sslcertmode
This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:
当前阅读 PG 18·选择有来源记录的版本
此版本暂无所选语言的定义,以下显示原始英文内容。
- Client library
- libpq 18.6
- Manual definition
- Documented
- Source environment fallback
- PGSSLCERTMODE
- Compiled fallback expression
- NULL
- default evidence
- A client certificate is never sent, even if one is available (default location or provided via sslcert ).
- documented
- true
- environment
- map[description:PGSSLCERTMODE behaves the same as the sslcertmode connection parameter. name:PGSSLCERTMODE source_url:/docs/18/libpq-envars.html]
- keyword
- sslcertmode
- manual path
- libpq-connect.html#LIBPQ-CONNECT-SSLCERTMODE
- signature
- sslcertmode
版本定义 PG 18
sslcertmode-
This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:
disable-
A client certificate is never sent, even if one is available (default location or provided via sslcert).
allow(default)-
A certificate may be sent, if the server requests one and the client has one to send.
require-
The server must request a certificate. The connection will fail if the client does not send a certificate and the server successfully authenticates the client anyway.
Note
sslcertmode=requiredoesn't add any additional security, since there is no guarantee that the server is validating the certificate correctly; PostgreSQL servers generally request TLS certificates from clients whether they validate them or not. The option may be useful when troubleshooting more complicated TLS setups.
Environment fallback
| Variable | Documented behavior |
|---|---|
| PGSSLCERTMODE | PGSSLCERTMODE behaves the same as the sslcertmode connection parameter. |
比较版本
完整来源事实
precedence evidence
The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example., Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\postgresql\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR ., Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.
source option
{"compiled_default_expression":"NULL","declaration":"\"sslcertmode\", \"PGSSLCERTMODE\", NULL, NULL, \"SSL-Client-Cert-Mode\", \"\", 8, offsetof(struct pg_conn, sslcertmode)","environment":"PGSSLCERTMODE","keyword":"sslcertmode","source_notes":[]}来源引用
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
- 固定 PostgreSQL 源码归档
定义来源
center · PostgreSQL 18 · ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
正文语言: en · ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8