{"Entry":{"collection":"conn","key":"sslmode","name":"sslmode","aliases":["PGSSLMODE","sslmode"],"metadata":{"aliases":["PGSSLMODE","sslmode"],"category":"TLS","content_hash":"e20ad76c6d164a60d2dc81fc43c3b73a08a7505639546fef1a90022550474642","imported_at":"2026-09-30T00:40:35.142013+08:00","name":"sslmode","name_zh":"","slug":"sslmode","summary":"This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:"}},"Definition":{"Collection":"conn","Key":"sslmode","SourceDatabase":"center","Version":"18","SourceTable":"connection_parameter","SourceKey":"sslmode","SourceRevision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","Facts":{"comparison_data":{"compiled_default_expression":"DefaultSSLMode","default_evidence":[],"definition":"This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 32.19 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .","documented":true,"environment":"PGSSLMODE","keyword":"sslmode"},"comparison_hash":"8cee88b057502e1ab1559e9a8b0b8bdc555df07335cf7edfdd1c462963812a19","default_evidence":[],"description":["This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:"],"documented":true,"environment":[{"description":"PGSSLMODE behaves the same as the sslmode connection parameter.","name":"PGSSLMODE","source_url":"/docs/18/libpq-envars.html"}],"facts":[{"label":"Client library","value":"libpq 18.6"},{"label":"Manual definition","value":"Documented"},{"label":"Source environment fallback","value":"PGSSLMODE"},{"label":"Compiled fallback expression","value":"DefaultSSLMode"}],"keyword":"sslmode","manual_html":"\u003cdiv\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt id=\"LIBPQ-CONNECT-SSLMODE\"\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003esslmode\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThis option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003edisable\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try a non-SSL connection\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eallow\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003efirst try a non-SSL connection; if that fails, try an SSL connection\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eprefer\u003c/code\u003e (default)\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003efirst try an SSL connection; if that fails, try a non-SSL connection\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003erequire\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try an SSL connection. If a root CA file is present, verify the certificate in the same way as if \u003ccode class=\"literal\"\u003everify-ca\u003c/code\u003e was specified\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003everify-ca\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority (CA)\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003everify-full\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eSee \u003ca class=\"xref\" href=\"/docs/18/libpq-ssl.html\" title=\"32.19. SSL Support\"\u003eSection 32.19\u003c/a\u003e for a detailed description of how these options work.\u003c/p\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003esslmode\u003c/code\u003e is ignored for Unix domain socket communication. If \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e is compiled without SSL support, using options \u003ccode class=\"literal\"\u003erequire\u003c/code\u003e, \u003ccode class=\"literal\"\u003everify-ca\u003c/code\u003e, or \u003ccode class=\"literal\"\u003everify-full\u003c/code\u003e will cause an error, while options \u003ccode class=\"literal\"\u003eallow\u003c/code\u003e and \u003ccode class=\"literal\"\u003eprefer\u003c/code\u003e will be accepted but \u003cspan class=\"application\"\u003elibpq\u003c/span\u003e will not actually attempt an SSL connection.\u003c/p\u003e\n\u003cp\u003eNote that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of \u003ccode class=\"literal\"\u003esslmode\u003c/code\u003e. To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set \u003ccode class=\"literal\"\u003egssencmode\u003c/code\u003e to \u003ccode class=\"literal\"\u003edisable\u003c/code\u003e.\u003c/p\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","manual_path":"libpq-connect.html#LIBPQ-CONNECT-SSLMODE","precedence_evidence":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"related":[{"label":"Connection service file","url":"/docs/18/libpq-pgservice.html"},{"label":"Password file","url":"/docs/18/libpq-pgpass.html"},{"label":"All libpq environment variables","url":"/docs/18/libpq-envars.html"}],"release":{"channel":"stable","evidence_kind":"English manual and source declarations","label":"18.6","major":"18","manifest":{"index":"index.html","major":"18","pages":1148,"pdf":{"A4":{"built_at":"2026-09-26","bytes":15865106,"pages":3154,"sha256":"19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190","url":"/files/documentation/pdf/18/postgresql-18-A4.pdf"},"US":{"built_at":"2026-09-26","bytes":15748059,"pages":3328,"sha256":"facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319","url":"/files/documentation/pdf/18/postgresql-18-US.pdf"}},"release":"18.6","source_mode":"en SGML built with pinned official archive","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","svg_assets":3,"tree":"18"},"ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sections":[{"paragraphs":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"title":"Default resolution and service-file precedence"},{"paragraphs":["PGSSLMODE behaves the same as the sslmode connection parameter."],"title":"Environment variable evidence"}],"signature":"sslmode","source_option":{"compiled_default_expression":"DefaultSSLMode","declaration":"\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)","environment":"PGSSLMODE","keyword":"sslmode","source_notes":[]},"sources":[{"anchor":"LIBPQ-CONNECT-SSLMODE","file":"libpq-connect.html","label":"18.6 English manual · libpq-connect.html","sha256":"c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f","url":"/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"},{"archive_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","file":"src/interfaces/libpq/fe-connect.c","label":"18.6 libpq connection option declarations","sha256":"44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"anchor":"","file":"libpq-envars.html","label":"18.6 English manual · libpq-envars.html","sha256":"d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363","url":"/docs/18/libpq-envars.html"},{"anchor":"","file":"libpq-pgservice.html","label":"18.6 English manual · libpq-pgservice.html","sha256":"6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7","url":"/docs/18/libpq-pgservice.html"}],"tables":[{"columns":[{"key":"name","label":"Variable"},{"key":"description","label":"Documented behavior"}],"key":"environment","rows":[{"description":"PGSSLMODE behaves the same as the sslmode connection parameter.","name":{"text":"PGSSLMODE","url":"/docs/18/libpq-envars.html"}}],"title":"Environment fallback"}]},"ManualEvidence":{"manual_path":"libpq-connect.html#LIBPQ-CONNECT-SSLMODE","release":{"channel":"stable","evidence_kind":"English manual and source declarations","label":"18.6","major":"18","manifest":{"index":"index.html","major":"18","pages":1148,"pdf":{"A4":{"built_at":"2026-09-26","bytes":15865106,"pages":3154,"sha256":"19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190","url":"/files/documentation/pdf/18/postgresql-18-A4.pdf"},"US":{"built_at":"2026-09-26","bytes":15748059,"pages":3328,"sha256":"facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319","url":"/files/documentation/pdf/18/postgresql-18-US.pdf"}},"release":"18.6","source_mode":"en SGML built with pinned official archive","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","svg_assets":3,"tree":"18"},"ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sources":[{"anchor":"LIBPQ-CONNECT-SSLMODE","file":"libpq-connect.html","label":"18.6 English manual · libpq-connect.html","sha256":"c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f","url":"/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"},{"archive_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","file":"src/interfaces/libpq/fe-connect.c","label":"18.6 libpq connection option declarations","sha256":"44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"anchor":"","file":"libpq-envars.html","label":"18.6 English manual · libpq-envars.html","sha256":"d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363","url":"/docs/18/libpq-envars.html"},{"anchor":"","file":"libpq-pgservice.html","label":"18.6 English manual · libpq-pgservice.html","sha256":"6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7","url":"/docs/18/libpq-pgservice.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"conn","Key":"sslmode","SourceDatabase":"center","Version":"18","Locale":"en","Title":"sslmode","Summary":"This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:","BodyHTML":"\u003cdiv\u003e\u003cdl\u003e\u003cdt id=\"LIBPQ-CONNECT-SSLMODE\"\u003e\u003cspan\u003e\u003ccode\u003esslmode\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThis option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:\u003c/p\u003e\n\u003cdiv\u003e\n\u003cdl\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003edisable\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try a non-SSL connection\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eallow\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003efirst try a non-SSL connection; if that fails, try an SSL connection\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003eprefer\u003c/code\u003e (default)\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003efirst try an SSL connection; if that fails, try a non-SSL connection\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003erequire\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try an SSL connection. If a root CA file is present, verify the certificate in the same way as if \u003ccode\u003everify-ca\u003c/code\u003e was specified\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003everify-ca\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority (CA)\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan\u003e\u003ccode\u003everify-full\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eSee \u003ca href=\"/docs/18/libpq-ssl.html\" rel=\"nofollow\"\u003eSection 32.19\u003c/a\u003e for a detailed description of how these options work.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003esslmode\u003c/code\u003e is ignored for Unix domain socket communication. If \u003cspan\u003ePostgreSQL\u003c/span\u003e is compiled without SSL support, using options \u003ccode\u003erequire\u003c/code\u003e, \u003ccode\u003everify-ca\u003c/code\u003e, or \u003ccode\u003everify-full\u003c/code\u003e will cause an error, while options \u003ccode\u003eallow\u003c/code\u003e and \u003ccode\u003eprefer\u003c/code\u003e will be accepted but \u003cspan\u003elibpq\u003c/span\u003e will not actually attempt an SSL connection.\u003c/p\u003e\n\u003cp\u003eNote that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of \u003ccode\u003esslmode\u003c/code\u003e. To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set \u003ccode\u003egssencmode\u003c/code\u003e to \u003ccode\u003edisable\u003c/code\u003e.\u003c/p\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","SourceRevision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","ContentHash":"62241944c2e5c4d413e82fafc9c04c642fcd041b577106ee3ff70dbc8e9d2a90","Payload":{"description":["This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:"],"manual_html":"\u003cdiv\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt id=\"LIBPQ-CONNECT-SSLMODE\"\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003esslmode\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThis option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:\u003c/p\u003e\n\u003cdiv class=\"variablelist\"\u003e\n\u003cdl class=\"variablelist\"\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003edisable\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try a non-SSL connection\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eallow\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003efirst try a non-SSL connection; if that fails, try an SSL connection\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003eprefer\u003c/code\u003e (default)\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003efirst try an SSL connection; if that fails, try a non-SSL connection\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003erequire\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try an SSL connection. If a root CA file is present, verify the certificate in the same way as if \u003ccode class=\"literal\"\u003everify-ca\u003c/code\u003e was specified\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003everify-ca\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority (CA)\u003c/p\u003e\n\u003c/dd\u003e\n\u003cdt\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003everify-full\u003c/code\u003e\u003c/span\u003e\u003c/dt\u003e\n\u003cdd\u003e\n\u003cp\u003eonly try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate\u003c/p\u003e\n\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/div\u003e\n\u003cp\u003eSee \u003ca class=\"xref\" href=\"/docs/18/libpq-ssl.html\" title=\"32.19. SSL Support\"\u003eSection 32.19\u003c/a\u003e for a detailed description of how these options work.\u003c/p\u003e\n\u003cp\u003e\u003ccode class=\"literal\"\u003esslmode\u003c/code\u003e is ignored for Unix domain socket communication. If \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e is compiled without SSL support, using options \u003ccode class=\"literal\"\u003erequire\u003c/code\u003e, \u003ccode class=\"literal\"\u003everify-ca\u003c/code\u003e, or \u003ccode class=\"literal\"\u003everify-full\u003c/code\u003e will cause an error, while options \u003ccode class=\"literal\"\u003eallow\u003c/code\u003e and \u003ccode class=\"literal\"\u003eprefer\u003c/code\u003e will be accepted but \u003cspan class=\"application\"\u003elibpq\u003c/span\u003e will not actually attempt an SSL connection.\u003c/p\u003e\n\u003cp\u003eNote that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of \u003ccode class=\"literal\"\u003esslmode\u003c/code\u003e. To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set \u003ccode class=\"literal\"\u003egssencmode\u003c/code\u003e to \u003ccode class=\"literal\"\u003edisable\u003c/code\u003e.\u003c/p\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","related":[{"label":"Connection service file","url":"/docs/18/libpq-pgservice.html"},{"label":"Password file","url":"/docs/18/libpq-pgpass.html"},{"label":"All libpq environment variables","url":"/docs/18/libpq-envars.html"}],"sections":[{"paragraphs":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"title":"Default resolution and service-file precedence"},{"paragraphs":["PGSSLMODE behaves the same as the sslmode connection parameter."],"title":"Environment variable evidence"}],"tables":[{"columns":[{"key":"name","label":"Variable"},{"key":"description","label":"Documented behavior"}],"key":"environment","rows":[{"description":"PGSSLMODE behaves the same as the sslmode connection parameter.","name":{"text":"PGSSLMODE","url":"/docs/18/libpq-envars.html"}}],"title":"Environment fallback"}]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
