{"Entry":{"collection":"guc","key":"ssl_min_protocol_version","name":"ssl_min_protocol_version","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / SSL","category_zh":"","changed_in":["13"],"changes":[{"documentation_changed":false,"fields":{},"from":"11","status":"added","to":"12"},{"documentation_changed":true,"fields":{"boot_val":{"from":"TLSv1","to":"TLSv1.2"}},"from":"12","status":"changed","to":"13"}],"content_hash":"f4153560626cfcb6a1641f0836ed1b3497568c0f4c75c5806b425f0107c995d0","context":"","default_changed_in":["13"],"default_history":[{"from":"12","to":"12","value":"TLSv1"},{"from":"13","to":"19","value":"TLSv1.2"}],"editorial":{"advice":{"olap":"Use the same TLS floor for analytical traffic; benchmark only after correctness because bulk transfer may expose CPU cost but is not a reason to accept obsolete protocols.","oltp":"Treat ssl_min_protocol_version as transport-security policy rather than a performance knob. Follow the organization's TLS baseline and test certificate rotation, reload, and every client class.","small":"Keep ssl_min_protocol_version simple and secure, using managed certificates and library defaults reviewed for the installed OpenSSL version. Rehearse renewal before expiry."},"mechanism":["ssl_min_protocol_version sets the minimum SSL/TLS protocol version to use. Connections negotiating below the floor are rejected; the upstream default moved from TLSv1 in PostgreSQL 12 to TLSv1.2 in PostgreSQL 13.","ssl_min_protocol_version is a SIGHUP-context setting: a configuration reload activates the new server value without a restart; subsequent operations that consult it use the refreshed value. Existing TLS sessions are not renegotiated.","It participates in the TLS context used for new handshakes. ssl enables transport, pg_hba.conf decides which connection classes require it, and the certificate, key, CA, revocation, protocol, and cipher settings must form one valid policy."],"pitfalls":["Editing ssl_min_protocol_version without reloading configuration and verifying the effective value and subsequent behavior.","Updating only one TLS file or policy knob and leaving an invalid chain, unreadable key, or incompatible protocol set.","Assuming a reload renegotiates existing sessions; TLS policy changes affect new handshakes.","Changing ssl_min_protocol_version globally without a rollback plan and a client or operational compatibility test."],"references":[{"title":"PostgreSQL 19 Beta 4: ssl_min_protocol_version","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-SSL-MIN-PROTOCOL-VERSION"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["ssl_ciphers","ssl_tls13_ciphers","ssl_max_protocol_version","ssl_prefer_server_ciphers","ssl_groups"],"summary":"ssl_min_protocol_version is the PostgreSQL setting that defines the minimum SSL/TLS protocol version to use."},"enumvals":[],"first_version":"12","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:32.031598+08:00","intro_commit":{"authored_at":"2018-11-20T21:49:01+01:00","discussion":["https://www.postgresql.org/message-id/flat/1822da87-b862-041a-9fc2-d0310c3da173@2ndquadrant.com"],"hash":"e73e67c719593c1c16139cc6c516d8379f22f182","subject":"Add settings to control SSL/TLS protocol version","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=e73e67c719593c1c16139cc6c516d8379f22f182"},"key":"ssl_min_protocol_version","last_version":"20","max_val":"","min_val":"","name":"ssl_min_protocol_version","position":377,"present_in":["12","13","14","15","16","17","18","19","20"],"short_desc":"Sets the minimum SSL/TLS protocol version to use.","short_desc_zh":"","source_rev":"english-manuals:7f65de70014ca305d72187b8c740d313ce8adf6edeac73d6448faa44dd708437","unit":"","vartype":"enum"}},"Definition":{"Collection":"guc","Key":"ssl_min_protocol_version","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"ssl_min_protocol_version","SourceRevision":"english-manuals:7f65de70014ca305d72187b8c740d313ce8adf6edeac73d6448faa44dd708437","Facts":{"boot_val":"TLSv1.2","category":"Connections and Authentication / SSL","context":"sighup","description":"Sets the minimum SSL/TLS protocol version to use. Valid values are currently: TLSv1, TLSv1.1, TLSv1.2, TLSv1.3. Older versions of the OpenSSL library do not support all values; an error will be raised if an unsupported setting is chosen. Protocol versions before TLS 1.0, namely SSL version 2 and 3, are always disabled. The default is TLSv1.2, which satisfies industry best practices as of this writing. This parameter can only be set in the postgresql.conf file or on the server command line.","doc":{"anchor":"GUC-SSL-MIN-PROTOCOL-VERSION","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":["TLSv1","TLSv1.1","TLSv1.2","TLSv1.3"],"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"ssl_min_protocol_version","short_desc":"Sets the minimum SSL/TLS protocol version to use.","source":"pg-settings-source-snapshot","unit":null,"vartype":"enum"},"ManualEvidence":{"doc":{"anchor":"GUC-SSL-MIN-PROTOCOL-VERSION","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"ssl_min_protocol_version","SourceDatabase":"center","Version":"18","Locale":"en","Title":"ssl_min_protocol_version","Summary":"Sets the minimum SSL/TLS protocol version to use. Valid values are currently: TLSv1, TLSv1.1, TLSv1.2, TLSv1.3. Older versions of the OpenSSL library do not support all values; an error will be raised if an unsupported setting is chosen. Protocol versions before TLS 1.0, namely SSL version 2 and 3, are always disabled. The default is TLSv1.2, which satisfies industry best practices as of this writing. This parameter can only be set in the postgresql.conf file or on the server command line.","BodyHTML":"\u003cp\u003eSets the minimum SSL/TLS protocol version to use. Valid values are currently: TLSv1, TLSv1.1, TLSv1.2, TLSv1.3. Older versions of the OpenSSL library do not support all values; an error will be raised if an unsupported setting is chosen. Protocol versions before TLS 1.0, namely SSL version 2 and 3, are always disabled. The default is TLSv1.2, which satisfies industry best practices as of this writing. This parameter can only be set in the postgresql.conf file or on the server command line.\u003c/p\u003e","SourceRevision":"english-manuals:7f65de70014ca305d72187b8c740d313ce8adf6edeac73d6448faa44dd708437","ContentHash":"ab9ff458693b934bcd824687df66be2ae933995bd26bd2b5086601030f053bc2","Payload":{"description":"Sets the minimum SSL/TLS protocol version to use. Valid values are currently: TLSv1, TLSv1.1, TLSv1.2, TLSv1.3. Older versions of the OpenSSL library do not support all values; an error will be raised if an unsupported setting is chosen. Protocol versions before TLS 1.0, namely SSL version 2 and 3, are always disabled. The default is TLSv1.2, which satisfies industry best practices as of this writing. This parameter can only be set in the postgresql.conf file or on the server command line."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["12","13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
