{"Entry":{"collection":"conn","key":"sslpassword","name":"sslpassword","aliases":["sslpassword"],"metadata":{"aliases":["sslpassword"],"category":"TLS","content_hash":"e89c2840ba632aa572144528454e792a697fa2526b32b2e5412f3e127ae8b97d","imported_at":"2026-09-30T00:40:35.155702+08:00","name":"sslpassword","name_zh":"","slug":"sslpassword","summary":"This parameter specifies the password for the secret key specified in sslkey , allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical."}},"Definition":{"Collection":"conn","Key":"sslpassword","SourceDatabase":"center","Version":"18","SourceTable":"connection_parameter","SourceKey":"sslpassword","SourceRevision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","Facts":{"comparison_data":{"compiled_default_expression":"NULL","default_evidence":["Specifying this parameter with any non-empty value suppresses the Enter PEM pass phrase: prompt that OpenSSL will emit by default when an encrypted client certificate key is provided to libpq ."],"definition":"This parameter specifies the password for the secret key specified in sslkey , allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical. Specifying this parameter with any non-empty value suppresses the Enter PEM pass phrase: prompt that OpenSSL will emit by default when an encrypted client certificate key is provided to libpq . If the key is not encrypted this parameter is ignored. The parameter has no effect on keys specified by OpenSSL engines unless the engine uses the OpenSSL password callback mechanism for prompts. There is no environment variable equivalent to this option, and no facility for looking it up in .pgpass . It can be used in a service file connection definition. Users with more sophisticated uses should consider using OpenSSL engines and tools like PKCS#11 or USB crypto offload devices.","documented":true,"environment":"","keyword":"sslpassword"},"comparison_hash":"76d31098c53b756591e108ab2a65b1fee7a5d8a7651bc44feea6b8293d631cd0","default_evidence":["Specifying this parameter with any non-empty value suppresses the Enter PEM pass phrase: prompt that OpenSSL will emit by default when an encrypted client certificate key is provided to libpq ."],"description":["This parameter specifies the password for the secret key specified in sslkey , allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical."],"documented":true,"environment":[],"facts":[{"label":"Client library","value":"libpq 18.6"},{"label":"Manual definition","value":"Documented"},{"label":"Source environment fallback","value":"None declared in the option table"},{"label":"Compiled fallback expression","value":"NULL"}],"keyword":"sslpassword","manual_html":"\u003cdiv\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt id=\"LIBPQ-CONNECT-SSLPASSWORD\"\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003esslpassword\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThis parameter specifies the password for the secret key specified in \u003ccode class=\"literal\"\u003esslkey\u003c/code\u003e, allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical.\u003c/p\u003e\n\u003cp\u003eSpecifying this parameter with any non-empty value suppresses the \u003ccode class=\"literal\"\u003eEnter PEM pass phrase:\u003c/code\u003e prompt that \u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e will emit by default when an encrypted client certificate key is provided to \u003cspan class=\"application\"\u003elibpq\u003c/span\u003e.\u003c/p\u003e\n\u003cp\u003eIf the key is not encrypted this parameter is ignored. The parameter has no effect on keys specified by \u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e engines unless the engine uses the \u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e password callback mechanism for prompts.\u003c/p\u003e\n\u003cp\u003eThere is no environment variable equivalent to this option, and no facility for looking it up in \u003ccode class=\"filename\"\u003e.pgpass\u003c/code\u003e. It can be used in a service file connection definition. Users with more sophisticated uses should consider using \u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e engines and tools like PKCS#11 or USB crypto offload devices.\u003c/p\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","manual_path":"libpq-connect.html#LIBPQ-CONNECT-SSLPASSWORD","precedence_evidence":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"related":[{"label":"Connection service file","url":"/docs/18/libpq-pgservice.html"},{"label":"Password file","url":"/docs/18/libpq-pgpass.html"},{"label":"All libpq environment variables","url":"/docs/18/libpq-envars.html"}],"release":{"channel":"stable","evidence_kind":"English manual and source declarations","label":"18.6","major":"18","manifest":{"index":"index.html","major":"18","pages":1148,"pdf":{"A4":{"built_at":"2026-09-26","bytes":15865106,"pages":3154,"sha256":"19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190","url":"/files/documentation/pdf/18/postgresql-18-A4.pdf"},"US":{"built_at":"2026-09-26","bytes":15748059,"pages":3328,"sha256":"facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319","url":"/files/documentation/pdf/18/postgresql-18-US.pdf"}},"release":"18.6","source_mode":"en SGML built with pinned official archive","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","svg_assets":3,"tree":"18"},"ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sections":[{"paragraphs":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"title":"Default resolution and service-file precedence"},{"paragraphs":[],"title":"Environment variable evidence"}],"signature":"sslpassword","source_option":{"compiled_default_expression":"NULL","declaration":"\"sslpassword\", NULL, NULL, NULL, \"SSL-Client-Key-Password\", \"*\", 20, offsetof(struct pg_conn, sslpassword)","environment":"","keyword":"sslpassword","source_notes":[]},"sources":[{"anchor":"LIBPQ-CONNECT-SSLPASSWORD","file":"libpq-connect.html","label":"18.6 English manual · libpq-connect.html","sha256":"c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f","url":"/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLPASSWORD"},{"archive_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","file":"src/interfaces/libpq/fe-connect.c","label":"18.6 libpq connection option declarations","sha256":"44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"anchor":"","file":"libpq-envars.html","label":"18.6 English manual · libpq-envars.html","sha256":"d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363","url":"/docs/18/libpq-envars.html"},{"anchor":"","file":"libpq-pgservice.html","label":"18.6 English manual · libpq-pgservice.html","sha256":"6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7","url":"/docs/18/libpq-pgservice.html"}],"tables":[]},"ManualEvidence":{"manual_path":"libpq-connect.html#LIBPQ-CONNECT-SSLPASSWORD","release":{"channel":"stable","evidence_kind":"English manual and source declarations","label":"18.6","major":"18","manifest":{"index":"index.html","major":"18","pages":1148,"pdf":{"A4":{"built_at":"2026-09-26","bytes":15865106,"pages":3154,"sha256":"19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190","url":"/files/documentation/pdf/18/postgresql-18-A4.pdf"},"US":{"built_at":"2026-09-26","bytes":15748059,"pages":3328,"sha256":"facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319","url":"/files/documentation/pdf/18/postgresql-18-US.pdf"}},"release":"18.6","source_mode":"en SGML built with pinned official archive","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","svg_assets":3,"tree":"18"},"ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sources":[{"anchor":"LIBPQ-CONNECT-SSLPASSWORD","file":"libpq-connect.html","label":"18.6 English manual · libpq-connect.html","sha256":"c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f","url":"/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLPASSWORD"},{"archive_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","file":"src/interfaces/libpq/fe-connect.c","label":"18.6 libpq connection option declarations","sha256":"44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"anchor":"","file":"libpq-envars.html","label":"18.6 English manual · libpq-envars.html","sha256":"d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363","url":"/docs/18/libpq-envars.html"},{"anchor":"","file":"libpq-pgservice.html","label":"18.6 English manual · libpq-pgservice.html","sha256":"6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7","url":"/docs/18/libpq-pgservice.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"conn","Key":"sslpassword","SourceDatabase":"center","Version":"18","Locale":"en","Title":"sslpassword","Summary":"This parameter specifies the password for the secret key specified in sslkey , allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical.","BodyHTML":"\u003cdiv\u003e\u003cdl\u003e\u003cdt id=\"LIBPQ-CONNECT-SSLPASSWORD\"\u003e\u003cspan\u003e\u003ccode\u003esslpassword\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThis parameter specifies the password for the secret key specified in \u003ccode\u003esslkey\u003c/code\u003e, allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical.\u003c/p\u003e\n\u003cp\u003eSpecifying this parameter with any non-empty value suppresses the \u003ccode\u003eEnter PEM pass phrase:\u003c/code\u003e prompt that \u003cspan\u003eOpenSSL\u003c/span\u003e will emit by default when an encrypted client certificate key is provided to \u003cspan\u003elibpq\u003c/span\u003e.\u003c/p\u003e\n\u003cp\u003eIf the key is not encrypted this parameter is ignored. The parameter has no effect on keys specified by \u003cspan\u003eOpenSSL\u003c/span\u003e engines unless the engine uses the \u003cspan\u003eOpenSSL\u003c/span\u003e password callback mechanism for prompts.\u003c/p\u003e\n\u003cp\u003eThere is no environment variable equivalent to this option, and no facility for looking it up in \u003ccode\u003e.pgpass\u003c/code\u003e. It can be used in a service file connection definition. Users with more sophisticated uses should consider using \u003cspan\u003eOpenSSL\u003c/span\u003e engines and tools like PKCS#11 or USB crypto offload devices.\u003c/p\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","SourceRevision":"ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8","ContentHash":"efd5211091d58c2341030863fe020620d069b58c5b2c2b705873c210d0d31b9e","Payload":{"description":["This parameter specifies the password for the secret key specified in sslkey , allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical."],"manual_html":"\u003cdiv\u003e\u003cdl class=\"variablelist\"\u003e\u003cdt id=\"LIBPQ-CONNECT-SSLPASSWORD\"\u003e\u003cspan class=\"term\"\u003e\u003ccode class=\"literal\"\u003esslpassword\u003c/code\u003e\u003c/span\u003e \u003c/dt\u003e\u003cdd\u003e\n\u003cp\u003eThis parameter specifies the password for the secret key specified in \u003ccode class=\"literal\"\u003esslkey\u003c/code\u003e, allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical.\u003c/p\u003e\n\u003cp\u003eSpecifying this parameter with any non-empty value suppresses the \u003ccode class=\"literal\"\u003eEnter PEM pass phrase:\u003c/code\u003e prompt that \u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e will emit by default when an encrypted client certificate key is provided to \u003cspan class=\"application\"\u003elibpq\u003c/span\u003e.\u003c/p\u003e\n\u003cp\u003eIf the key is not encrypted this parameter is ignored. The parameter has no effect on keys specified by \u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e engines unless the engine uses the \u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e password callback mechanism for prompts.\u003c/p\u003e\n\u003cp\u003eThere is no environment variable equivalent to this option, and no facility for looking it up in \u003ccode class=\"filename\"\u003e.pgpass\u003c/code\u003e. It can be used in a service file connection definition. Users with more sophisticated uses should consider using \u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e engines and tools like PKCS#11 or USB crypto offload devices.\u003c/p\u003e\n\u003c/dd\u003e\u003c/dl\u003e\u003c/div\u003e","related":[{"label":"Connection service file","url":"/docs/18/libpq-pgservice.html"},{"label":"Password file","url":"/docs/18/libpq-pgpass.html"},{"label":"All libpq environment variables","url":"/docs/18/libpq-envars.html"}],"sections":[{"paragraphs":["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.","Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .","Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."],"title":"Default resolution and service-file precedence"},{"paragraphs":[],"title":"Environment variable evidence"}],"tables":[]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
