{"Entry":{"collection":"conn","key":"oauth-ca-file","name":"oauth_ca_file","aliases":["PGOAUTHCAFILE","oauth_ca_file"],"metadata":{"aliases":["PGOAUTHCAFILE","oauth_ca_file"],"category":"Authentication","content_hash":"b4ab75db876333abbd7e3f89b1cd1d1bfacb716949943d0ea1ad63926f41bf90","imported_at":"2026-09-30T00:40:34.979381+08:00","name":"oauth_ca_file","name_zh":"","slug":"oauth-ca-file","summary":"The name of a file containing one or more SSL certificate authority ( CA ) certificates, which will be used to verify the identity of the authorization server and its endpoints. By default, the Curl system certificate bundle is used."}},"Definition":{"Collection":"conn","Key":"oauth-ca-file","SourceDatabase":"center","Version":"20","SourceTable":"connection_parameter","SourceKey":"oauth-ca-file","SourceRevision":"2eba5e0fd4c3bffb2803247b6cd537878e9d6ee5a6dfbe3c50ece8b421b80918","Facts":{"comparison_data":{"compiled_default_expression":"NULL","default_evidence":["The name of a file containing one or more SSL certificate authority ( CA ) certificates, which will be used to verify the identity of the authorization server and its endpoints. By default, the Curl system certificate bundle is used."],"definition":"The name of a file containing one or more SSL certificate authority ( CA ) certificates, which will be used to verify the identity of the authorization server and its endpoints. By default, the Curl system certificate bundle is used. This parameter does not affect verification of the PostgreSQL server certificate; see sslrootcert instead.","documented":true,"environment":"PGOAUTHCAFILE","keyword":"oauth_ca_file"},"comparison_hash":"210f735d3fb6060bce3d46d96f14edd4a4d5f8da8feb86268495b267a9307444","default_evidence":["The name of a file containing one or more SSL certificate authority ( CA ) certificates, which will be used to verify the identity of the authorization server and its endpoints. By default, the Curl system certificate bundle is used."],"description":["The name of a file containing one or more SSL certificate authority ( CA ) certificates, which will be used to verify the identity of the authorization server and its endpoints. By default, the Curl system certificate bundle is used."],"documented":true,"environment":[{"description":"PGOAUTHCAFILE behaves the same as the oauth_ca_file connection parameter.","name":"PGOAUTHCAFILE","source_url":"/docs/devel/libpq-envars.html"}],"facts":[{"label":"Client library","value":"libpq 20devel"},{"label":"Manual definition","value":"Documented"},{"label":"Source environment fallback","value":"PGOAUTHCAFILE"},{"label":"Compiled fallback expression","value":"NULL"}],"keyword":"oauth_ca_file","manual_html":"\u003cdiv\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt id=\"LIBPQ-CONNECT-OAUTH-CA-FILE\"\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eoauth_ca_file\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThe name of a file containing one or more SSL certificate authority (CA) certificates, which will be used to verify the identity of the authorization server and its endpoints. By default, the \u003cspan class=\"productname\"\u003eCurl\u003c/span\u003e system certificate bundle is used.\u003c/p\u003e\n\u003cp\u003eThis parameter does not affect verification of the \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e server certificate; see \u003ca class=\"xref\" href=\"/docs/devel/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT\"\u003esslrootcert\u003c/a\u003e instead.\u003c/p\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","manual_path":"libpq-connect.html#LIBPQ-CONNECT-OAUTH-CA-FILE","precedence_evidence":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"related":[{"label":"Connection service file","url":"/docs/devel/libpq-pgservice.html"},{"label":"Password file","url":"/docs/devel/libpq-pgpass.html"},{"label":"All libpq environment variables","url":"/docs/devel/libpq-envars.html"}],"release":{"channel":"devel","evidence_kind":"English manual and source declarations","label":"20devel","major":"20","manifest":{"index":"index.html","major":"20","pages":1156,"pdf":{"A4":{"built_at":"2026-09-28","bytes":16030631,"pages":3052,"sha256":"bd5d82c0ce38fc18f92a0447818a91a193a261776bca1c37564bf9a683e177d0","url":"/files/documentation/pdf/20/postgresql-20-A4.pdf"},"US":{"built_at":"2026-09-28","bytes":15936613,"pages":3223,"sha256":"d97d9e0db479a02f4234b175f50fcad70c3661619afc8d6df9b9437882e3c299","url":"/files/documentation/pdf/20/postgresql-20-US.pdf"}},"release":"20devel","source_mode":"en SGML built with pinned official archive","source_sha256":"4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41","source_snapshot_utc":"26-Sep-2026 20:22","source_url":"https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2","svg_assets":6,"tree":"0"},"ref":"https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2","revision":"2eba5e0fd4c3bffb2803247b6cd537878e9d6ee5a6dfbe3c50ece8b421b80918","source_sha256":"4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"},"sections":[{"paragraphs":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"title":"Default resolution and service-file precedence"},{"paragraphs":["PGOAUTHCAFILE behaves the same as the oauth_ca_file connection parameter."],"title":"Environment variable evidence"}],"signature":"oauth_ca_file","source_option":{"compiled_default_expression":"NULL","declaration":"\"oauth_ca_file\", \"PGOAUTHCAFILE\", NULL, NULL, \"OAuth-CA-File\", \"\", 64, offsetof(struct pg_conn, oauth_ca_file)","environment":"PGOAUTHCAFILE","keyword":"oauth_ca_file","source_notes":[]},"sources":[{"anchor":"LIBPQ-CONNECT-OAUTH-CA-FILE","file":"libpq-connect.html","label":"20devel English manual · libpq-connect.html","sha256":"eeb28ce798c0f99c3581400b4baaae7687ee5d4176fcb9f5d2fd28809282d48f","url":"/docs/devel/libpq-connect.html#LIBPQ-CONNECT-OAUTH-CA-FILE"},{"archive_sha256":"4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41","file":"src/interfaces/libpq/fe-connect.c","label":"20devel libpq connection option declarations","sha256":"d6eab6e2f37054b32a7ee7039b53beae603316f8ec3f0a14716061e042fc4aa1","url":"https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2"},{"anchor":"","file":"libpq-envars.html","label":"20devel English manual · libpq-envars.html","sha256":"7c49cf204e26ea86654491db5ea06c4f558c670e2e60a60b1dbf708ce682accc","url":"/docs/devel/libpq-envars.html"},{"anchor":"","file":"libpq-pgservice.html","label":"20devel English manual · libpq-pgservice.html","sha256":"a1ccd63a6e307a5541d58eabd57be5b467dff2480770838ec9b6a59a3ef110dc","url":"/docs/devel/libpq-pgservice.html"}],"tables":[{"columns":[{"key":"name","label":"Variable"},{"key":"description","label":"Documented behavior"}],"key":"environment","rows":[{"description":"PGOAUTHCAFILE behaves the same as the oauth_ca_file connection parameter.","name":{"text":"PGOAUTHCAFILE","url":"/docs/devel/libpq-envars.html"}}],"title":"Environment fallback"}]},"ManualEvidence":{"manual_path":"libpq-connect.html#LIBPQ-CONNECT-OAUTH-CA-FILE","release":{"channel":"devel","evidence_kind":"English manual and source declarations","label":"20devel","major":"20","manifest":{"index":"index.html","major":"20","pages":1156,"pdf":{"A4":{"built_at":"2026-09-28","bytes":16030631,"pages":3052,"sha256":"bd5d82c0ce38fc18f92a0447818a91a193a261776bca1c37564bf9a683e177d0","url":"/files/documentation/pdf/20/postgresql-20-A4.pdf"},"US":{"built_at":"2026-09-28","bytes":15936613,"pages":3223,"sha256":"d97d9e0db479a02f4234b175f50fcad70c3661619afc8d6df9b9437882e3c299","url":"/files/documentation/pdf/20/postgresql-20-US.pdf"}},"release":"20devel","source_mode":"en SGML built with pinned official archive","source_sha256":"4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41","source_snapshot_utc":"26-Sep-2026 20:22","source_url":"https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2","svg_assets":6,"tree":"0"},"ref":"https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2","revision":"2eba5e0fd4c3bffb2803247b6cd537878e9d6ee5a6dfbe3c50ece8b421b80918","source_sha256":"4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"},"sources":[{"anchor":"LIBPQ-CONNECT-OAUTH-CA-FILE","file":"libpq-connect.html","label":"20devel English manual · libpq-connect.html","sha256":"eeb28ce798c0f99c3581400b4baaae7687ee5d4176fcb9f5d2fd28809282d48f","url":"/docs/devel/libpq-connect.html#LIBPQ-CONNECT-OAUTH-CA-FILE"},{"archive_sha256":"4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41","file":"src/interfaces/libpq/fe-connect.c","label":"20devel libpq connection option declarations","sha256":"d6eab6e2f37054b32a7ee7039b53beae603316f8ec3f0a14716061e042fc4aa1","url":"https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2"},{"anchor":"","file":"libpq-envars.html","label":"20devel English manual · libpq-envars.html","sha256":"7c49cf204e26ea86654491db5ea06c4f558c670e2e60a60b1dbf708ce682accc","url":"/docs/devel/libpq-envars.html"},{"anchor":"","file":"libpq-pgservice.html","label":"20devel English manual · libpq-pgservice.html","sha256":"a1ccd63a6e307a5541d58eabd57be5b467dff2480770838ec9b6a59a3ef110dc","url":"/docs/devel/libpq-pgservice.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"conn","Key":"oauth-ca-file","SourceDatabase":"center","Version":"20","Locale":"en","Title":"oauth_ca_file","Summary":"The name of a file containing one or more SSL certificate authority ( CA ) certificates, which will be used to verify the identity of the authorization server and its endpoints. By default, the Curl system certificate bundle is used.","BodyHTML":"\u003cdiv\u003e\u003cdl\u003e\u003cdt id=\"LIBPQ-CONNECT-OAUTH-CA-FILE\"\u003e\u003cspan\u003e\u003ccode\u003eoauth_ca_file\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThe name of a file containing one or more SSL certificate authority (CA) certificates, which will be used to verify the identity of the authorization server and its endpoints. By default, the \u003cspan\u003eCurl\u003c/span\u003e system certificate bundle is used.\u003c/p\u003e\n\u003cp\u003eThis parameter does not affect verification of the \u003cspan\u003ePostgreSQL\u003c/span\u003e server certificate; see \u003ca href=\"/docs/devel/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT\" rel=\"nofollow\"\u003esslrootcert\u003c/a\u003e instead.\u003c/p\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","SourceRevision":"2eba5e0fd4c3bffb2803247b6cd537878e9d6ee5a6dfbe3c50ece8b421b80918","ContentHash":"c8d845e0be72a0c67f129d9d3eb4d71eee93a1a4dd14d56b03f9193f35163f26","Payload":{"description":["The name of a file containing one or more SSL certificate authority ( CA ) certificates, which will be used to verify the identity of the authorization server and its endpoints. By default, the Curl system certificate bundle is used."],"manual_html":"\u003cdiv\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt id=\"LIBPQ-CONNECT-OAUTH-CA-FILE\"\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eoauth_ca_file\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThe name of a file containing one or more SSL certificate authority (CA) certificates, which will be used to verify the identity of the authorization server and its endpoints. By default, the \u003cspan class=\"productname\"\u003eCurl\u003c/span\u003e system certificate bundle is used.\u003c/p\u003e\n\u003cp\u003eThis parameter does not affect verification of the \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e server certificate; see \u003ca class=\"xref\" href=\"/docs/devel/libpq-connect.html#LIBPQ-CONNECT-SSLROOTCERT\"\u003esslrootcert\u003c/a\u003e instead.\u003c/p\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","related":[{"label":"Connection service file","url":"/docs/devel/libpq-pgservice.html"},{"label":"Password file","url":"/docs/devel/libpq-pgpass.html"},{"label":"All libpq environment variables","url":"/docs/devel/libpq-envars.html"}],"sections":[{"paragraphs":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"title":"Default resolution and service-file precedence"},{"paragraphs":["PGOAUTHCAFILE behaves the same as the oauth_ca_file connection parameter."],"title":"Environment variable evidence"}],"tables":[{"columns":[{"key":"name","label":"Variable"},{"key":"description","label":"Documented behavior"}],"key":"environment","rows":[{"description":"PGOAUTHCAFILE behaves the same as the oauth_ca_file connection parameter.","name":{"text":"PGOAUTHCAFILE","url":"/docs/devel/libpq-envars.html"}}],"title":"Environment fallback"}]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
