{"Entry":{"collection":"guc","key":"ssl_key_file","name":"ssl_key_file","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / SSL","category_zh":"","changed_in":["10","11"],"changes":[{"documentation_changed":false,"fields":{},"from":"9.1","status":"added","to":"9.2"},{"documentation_changed":true,"fields":{"context":{"from":"postmaster","to":"sighup"}},"from":"9.6","status":"changed","to":"10"},{"documentation_changed":false,"fields":{"category":{"from":"Connections and Authentication / Security and Authentication","to":"Connections and Authentication / SSL"}},"from":"10","status":"changed","to":"11"}],"content_hash":"4204bc34338175955798df65ca786bf515658ddd5328169037d916f75e666b5b","context":"","default_changed_in":[],"default_history":[{"from":"9.2","to":"19","value":"server.key"}],"editorial":{"advice":{"olap":"Use the same private-key controls for analytical nodes; workload type never justifies a shared, group-writable, or copied key outside the managed PKI process.","oltp":"Keep ssl_key_file owned by the PostgreSQL service account with PostgreSQL-accepted restrictive permissions, ensure it matches ssl_cert_file, and rotate it through an audited secret-delivery path.","small":"Prefer one managed key with expiry/renewal tests and protected backups. If it is encrypted, test ssl_passphrase_command and reload behavior before an unattended restart."},"mechanism":["ssl_key_file identifies the location of the SSL server private key file. The file contains the private key matching ssl_cert_file; PostgreSQL enforces restrictive ownership and permissions before accepting it.","ssl_key_file is a SIGHUP-context setting: a configuration reload activates the new server value without a restart; subsequent operations that consult it use the refreshed value. Existing TLS sessions are not renegotiated.","It participates in the TLS context used for new handshakes. ssl enables transport, pg_hba.conf decides which connection classes require it, and the certificate, key, CA, revocation, protocol, and cipher settings must form one valid policy."],"pitfalls":["Editing ssl_key_file without reloading configuration and verifying the effective value and subsequent behavior.","Updating only one TLS file or policy knob and leaving an invalid chain, unreadable key, or incompatible protocol set.","Assuming a reload renegotiates existing sessions; TLS policy changes affect new handshakes.","Installing a private key with ownership or permissions that PostgreSQL rejects, or leaking it to a readable group."],"references":[{"title":"PostgreSQL 19 Beta 4: ssl_key_file","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-SSL-KEY-FILE"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["ssl","ssl_cert_file","ssl_ca_file","ssl_crl_file","ssl_min_protocol_version"],"summary":"ssl_key_file is the PostgreSQL setting that identifies the location of the SSL server private key file."},"enumvals":[],"first_version":"9.2","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:32.021741+08:00","intro_commit":{"authored_at":"2012-02-22T23:40:46+02:00","discussion":[],"hash":"a445cb92ef5b3a31313ebce30e18cc1d6e0bdecb","subject":"Add parameters for controlling locations of server-side SSL files","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=a445cb92ef5b3a31313ebce30e18cc1d6e0bdecb"},"key":"ssl_key_file","last_version":"20","max_val":"","min_val":"","name":"ssl_key_file","position":374,"present_in":["9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"Specifies the name of the file containing the SSL server private key.","short_desc_zh":"","source_rev":"english-manuals:8e50c0af4505989c648b629ef70dd6b539f5368ed6d4f4b8e6e3bea44d9940be","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"ssl_key_file","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"ssl_key_file","SourceRevision":"english-manuals:8e50c0af4505989c648b629ef70dd6b539f5368ed6d4f4b8e6e3bea44d9940be","Facts":{"boot_val":"server.key","category":"Connections and Authentication / SSL","context":"sighup","description":"Specifies the name of the file containing the SSL server private key. Relative paths are relative to the data directory. This parameter can only be set in the postgresql.conf file or on the server command line. The default is server.key.","doc":{"anchor":"GUC-SSL-KEY-FILE","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"ssl_key_file","short_desc":"Location of the SSL server private key file.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-SSL-KEY-FILE","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"ssl_key_file","SourceDatabase":"center","Version":"18","Locale":"en","Title":"ssl_key_file","Summary":"Specifies the name of the file containing the SSL server private key. Relative paths are relative to the data directory. This parameter can only be set in the postgresql.conf file or on the server command line. The default is server.key.","BodyHTML":"\u003cp\u003eSpecifies the name of the file containing the SSL server private key. Relative paths are relative to the data directory. This parameter can only be set in the postgresql.conf file or on the server command line. The default is server.key.\u003c/p\u003e","SourceRevision":"english-manuals:8e50c0af4505989c648b629ef70dd6b539f5368ed6d4f4b8e6e3bea44d9940be","ContentHash":"839518bae21f66d612db48a3fad3d8f7c100f4320477511023d88d4b503826be","Payload":{"description":"Specifies the name of the file containing the SSL server private key. Relative paths are relative to the data directory. This parameter can only be set in the postgresql.conf file or on the server command line. The default is server.key."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20","9.2","9.3","9.4","9.5","9.6"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
