sslnegotiation
This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.
当前阅读 PG 18·选择有来源记录的版本
此版本暂无所选语言的定义,以下显示原始英文内容。
- Client library
- libpq 18.6
- Manual definition
- Documented
- Source environment fallback
- PGSSLNEGOTIATION
- Compiled fallback expression
- DefaultSSLNegotiation
- documented
- true
- environment
- map[description:PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter. name:PGSSLNEGOTIATION source_url:/docs/18/libpq-envars.html]
- keyword
- sslnegotiation
- manual path
- libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION
- signature
- sslnegotiation
版本定义 PG 18
sslnegotiation-
This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default
postgresmode, the client first asks the server if SSL is supported. Indirectmode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.postgres-
perform PostgreSQL protocol negotiation. This is the default if the option is not provided.
direct-
start SSL handshake directly after establishing the TCP/IP connection. This is only allowed with
sslmode=requireor higher, because the weaker settings could lead to unintended fallback to plaintext authentication when the server does not support direct SSL handshake.
Environment fallback
| Variable | Documented behavior |
|---|---|
| PGSSLNEGOTIATION | PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter. |
比较版本
完整来源事实
default evidence
This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17., perform PostgreSQL protocol negotiation. This is the default if the option is not provided.
precedence evidence
The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example., Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\postgresql\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR ., Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.
source option
{"compiled_default_expression":"DefaultSSLNegotiation","declaration":"\"sslnegotiation\", \"PGSSLNEGOTIATION\", DefaultSSLNegotiation, NULL, \"SSL-Negotiation\", \"\", 9, offsetof(struct pg_conn, sslnegotiation)","environment":"PGSSLNEGOTIATION","keyword":"sslnegotiation","source_notes":[]}来源引用
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
- 固定 PostgreSQL 源码归档
定义来源
center · PostgreSQL 18 · ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
正文语言: en · ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8