{"Entry":{"collection":"guc","key":"ssl_crl_dir","name":"ssl_crl_dir","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / SSL","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"13","status":"added","to":"14"}],"content_hash":"992d8ab98eb35c01fc5387086280bd82ba63468d706dfcdaab2d68871a1e7fb4","context":"","default_changed_in":[],"default_history":[{"from":"14","to":"19","value":"Empty string"}],"editorial":{"advice":{"olap":"Analytical certificates use the same revocation repository. Do not create a separate stale directory merely because those clients connect less often.","oltp":"Manage ssl_crl_dir as an issuer-indexed CRL repository: add current CRLs, run openssl rehash or c_rehash, and test revocation with a new connection. Use it when on-demand multi-issuer updates are operationally maintained.","small":"Keep the directory empty unless automated CRL retrieval, rehashing, expiry monitoring, and failover synchronization are in place; an unmaintained directory creates false assurance."},"mechanism":["ssl_crl_dir names a directory of client-certificate revocation lists. OpenSSL requires hashed lookup links, so the directory must be prepared again with openssl rehash or c_rehash whenever CRLs are added or replaced. It supplements ssl_crl_file; both sources can be active.","Changing the directory path is a SIGHUP-context configuration change, but CRL files inside the configured directory are loaded on demand at connection time. A newly installed and correctly rehashed CRL can therefore be used immediately by new connections without a PostgreSQL reload.","This differs from ssl_crl_file, whose file content is loaded at server startup or configuration reload. Existing TLS sessions are not retroactively revoked by either setting; test revocation with a fresh client-certificate handshake and monitor CRL issuer, signature, and expiry."],"pitfalls":["Adding or replacing a CRL without running openssl rehash or c_rehash, leaving it undiscoverable by OpenSSL.","Reloading PostgreSQL but not refreshing an expired CRL, or assuming a directory change applies retroactively to established TLS sessions.","Treating ssl_crl_dir like ssl_crl_file and missing that directory CRLs are loaded on demand for new connections.","Synchronizing the directory path but not its CRLs and hash links to every failover node."],"references":[{"title":"PostgreSQL 19 Beta 4: ssl_crl_dir","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-SSL-CRL-DIR"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["ssl","ssl_cert_file","ssl_key_file","ssl_ca_file","ssl_crl_file","ssl_min_protocol_version"],"summary":"ssl_crl_dir is the PostgreSQL setting that identifies the location of the SSL certificate revocation list directory."},"enumvals":[],"first_version":"14","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:32.006389+08:00","intro_commit":{"authored_at":"2021-02-18T07:59:10+01:00","discussion":["https://www.postgresql.org/message-id/flat/20200731.173911.904649928639357911.horikyota.ntt@gmail.com"],"hash":"f5465fade90827534fbd0b795d18dc62e56939e9","subject":"Allow specifying CRL directory","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=f5465fade90827534fbd0b795d18dc62e56939e9"},"key":"ssl_crl_dir","last_version":"20","max_val":"","min_val":"","name":"ssl_crl_dir","position":369,"present_in":["14","15","16","17","18","19","20"],"short_desc":"Specifies the name of the directory containing the SSL client certificate revocation list (CRL).","short_desc_zh":"","source_rev":"english-manuals:f36231a3b388f8ed67cf405aa1e777f667d82071da3fac728ea8c5aa6dd39eb0","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"ssl_crl_dir","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"ssl_crl_dir","SourceRevision":"english-manuals:f36231a3b388f8ed67cf405aa1e777f667d82071da3fac728ea8c5aa6dd39eb0","Facts":{"boot_val":"","category":"Connections and Authentication / SSL","context":"sighup","description":"Specifies the name of the directory containing the SSL client certificate revocation list (CRL). Relative paths are relative to the data directory. This parameter can only be set in the postgresql.conf file or on the server command line. The default is empty, meaning no CRLs are used (unless ssl_crl_file is set). The directory needs to be prepared with the OpenSSL command openssl rehash or c_rehash. See its documentation for details. When using this setting, CRLs in the specified directory are loaded on-demand at connection time. New CRLs can be added to the directory and will be used immediately. This is unlike ssl_crl_file, which causes the CRL in the file to be loaded at server start time or when the configuration is reloaded. Both settings can be used together.","doc":{"anchor":"GUC-SSL-CRL-DIR","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"ssl_crl_dir","short_desc":"Location of the SSL certificate revocation list directory.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-SSL-CRL-DIR","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"ssl_crl_dir","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"ssl_crl_dir","Summary":"","BodyHTML":"\u003cp\u003e指定包含SSL客户端证书吊销列表（CRL）的目录名称。相对路径是相对于数据目录的。此参数只能在\u003ccode\u003epostgresql.conf\u003c/code\u003e文件或服务器命令行中设置。默认为空，表示不使用CRL（除非设置了\u003ca href=\"/docs/18/runtime-config-connection.html#GUC-SSL-CRL-FILE\" rel=\"nofollow\"\u003essl_crl_file\u003c/a\u003e）。\u003c/p\u003e\u003cp\u003e这个目录需要用\u003cspan\u003eOpenSSL\u003c/span\u003e 命令 \u003ccode\u003eopenssl rehash\u003c/code\u003e 或 \u003ccode\u003ec_rehash\u003c/code\u003e来准备。详情参阅相应文档。\u003c/p\u003e\u003cp\u003e当使用此设置时，在连接时会按需加载指定目录下的CRL。新的CRL可以添加到该目录中，并可以立即使用。这与\u003ca href=\"/docs/18/runtime-config-connection.html#GUC-SSL-CRL-FILE\" rel=\"nofollow\"\u003essl_crl_file\u003c/a\u003e不同，那个会导致文件中的CRL在服务器启动时或重新加载配置时加载。两个设置可以一起使用。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"658e34601bdf038bb874d23f109c6010744f5b4ab620164df9dabb83dcd6dbed","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e指定包含SSL客户端证书吊销列表（CRL）的目录名称。相对路径是相对于数据目录的。此参数只能在\u003ccode class=\"filename\"\u003epostgresql.conf\u003c/code\u003e文件或服务器命令行中设置。默认为空，表示不使用CRL（除非设置了\u003ca href=\"/docs/18/runtime-config-connection.html#GUC-SSL-CRL-FILE\"\u003essl_crl_file\u003c/a\u003e）。\u003c/p\u003e\u003cp\u003e这个目录需要用\u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e 命令 \u003ccode class=\"literal\"\u003eopenssl rehash\u003c/code\u003e 或 \u003ccode class=\"literal\"\u003ec_rehash\u003c/code\u003e来准备。详情参阅相应文档。\u003c/p\u003e\u003cp\u003e当使用此设置时，在连接时会按需加载指定目录下的CRL。新的CRL可以添加到该目录中，并可以立即使用。这与\u003ca href=\"/docs/18/runtime-config-connection.html#GUC-SSL-CRL-FILE\"\u003essl_crl_file\u003c/a\u003e不同，那个会导致文件中的CRL在服务器启动时或重新加载配置时加载。两个设置可以一起使用。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["14","15","16","17","18","19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
