{"Entry":{"collection":"guc","key":"ssl_renegotiation_limit","name":"ssl_renegotiation_limit","aliases":[],"metadata":{"baseline":true,"boot_human":"0 B","boot_val":"0","category":"Connections and Authentication / Security and Authentication","category_zh":"","changed_in":[],"changes":[{"documentation_changed":true,"fields":{},"from":"8.4","status":"changed","to":"9.0"},{"documentation_changed":false,"fields":{},"from":"9.4","status":"removed","to":"9.5"}],"content_hash":"d424a58e31ee104084c539019b44de92466f3843a10f73e268e47a9bd0dcd680","context":"user","default_changed_in":[],"default_history":[{"from":"9.0","to":"9.4","value":"0 B"}],"editorial":{"advice":{"olap":"For an upgrade or analytical estate, inventory every generated configuration before cutover. Map the old control to its successor and compare plans, throughput, WAL, or logging behavior rather than assuming the old numeric value is portable.","oltp":"Do not add this retired name to a current OLTP configuration. Translate its intent to the documented successor, test the migration under connection and write concurrency, and remove stale automation that still emits it.","small":"Delete the obsolete override after recording why it existed. On a small node, prefer the successor's default until measurements justify a new value; an unknown startup parameter can otherwise stop the server."},"mechanism":["PostgreSQL describes ssl_renegotiation_limit as follows: “Set the amount of traffic to send and receive before renegotiating the encryption keys.” It can be changed per session, which makes plan or behavior comparisons possible without changing every workload. The atlas measures it in PG9.0–9.4; boot_val is the compiled or initialized baseline, not proof of a running cluster's effective setting.","This setting initiated TLS key renegotiation after a traffic threshold. PostgreSQL removed it in 9.5 as protocol/library behavior and security guidance moved away from renegotiation; modern TLS policy should use supported protocol versions, ciphers, certificates, and ordinary connection rotation.","Read it together with ssl_min_protocol_version, ssl_max_protocol_version, ssl_ciphers, ssl. Check SHOW and pg_settings on the target server, verify the source and pending_restart fields, and compare workload, logs, and resource metrics before and after any change."],"pitfalls":["Treating the measured boot_val for ssl_renegotiation_limit as proof of the effective value on an initialized or managed cluster.","Applying a change as though it were immediate while pg_settings reports user context.","Changing this setting in isolation without checking the linked limits, observability, and rollback path.","Copying the removed name into a modern postgresql.conf instead of migrating to its documented successor."],"references":[{"title":"PostgreSQL 9.4: ssl_renegotiation_limit","url":"https://www.postgresql.org/docs/9.4/runtime-config-connection.html#GUC-SSL-RENEGOTIATION-LIMIT"}],"related":["ssl_min_protocol_version","ssl_max_protocol_version","ssl_ciphers","ssl"],"summary":"ssl_renegotiation_limit — Set the amount of traffic to send and receive before renegotiating the encryption keys. Observed in PG9.0–9.4; its last measured boot default is 0 B in PG9.4, with user context. It was removed in PG9.5."},"enumvals":[],"first_version":"7.4","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:32.046298+08:00","intro_commit":{},"key":"ssl_renegotiation_limit","last_version":"9.4","max_val":"2147483647","min_val":"0","name":"ssl_renegotiation_limit","position":381,"present_in":["7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4"],"short_desc":"Specifies how much data can flow over an SSL-encrypted connection before renegotiation of the session keys will take place.","short_desc_zh":"","source_rev":"english-manuals:ea3d06ed0647944c5f0fb98b32f327ef6259384fece9ba1a06818385b3d396fe","unit":"kB","vartype":"integer"}},"Definition":{"Collection":"guc","Key":"ssl_renegotiation_limit","SourceDatabase":"center","Version":"9.4","SourceTable":"guc","SourceKey":"ssl_renegotiation_limit","SourceRevision":"english-manuals:ea3d06ed0647944c5f0fb98b32f327ef6259384fece9ba1a06818385b3d396fe","Facts":{"boot_val":"0","category":"Connections and Authentication / Security and Authentication","context":"user","description":"Specifies how much data can flow over an SSL-encrypted connection before renegotiation of the session keys will take place. Renegotiation decreases an attacker's chances of doing cryptanalysis when large amounts of traffic can be examined, but it also carries a large performance penalty. The sum of sent and received traffic is used to check the limit. If this parameter is set to 0, renegotiation is disabled. The default is 0. Note: SSL libraries from before November 2009 are insecure when using SSL renegotiation, due to a vulnerability in the SSL protocol. As a stop-gap fix for this vulnerability, some vendors shipped SSL libraries incapable of doing renegotiation. If any such libraries are in use on the client or server, SSL renegotiation should be disabled. Warning Due to bugs in OpenSSL enabling ssl renegotiation, by configuring a non-zero ssl_renegotiation_limit, is likely to lead to problems like long-lived connections breaking.","doc":{"anchor":"GUC-SSL-RENEGOTIATION-LIMIT","file":"runtime-config-connection.html","lang":"en","sha256":"26637417e03438ebe017f1c6c508f0656e993e1e836f76bcf7a70b1c8fda66bf","slug":"9.4"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":"2147483647","metadata_version":"9.4","min_val":"0","name":"ssl_renegotiation_limit","short_desc":"Set the amount of traffic to send and receive before renegotiating the encryption keys.","source":"pg-settings-source-snapshot","unit":"kB","vartype":"integer"},"ManualEvidence":{"doc":{"anchor":"GUC-SSL-RENEGOTIATION-LIMIT","file":"runtime-config-connection.html","lang":"en","sha256":"26637417e03438ebe017f1c6c508f0656e993e1e836f76bcf7a70b1c8fda66bf","slug":"9.4"}},"MeasuredEvidence":{"metadata_version":"9.4"}},"Text":{"Collection":"guc","Key":"ssl_renegotiation_limit","SourceDatabase":"center","Version":"9.4","Locale":"en","Title":"ssl_renegotiation_limit","Summary":"Specifies how much data can flow over an SSL-encrypted connection before renegotiation of the session keys will take place. Renegotiation decreases an attacker's chances of doing cryptanalysis when large amounts of traffic can be examined, but it also carries a large performance penalty. The sum of sent and received traffic is used to check the limit. If this parameter is set to 0, renegotiation is disabled. The default is 0. Note: SSL libraries from before November 2009 are insecure when using SSL renegotiation, due to a vulnerability in the SSL protocol. As a stop-gap fix for this vulnerability, some vendors shipped SSL libraries incapable of doing renegotiation. If any such libraries are in use on the client or server, SSL renegotiation should be disabled. Warning Due to bugs in OpenSSL enabling ssl renegotiation, by configuring a non-zero ssl_renegotiation_limit, is likely to lead to problems like long-lived connections breaking.","BodyHTML":"\u003cp\u003eSpecifies how much data can flow over an SSL-encrypted connection before renegotiation of the session keys will take place. Renegotiation decreases an attacker\u0026#39;s chances of doing cryptanalysis when large amounts of traffic can be examined, but it also carries a large performance penalty. The sum of sent and received traffic is used to check the limit. If this parameter is set to 0, renegotiation is disabled. The default is 0. Note: SSL libraries from before November 2009 are insecure when using SSL renegotiation, due to a vulnerability in the SSL protocol. As a stop-gap fix for this vulnerability, some vendors shipped SSL libraries incapable of doing renegotiation. If any such libraries are in use on the client or server, SSL renegotiation should be disabled. Warning Due to bugs in OpenSSL enabling ssl renegotiation, by configuring a non-zero ssl_renegotiation_limit, is likely to lead to problems like long-lived connections breaking.\u003c/p\u003e","SourceRevision":"english-manuals:ea3d06ed0647944c5f0fb98b32f327ef6259384fece9ba1a06818385b3d396fe","ContentHash":"655935acc0098e504653a3930e1061d8729f2338b0dd0de0aaa1da2bc3936da1","Payload":{"description":"Specifies how much data can flow over an SSL-encrypted connection before renegotiation of the session keys will take place. Renegotiation decreases an attacker's chances of doing cryptanalysis when large amounts of traffic can be examined, but it also carries a large performance penalty. The sum of sent and received traffic is used to check the limit. If this parameter is set to 0, renegotiation is disabled. The default is 0. Note: SSL libraries from before November 2009 are insecure when using SSL renegotiation, due to a vulnerability in the SSL protocol. As a stop-gap fix for this vulnerability, some vendors shipped SSL libraries incapable of doing renegotiation. If any such libraries are in use on the client or server, SSL renegotiation should be disabled. Warning Due to bugs in OpenSSL enabling ssl renegotiation, by configuring a non-zero ssl_renegotiation_limit, is likely to lead to problems like long-lived connections breaking."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
