{"Entry":{"collection":"guc","key":"ssl_dh_params_file","name":"ssl_dh_params_file","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / SSL","category_zh":"","changed_in":["11","18"],"changes":[{"documentation_changed":false,"fields":{},"from":"9.6","status":"added","to":"10"},{"documentation_changed":false,"fields":{"category":{"from":"Connections and Authentication / Security and Authentication","to":"Connections and Authentication / SSL"}},"from":"10","status":"changed","to":"11"},{"documentation_changed":false,"fields":{"extra_desc":{"from":null,"to":"An empty string means use compiled-in default parameters."}},"from":"17","status":"changed","to":"18"}],"content_hash":"e1b59a70ec37e6ac63f5920cd5c901ecd079d0e23a4c3eff6ce564fe2c5220ab","context":"","default_changed_in":[],"default_history":[{"from":"10","to":"19","value":"Empty string"}],"editorial":{"advice":{"olap":"Analytical throughput is not a reason to weaken DH parameters. Prefer the same reviewed key-exchange policy and measure only after client compatibility is proven.","oltp":"Use a custom ssl_dh_params_file only when finite-field ephemeral-DH cipher suites are intentionally supported and the parameters are generated by an approved current process. Test OpenSSL acceptance and reload before rollout.","small":"Leave the file empty to use PostgreSQL's compiled-in parameters unless policy requires a managed custom set; generating or loading custom parameters does not improve capacity."},"mechanism":["ssl_dh_params_file identifies the location of the SSL DH parameters file. An empty string means use compiled-in default parameters. An empty value uses PostgreSQL's compiled-in DH parameters; the file matters only for cipher suites that perform finite-field Diffie-Hellman exchange.","ssl_dh_params_file is a SIGHUP-context setting: a configuration reload activates the new server value without a restart; subsequent operations that consult it use the refreshed value. Existing TLS sessions are not renegotiated.","It participates in the TLS context used for new handshakes. ssl enables transport, pg_hba.conf decides which connection classes require it, and the certificate, key, CA, revocation, protocol, and cipher settings must form one valid policy."],"pitfalls":["Editing ssl_dh_params_file without reloading configuration and verifying the effective value and subsequent behavior.","Updating only one TLS file or policy knob and leaving an invalid chain, unreadable key, or incompatible protocol set.","Assuming a reload renegotiates existing sessions; TLS policy changes affect new handshakes.","Changing ssl_dh_params_file globally without a rollback plan and a client or operational compatibility test."],"references":[{"title":"PostgreSQL 19 Beta 4: ssl_dh_params_file","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-SSL-DH-PARAMS-FILE"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["ssl_ciphers","ssl_tls13_ciphers","ssl_min_protocol_version","ssl_max_protocol_version","ssl_prefer_server_ciphers","ssl_groups"],"summary":"ssl_dh_params_file is the PostgreSQL setting that identifies the location of the SSL DH parameters file."},"enumvals":[],"first_version":"10","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:32.013271+08:00","intro_commit":{"authored_at":"2017-07-31T22:36:09+03:00","discussion":["https://www.postgresql.org/message-id/CAMxBoUyjOOautVozN6ofzym828aNrDjuCcOTcCquxjwS-L2hGQ@mail.gmail.com"],"hash":"c0a15e07cd718cb6e455e68328f522ac076a0e4b","subject":"Always use 2048 bit DH parameters for OpenSSL ephemeral DH ciphers.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=c0a15e07cd718cb6e455e68328f522ac076a0e4b"},"key":"ssl_dh_params_file","last_version":"20","max_val":"","min_val":"","name":"ssl_dh_params_file","position":371,"present_in":["10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"Specifies the name of the file containing Diffie-Hellman parameters used for so-called ephemeral DH family of SSL ciphers.","short_desc_zh":"","source_rev":"english-manuals:7157244762b6552a6ca3ea7180f2a5c23a54c48c074689e5c6b80f684f36ff25","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"ssl_dh_params_file","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"ssl_dh_params_file","SourceRevision":"english-manuals:7157244762b6552a6ca3ea7180f2a5c23a54c48c074689e5c6b80f684f36ff25","Facts":{"boot_val":"","category":"Connections and Authentication / SSL","context":"sighup","description":"Specifies the name of the file containing Diffie-Hellman parameters used for so-called ephemeral DH family of SSL ciphers. The default is empty, in which case compiled-in default DH parameters used. Using custom DH parameters reduces the exposure if an attacker manages to crack the well-known compiled-in DH parameters. You can create your own DH parameters file with the command openssl dhparam -out dhparams.pem 2048. This parameter can only be set in the postgresql.conf file or on the server command line.","doc":{"anchor":"GUC-SSL-DH-PARAMS-FILE","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"An empty string means use compiled-in default parameters.","lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"ssl_dh_params_file","short_desc":"Location of the SSL DH parameters file.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-SSL-DH-PARAMS-FILE","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"ssl_dh_params_file","SourceDatabase":"center","Version":"18","Locale":"en","Title":"ssl_dh_params_file","Summary":"Specifies the name of the file containing Diffie-Hellman parameters used for so-called ephemeral DH family of SSL ciphers. The default is empty, in which case compiled-in default DH parameters used. Using custom DH parameters reduces the exposure if an attacker manages to crack the well-known compiled-in DH parameters. You can create your own DH parameters file with the command openssl dhparam -out dhparams.pem 2048. This parameter can only be set in the postgresql.conf file or on the server command line.","BodyHTML":"\u003cp\u003eSpecifies the name of the file containing Diffie-Hellman parameters used for so-called ephemeral DH family of SSL ciphers. The default is empty, in which case compiled-in default DH parameters used. Using custom DH parameters reduces the exposure if an attacker manages to crack the well-known compiled-in DH parameters. You can create your own DH parameters file with the command openssl dhparam -out dhparams.pem 2048. This parameter can only be set in the postgresql.conf file or on the server command line.\u003c/p\u003e","SourceRevision":"english-manuals:7157244762b6552a6ca3ea7180f2a5c23a54c48c074689e5c6b80f684f36ff25","ContentHash":"740932e14266b1bd776f82d1454ff8370bb8e4f10dbdf04b188d5ccc12c3c8de","Payload":{"description":"Specifies the name of the file containing Diffie-Hellman parameters used for so-called ephemeral DH family of SSL ciphers. The default is empty, in which case compiled-in default DH parameters used. Using custom DH parameters reduces the exposure if an attacker manages to crack the well-known compiled-in DH parameters. You can create your own DH parameters file with the command openssl dhparam -out dhparams.pem 2048. This parameter can only be set in the postgresql.conf file or on the server command line."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
