{"Entry":{"collection":"guc","key":"ssl_groups","name":"ssl_groups","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / SSL","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"17","status":"added","to":"18"},{"documentation_changed":true,"fields":{},"from":"18","status":"changed","to":"19"}],"content_hash":"06bd14a2c8a061c3d98caae0b04757e69fec3e81e2a513f045f571bd2149ecf3","context":"","default_changed_in":[],"default_history":[{"from":"18","to":"19","value":"X25519:prime256v1"}],"editorial":{"advice":{"olap":"Use the same TLS floor for analytical traffic; benchmark only after correctness because bulk transfer may expose CPU cost but is not a reason to accept obsolete protocols.","oltp":"Treat ssl_groups as transport-security policy rather than a performance knob. Follow the organization's TLS baseline and test certificate rotation, reload, and every client class.","small":"Keep ssl_groups simple and secure, using managed certificates and library defaults reviewed for the installed OpenSSL version. Rehearse renewal before expiry."},"mechanism":["ssl_groups sets the group(s) to use for Diffie-Hellman key exchange. Multiple groups can be specified using a colon-separated list. PostgreSQL 18 accepts an ordered colon-separated list, replacing the former single ssl_ecdh_curve choice and covering supported key-exchange groups.","ssl_groups is a SIGHUP-context setting: a configuration reload activates the new server value without a restart; subsequent operations that consult it use the refreshed value. Existing TLS sessions are not renegotiated.","It participates in the TLS context used for new handshakes. ssl enables transport, pg_hba.conf decides which connection classes require it, and the certificate, key, CA, revocation, protocol, and cipher settings must form one valid policy."],"pitfalls":["Editing ssl_groups without reloading configuration and verifying the effective value and subsequent behavior.","Updating only one TLS file or policy knob and leaving an invalid chain, unreadable key, or incompatible protocol set.","Assuming a reload renegotiates existing sessions; TLS policy changes affect new handshakes.","Changing ssl_groups globally without a rollback plan and a client or operational compatibility test."],"references":[{"title":"PostgreSQL 19 Beta 4: ssl_groups","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-SSL-GROUPS"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["ssl_ciphers","ssl_tls13_ciphers","ssl_min_protocol_version","ssl_max_protocol_version","ssl_prefer_server_ciphers"],"summary":"ssl_groups is the PostgreSQL setting that defines the group(s) to use for Diffie-Hellman key exchange."},"enumvals":[],"first_version":"18","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:32.019083+08:00","intro_commit":{"authored_at":"2024-10-24T15:20:28+02:00","discussion":["https://postgr.es/m/tencent_063F89FA72CCF2E48A0DF5338841988E9809@qq.com"],"hash":"3d1ef3a15c3eb68dae44b94e89d04c422b26fc16","subject":"Support configuring multiple ECDH curves","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=3d1ef3a15c3eb68dae44b94e89d04c422b26fc16"},"key":"ssl_groups","last_version":"20","max_val":"","min_val":"","name":"ssl_groups","position":373,"present_in":["18","19","20"],"short_desc":"Specifies the named group to use for TLS key exchange.","short_desc_zh":"","source_rev":"english-manuals:5ef89eda014e7ae47b93e34a59df3eccc0aab99eb16fafe49af03e20e21b170a","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"ssl_groups","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"ssl_groups","SourceRevision":"english-manuals:5ef89eda014e7ae47b93e34a59df3eccc0aab99eb16fafe49af03e20e21b170a","Facts":{"boot_val":"X25519:prime256v1","category":"Connections and Authentication / SSL","context":"sighup","description":"Specifies the named group to use for TLS key exchange. It needs to be supported by all clients that connect. Multiple groups can be specified by using a colon-separated list. It does not need to match the key type used by the server certificate. This parameter can only be set in the postgresql.conf file or on the server command line. The default is X25519:prime256v1. OpenSSL names for the most common groups are: prime256v1 (NIST P-256), secp384r1 (NIST P-384), secp521r1 (NIST P-521). An incomplete list of available groups can be shown with the command openssl ecparam -list_curves. Not all of them are usable with TLS though, and many supported group names and aliases are omitted. In PostgreSQL versions before 18.0 this setting was named ssl_ecdh_curve and only accepted a single value.","doc":{"anchor":"GUC-SSL-GROUPS","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"Multiple groups can be specified using a colon-separated list.","lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"ssl_groups","short_desc":"Sets the group(s) to use for Diffie-Hellman key exchange.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-SSL-GROUPS","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"ssl_groups","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"ssl_groups","Summary":"","BodyHTML":"\u003cp\u003e指定用于 TLS 密钥交换的命名组。所有连接的客户端都需要支持该组。可以使用冒号分隔的列表指定多个组。它不需要与服务器证书所用的密钥类型匹配。该参数只能在\u003ccode\u003epostgresql.conf\u003c/code\u003e文件中或服务器命令行上设置。默认值为\u003ccode\u003eX25519:prime256v1\u003c/code\u003e。\u003c/p\u003e\u003cp\u003e\u003cspan\u003eOpenSSL\u003c/span\u003e最常见的组名是：\u003ccode\u003eprime256v1\u003c/code\u003e (NIST P-256)、\u003ccode\u003esecp384r1\u003c/code\u003e (NIST P-384)、\u003ccode\u003esecp521r1\u003c/code\u003e (NIST P-521)。\u003ccode\u003eopenssl ecparam -list_curves\u003c/code\u003e 命令可以显示可用组的不完整列表，但并非所有曲线都可用于 TLS，而且许多受支持的组名和别名并未列出。\u003c/p\u003e\u003cp\u003e在 \u003cspan\u003ePostgreSQL\u003c/span\u003e 18.0 之前，这个设置名为 \u003ccode\u003essl_ecdh_curve\u003c/code\u003e，并且只接受单个值。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"743f8d25be95608c89739eb6c89a77fca84ef3bd3ed08c03162334fae0d84198","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e指定用于 TLS 密钥交换的命名组。所有连接的客户端都需要支持该组。可以使用冒号分隔的列表指定多个组。它不需要与服务器证书所用的密钥类型匹配。该参数只能在\u003ccode class=\"filename\"\u003epostgresql.conf\u003c/code\u003e文件中或服务器命令行上设置。默认值为\u003ccode class=\"literal\"\u003eX25519:prime256v1\u003c/code\u003e。\u003c/p\u003e\u003cp\u003e\u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e最常见的组名是：\u003ccode class=\"literal\"\u003eprime256v1\u003c/code\u003e (NIST P-256)、\u003ccode class=\"literal\"\u003esecp384r1\u003c/code\u003e (NIST P-384)、\u003ccode class=\"literal\"\u003esecp521r1\u003c/code\u003e (NIST P-521)。\u003ccode class=\"command\"\u003eopenssl ecparam -list_curves\u003c/code\u003e 命令可以显示可用组的不完整列表，但并非所有曲线都可用于 TLS，而且许多受支持的组名和别名并未列出。\u003c/p\u003e\u003cp\u003e在 \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e 18.0 之前，这个设置名为 \u003ccode class=\"literal\"\u003essl_ecdh_curve\u003c/code\u003e，并且只接受单个值。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["18","19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
