{"Entry":{"collection":"guc","key":"ssl_crl_file","name":"ssl_crl_file","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / SSL","category_zh":"","changed_in":["10","11"],"changes":[{"documentation_changed":false,"fields":{},"from":"9.1","status":"added","to":"9.2"},{"documentation_changed":true,"fields":{"context":{"from":"postmaster","to":"sighup"}},"from":"9.6","status":"changed","to":"10"},{"documentation_changed":true,"fields":{"category":{"from":"Connections and Authentication / Security and Authentication","to":"Connections and Authentication / SSL"}},"from":"10","status":"changed","to":"11"},{"documentation_changed":true,"fields":{},"from":"13","status":"changed","to":"14"}],"content_hash":"2cd28a24b6d29e507631b3cbdca99e54bd5dea9224fdffea3d04d0482ad5e940","context":"","default_changed_in":[],"default_history":[{"from":"9.2","to":"19","value":"Empty string"}],"editorial":{"advice":{"olap":"Analytical clients follow the same revocation policy; do not defer CRL refresh because their sessions are longer or less frequent.","oltp":"Refresh ssl_crl_file from the issuing CA before its next-update deadline, validate its signature and issuer coverage, reload PostgreSQL, and prove that a newly revoked client certificate is rejected.","small":"If a managed CRL feed is unavailable, document that client-certificate revocation is not current rather than relying on a stale file. Keep the file and reload process monitored on every failover node."},"mechanism":["ssl_crl_file identifies the location of the SSL certificate revocation list file. The PEM revocation list is consulted when validating client certificates and must be refreshed as issuers publish new revocation state.","ssl_crl_file is a SIGHUP-context setting: a configuration reload activates the new server value without a restart; subsequent operations that consult it use the refreshed value. Existing TLS sessions are not renegotiated.","It participates in the TLS context used for new handshakes. ssl enables transport, pg_hba.conf decides which connection classes require it, and the certificate, key, CA, revocation, protocol, and cipher settings must form one valid policy."],"pitfalls":["Editing ssl_crl_file without reloading configuration and verifying the effective value and subsequent behavior.","Updating only one TLS file or policy knob and leaving an invalid chain, unreadable key, or incompatible protocol set.","Assuming a reload renegotiates existing sessions; TLS policy changes affect new handshakes.","Changing ssl_crl_file globally without a rollback plan and a client or operational compatibility test."],"references":[{"title":"PostgreSQL 19 Beta 4: ssl_crl_file","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-SSL-CRL-FILE"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["ssl","ssl_cert_file","ssl_key_file","ssl_ca_file","ssl_min_protocol_version"],"summary":"ssl_crl_file is the PostgreSQL setting that identifies the location of the SSL certificate revocation list file."},"enumvals":[],"first_version":"9.2","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:32.010035+08:00","intro_commit":{"authored_at":"2012-02-22T23:40:46+02:00","discussion":[],"hash":"a445cb92ef5b3a31313ebce30e18cc1d6e0bdecb","subject":"Add parameters for controlling locations of server-side SSL files","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=a445cb92ef5b3a31313ebce30e18cc1d6e0bdecb"},"key":"ssl_crl_file","last_version":"20","max_val":"","min_val":"","name":"ssl_crl_file","position":370,"present_in":["9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"Specifies the name of the file containing the SSL client certificate revocation list (CRL).","short_desc_zh":"","source_rev":"english-manuals:e69700e7b963bf6fa1a173deff4ff30cc88a3c9085f91626180d55054f82252b","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"ssl_crl_file","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"ssl_crl_file","SourceRevision":"english-manuals:e69700e7b963bf6fa1a173deff4ff30cc88a3c9085f91626180d55054f82252b","Facts":{"boot_val":"","category":"Connections and Authentication / SSL","context":"sighup","description":"Specifies the name of the file containing the SSL client certificate revocation list (CRL). Relative paths are relative to the data directory. This parameter can only be set in the postgresql.conf file or on the server command line. The default is empty, meaning no CRL file is loaded (unless ssl_crl_dir is set).","doc":{"anchor":"GUC-SSL-CRL-FILE","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"ssl_crl_file","short_desc":"Location of the SSL certificate revocation list file.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-SSL-CRL-FILE","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"ssl_crl_file","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"ssl_crl_file","Summary":"","BodyHTML":"\u003cp\u003e指定包含SSL客户端证书吊销列表（CRL）的文件名。相对路径是相对于数据目录的。此参数只能在\u003ccode\u003epostgresql.conf\u003c/code\u003e文件或服务器命令行中设置。默认为空，表示不加载CRL文件（除非设置了\u003ca href=\"/docs/18/runtime-config-connection.html#GUC-SSL-CRL-DIR\" rel=\"nofollow\"\u003essl_crl_dir\u003c/a\u003e）。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"fcfff6ee92aac77eb75e9313c1c0905893789d928b2d86f22a20ca54f93b07cd","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e指定包含SSL客户端证书吊销列表（CRL）的文件名。相对路径是相对于数据目录的。此参数只能在\u003ccode class=\"filename\"\u003epostgresql.conf\u003c/code\u003e文件或服务器命令行中设置。默认为空，表示不加载CRL文件（除非设置了\u003ca href=\"/docs/18/runtime-config-connection.html#GUC-SSL-CRL-DIR\"\u003essl_crl_dir\u003c/a\u003e）。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["10","11","12","13","14","15","16","17","18","19","20","9.2","9.3","9.4","9.5","9.6"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
