{"Entry":{"collection":"conn","key":"sslcertmode","name":"sslcertmode","aliases":["PGSSLCERTMODE","sslcertmode"],"metadata":{"aliases":["PGSSLCERTMODE","sslcertmode"],"category":"TLS","content_hash":"5e9918f7cf901f4522deaecdb8b315a03007df3152825df872acc543ff99ea29","imported_at":"2026-09-30T00:40:35.104012+08:00","name":"sslcertmode","name_zh":"","slug":"sslcertmode","summary":"This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:"}},"Definition":{"Collection":"conn","Key":"sslcertmode","SourceDatabase":"center","Version":"18","SourceTable":"connection_parameter","SourceKey":"sslcertmode","SourceRevision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","Facts":{"comparison_data":{"compiled_default_expression":"NULL","default_evidence":["A client certificate is never sent, even if one is available (default location or provided via sslcert )."],"definition":"This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes: disable A client certificate is never sent, even if one is available (default location or provided via sslcert ). allow (default) A certificate may be sent, if the server requests one and the client has one to send. require The server must request a certificate. The connection will fail if the client does not send a certificate and the server successfully authenticates the client anyway. Note sslcertmode=require doesn't add any additional security, since there is no guarantee that the server is validating the certificate correctly; PostgreSQL servers generally request TLS certificates from clients whether they validate them or not. The option may be useful when troubleshooting more complicated TLS setups.","documented":true,"environment":"PGSSLCERTMODE","keyword":"sslcertmode"},"comparison_hash":"f50d0868140d654ab2a45fb10a39e86a71d91b6d300ea34d3c28088537c8fdc5","default_evidence":["A client certificate is never sent, even if one is available (default location or provided via sslcert )."],"description":["This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:"],"documented":true,"environment":[{"description":"PGSSLCERTMODE behaves the same as the sslcertmode connection parameter.","name":"PGSSLCERTMODE","source_url":"/docs/18/libpq-envars.html"}],"facts":[{"label":"Client library","value":"libpq 18.6"},{"label":"Manual definition","value":"Documented"},{"label":"Source environment fallback","value":"PGSSLCERTMODE"},{"label":"Compiled fallback expression","value":"NULL"}],"keyword":"sslcertmode","manual_html":"\u003cdiv\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt id=\"LIBPQ-CONNECT-SSLCERTMODE\"\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003esslcertmode\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThis option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003edisable\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eA client certificate is never sent, even if one is available (default location or provided via \u003ca class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLCERT\"\u003esslcert\u003c/a\u003e).\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eallow\u003c/code\u003e (default)\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eA certificate may be sent, if the server requests one and the client has one to send.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003erequire\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eThe server \u003cspan class=\"emphasis\"\u003e\u003cem\u003emust\u003c/em\u003e\u003c/span\u003e request a certificate. The connection will fail if the client does not send a certificate and the server successfully authenticates the client anyway.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cdiv class=\"note\"\u003e\n\u003ch3 class=\"title\"\u003eNote\u003c/h3\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003esslcertmode=require\u003c/code\u003e doesn't add any additional security, since there is no guarantee that the server is validating the certificate correctly; PostgreSQL servers generally request TLS certificates from clients whether they validate them or not. The option may be useful when troubleshooting more complicated TLS setups.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","manual_path":"libpq-connect.html#LIBPQ-CONNECT-SSLCERTMODE","precedence_evidence":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"related":[{"label":"Connection service file","url":"/docs/18/libpq-pgservice.html"},{"label":"Password file","url":"/docs/18/libpq-pgpass.html"},{"label":"All libpq environment variables","url":"/docs/18/libpq-envars.html"}],"release":{"channel":"stable","evidence_kind":"English manual and source declarations","label":"18.6","major":"18","manifest":{"index":"index.html","major":"18","pages":1148,"pdf":{"A4":{"built_at":"2026-09-26","bytes":15865106,"pages":3154,"sha256":"19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190","url":"/files/documentation/pdf/18/postgresql-18-A4.pdf"},"US":{"built_at":"2026-09-26","bytes":15748059,"pages":3328,"sha256":"facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319","url":"/files/documentation/pdf/18/postgresql-18-US.pdf"}},"release":"18.6","source_mode":"en SGML built with pinned official archive","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","svg_assets":3,"tree":"18"},"ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sections":[{"paragraphs":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"title":"Default resolution and service-file precedence"},{"paragraphs":["PGSSLCERTMODE behaves the same as the sslcertmode connection parameter."],"title":"Environment variable evidence"}],"signature":"sslcertmode","source_option":{"compiled_default_expression":"NULL","declaration":"\"sslcertmode\", \"PGSSLCERTMODE\", NULL, NULL, \"SSL-Client-Cert-Mode\", \"\", 8, offsetof(struct pg_conn, sslcertmode)","environment":"PGSSLCERTMODE","keyword":"sslcertmode","source_notes":[]},"sources":[{"anchor":"LIBPQ-CONNECT-SSLCERTMODE","file":"libpq-connect.html","label":"18.6 English manual · libpq-connect.html","sha256":"c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f","url":"/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLCERTMODE"},{"archive_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","file":"src/interfaces/libpq/fe-connect.c","label":"18.6 libpq connection option declarations","sha256":"44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"anchor":"","file":"libpq-envars.html","label":"18.6 English manual · libpq-envars.html","sha256":"d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363","url":"/docs/18/libpq-envars.html"},{"anchor":"","file":"libpq-pgservice.html","label":"18.6 English manual · libpq-pgservice.html","sha256":"6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7","url":"/docs/18/libpq-pgservice.html"}],"tables":[{"columns":[{"key":"name","label":"Variable"},{"key":"description","label":"Documented behavior"}],"key":"environment","rows":[{"description":"PGSSLCERTMODE behaves the same as the sslcertmode connection parameter.","name":{"text":"PGSSLCERTMODE","url":"/docs/18/libpq-envars.html"}}],"title":"Environment fallback"}]},"ManualEvidence":{"manual_path":"libpq-connect.html#LIBPQ-CONNECT-SSLCERTMODE","release":{"channel":"stable","evidence_kind":"English manual and source declarations","label":"18.6","major":"18","manifest":{"index":"index.html","major":"18","pages":1148,"pdf":{"A4":{"built_at":"2026-09-26","bytes":15865106,"pages":3154,"sha256":"19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190","url":"/files/documentation/pdf/18/postgresql-18-A4.pdf"},"US":{"built_at":"2026-09-26","bytes":15748059,"pages":3328,"sha256":"facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319","url":"/files/documentation/pdf/18/postgresql-18-US.pdf"}},"release":"18.6","source_mode":"en SGML built with pinned official archive","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","svg_assets":3,"tree":"18"},"ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sources":[{"anchor":"LIBPQ-CONNECT-SSLCERTMODE","file":"libpq-connect.html","label":"18.6 English manual · libpq-connect.html","sha256":"c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f","url":"/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLCERTMODE"},{"archive_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","file":"src/interfaces/libpq/fe-connect.c","label":"18.6 libpq connection option declarations","sha256":"44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"anchor":"","file":"libpq-envars.html","label":"18.6 English manual · libpq-envars.html","sha256":"d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363","url":"/docs/18/libpq-envars.html"},{"anchor":"","file":"libpq-pgservice.html","label":"18.6 English manual · libpq-pgservice.html","sha256":"6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7","url":"/docs/18/libpq-pgservice.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"conn","Key":"sslcertmode","SourceDatabase":"center","Version":"18","Locale":"en","Title":"sslcertmode","Summary":"This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:","BodyHTML":"\u003cdiv\u003e\u003cdl\u003e\u003cdt id=\"LIBPQ-CONNECT-SSLCERTMODE\"\u003e\u003cspan\u003e\u003ccode\u003esslcertmode\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThis option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:\u003c/p\u003e\n\u003cdiv\u003e\n\u003cdl\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003edisable\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eA client certificate is never sent, even if one is available (default location or provided via \u003ca href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLCERT\" rel=\"nofollow\"\u003esslcert\u003c/a\u003e).\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eallow\u003c/code\u003e (default)\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eA certificate may be sent, if the server requests one and the client has one to send.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003erequire\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eThe server \u003cspan\u003e\u003cem\u003emust\u003c/em\u003e\u003c/span\u003e request a certificate. The connection will fail if the client does not send a certificate and the server successfully authenticates the client anyway.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cdiv\u003e\n\u003ch3\u003eNote\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003esslcertmode=require\u003c/code\u003e doesn\u0026#39;t add any additional security, since there is no guarantee that the server is validating the certificate correctly; PostgreSQL servers generally request TLS certificates from clients whether they validate them or not. The option may be useful when troubleshooting more complicated TLS setups.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","SourceRevision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","ContentHash":"49dce41452c57e2134e1db88b80466d3e18f7daff5aa0746a250ee6e71dc29f0","Payload":{"description":["This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:"],"manual_html":"\u003cdiv\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt id=\"LIBPQ-CONNECT-SSLCERTMODE\"\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003esslcertmode\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThis option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003edisable\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eA client certificate is never sent, even if one is available (default location or provided via \u003ca class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLCERT\"\u003esslcert\u003c/a\u003e).\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eallow\u003c/code\u003e (default)\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eA certificate may be sent, if the server requests one and the client has one to send.\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003erequire\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eThe server \u003cspan class=\"emphasis\"\u003e\u003cem\u003emust\u003c/em\u003e\u003c/span\u003e request a certificate. The connection will fail if the client does not send a certificate and the server successfully authenticates the client anyway.\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cdiv class=\"note\"\u003e\n\u003ch3 class=\"title\"\u003eNote\u003c/h3\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003esslcertmode=require\u003c/code\u003e doesn't add any additional security, since there is no guarantee that the server is validating the certificate correctly; PostgreSQL servers generally request TLS certificates from clients whether they validate them or not. The option may be useful when troubleshooting more complicated TLS setups.\u003c/p\u003e\n\u003c/div\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","related":[{"label":"Connection service file","url":"/docs/18/libpq-pgservice.html"},{"label":"Password file","url":"/docs/18/libpq-pgpass.html"},{"label":"All libpq environment variables","url":"/docs/18/libpq-envars.html"}],"sections":[{"paragraphs":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"title":"Default resolution and service-file precedence"},{"paragraphs":["PGSSLCERTMODE behaves the same as the sslcertmode connection parameter."],"title":"Environment variable evidence"}],"tables":[{"columns":[{"key":"name","label":"Variable"},{"key":"description","label":"Documented behavior"}],"key":"environment","rows":[{"description":"PGSSLCERTMODE behaves the same as the sslcertmode connection parameter.","name":{"text":"PGSSLCERTMODE","url":"/docs/18/libpq-envars.html"}}],"title":"Environment fallback"}]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
