"literal\">sslrootcert=system</code>, the default <code class=\"literal\">sslmode</code> is changed to <code class=\"literal\">verify-full</code>, and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering <code class=\"literal\">verify-ca</code> and all weaker modes useless.</p>\n<p>The magic <code class=\"literal\">system</code> value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like <code class=\"literal\">sslrootcert=./system</code> instead.</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT", "source_option": {"keyword": "sslrootcert", "declaration": "\"sslrootcert\", \"PGSSLROOTCERT\", NULL, NULL, \"SSL-Root-Certificate\", \"\", 64, offsetof(struct pg_conn, sslrootcert)", "environment": "PGSSLROOTCERT", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "sslrootcert", "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt . The special value system may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For OpenSSL in particular, the locations may be further modified by the SSL_CERT_DIR and SSL_CERT_FILE environment variables. Note When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless. The magic system value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like sslrootcert=./system instead.", "documented": true, "environment": "PGSSLROOTCERT", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "compiled_default_expression": "NULL"}, "comparison_hash": "cfaf4586de024c51c1f0e01892077feddab5b492ce218160353456e11a6799e1", "default_evidence": ["This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .", "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "comparison": {"left": "17", "right": "18", "status": "unchanged", "diff": ""}}