{"Entry":{"collection":"guc","key":"ssl_sni","name":"ssl_sni","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / SSL","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"18","status":"added","to":"19"}],"content_hash":"f6396c00af94236fb4c2db5e2d2c8c9ccecef4a806c0913e818a4ade5a1b639e","context":"","default_changed_in":[],"default_history":[{"from":"19","to":"19","value":"off"}],"editorial":{"advice":{"olap":"Apply the same security policy to batch drivers and long-lived ETL connections. Test clients that omit SNI, credential-expiry automation, reload behavior, and certificate-chain compatibility.","oltp":"Roll out through staged clients, validate certificate selection and expiry warnings, and monitor authentication failures. Keep a tested fallback and treat file permissions and secret rotation as part of the same change.","small":"Prefer a simple, documented TLS and credential policy. Do not enable multi-certificate routing without a test for every hostname and fallback path, and never weaken verification to hide configuration mistakes."},"mechanism":["PostgreSQL describes ssl_sni as follows: “Sets whether to interpret SNI extensions in SSL connections.” A configuration reload applies the value to the server without a full restart. The atlas measures it in PG19 Beta 3; boot_val is the compiled or initialized baseline, not proof of a running cluster's effective setting.","When enabled with TLS, PostgreSQL reads the client's Server Name Indication and selects credentials through hosts_file. Hostnames match case-insensitively; /no_sni/ and * provide explicit fallback behavior. Certificate identity, client verification, CRLs, permissions, and reload failures still require independent validation.","Read it together with hosts_file, ssl, ssl_cert_file, ssl_key_file. Check SHOW and pg_settings on the target server, verify the source and pending_restart fields, and compare workload, logs, and resource metrics before and after any change."],"pitfalls":["Treating the measured boot_val for ssl_sni as proof of the effective value on an initialized or managed cluster.","Applying a change as though it were immediate while pg_settings reports sighup context.","Changing this setting in isolation without checking the linked limits, observability, and rollback path.","Depending on beta behavior in production without retesting the PostgreSQL 19 final release."],"references":[{"title":"PostgreSQL 19 Beta 4: ssl_sni","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-SSL-SNI"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["hosts_file","ssl","ssl_cert_file","ssl_key_file","ssl_ca_file"],"summary":"ssl_sni — Sets whether to interpret SNI extensions in SSL connections. Observed in PG19 Beta 4; its last measured boot default is off in PG19 Beta 4, with sighup context. This is a beta-snapshot fact and can change before PostgreSQL 19 GA."},"enumvals":[],"first_version":"19","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:32.049264+08:00","intro_commit":{"authored_at":"2026-03-18T12:37:11+01:00","discussion":["https://postgr.es/m/1C81CD0D-407E-44F9-833A-DD0331C202E5@yesql.se"],"hash":"4f433025f666fa4a6209f0e847715767fb1c7ace","subject":"ssl: Serverside SNI support for libpq","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=4f433025f666fa4a6209f0e847715767fb1c7ace"},"key":"ssl_sni","last_version":"20","max_val":"","min_val":"","name":"ssl_sni","position":382,"present_in":["19","20"],"short_desc":"Enables SNI configuration for SSL connections.","short_desc_zh":"","source_rev":"english-manuals:3a23ae1e506ac78f99b4002a1557e1d5d5521ac8d546e012f160998e54e61a77","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"ssl_sni","SourceDatabase":"center","Version":"20","SourceTable":"guc","SourceKey":"ssl_sni","SourceRevision":"english-manuals:3a23ae1e506ac78f99b4002a1557e1d5d5521ac8d546e012f160998e54e61a77","Facts":{"boot_val":null,"category":"SSL","context":"","description":"Enables SNI configuration for SSL connections. When set to on host configuration from hosts_file is used, see Section 18.9.6 for more details. This parameter can only be set in the postgresql.conf file or on the server command line. The default is off.","doc":{"anchor":"GUC-SSL-SNI","file":"runtime-config-connection.html","lang":"en","sha256":"4b80661e9622d2555407e5bd755b09f6beb861e678e1670b0c34695e79ae140e","slug":"devel"},"documented":true,"enumvals":[],"extra_desc":"","lang":"en","max_val":null,"metadata_version":"","min_val":null,"name":"ssl_sni","short_desc":"","source":"english-manual","unit":"","vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-SSL-SNI","file":"runtime-config-connection.html","lang":"en","sha256":"4b80661e9622d2555407e5bd755b09f6beb861e678e1670b0c34695e79ae140e","slug":"devel"}},"MeasuredEvidence":{"metadata_version":""}},"Text":{"Collection":"guc","Key":"ssl_sni","SourceDatabase":"pgweb","Version":"20","Locale":"zh-Hans","Title":"ssl_sni","Summary":"","BodyHTML":"\u003cp\u003e启用 SSL 连接的 SNI 配置。设置为\u003ccode\u003eon\u003c/code\u003e时，将使用来自\u003ca href=\"/docs/devel/runtime-config-file-locations.html#GUC-HOSTS-FILE\" rel=\"nofollow\"\u003ehosts_file\u003c/a\u003e的主机配置；更多细节参见\u003ca href=\"/docs/devel/ssl-tcp.html#SSL-SNI\" rel=\"nofollow\"\u003e第 18.9.6 节\u003c/a\u003e。\u003c/p\u003e\u003cp\u003e此参数只能在\u003ccode\u003epostgresql.conf\u003c/code\u003e文件中或者服务器命令行上设置。默认值为\u003ccode\u003eoff\u003c/code\u003e。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"df8c93ad77a431bd5b6ffd1144a64c21bad2e3b0a56f49d4bffa3a60ae844dd2","Payload":{"carried_from":"19","carry_reason":"手册不含 pg_settings 事实，沿用 19","doc_html":"\u003cp\u003e启用 SSL 连接的 SNI 配置。设置为\u003ccode class=\"literal\"\u003eon\u003c/code\u003e时，将使用来自\u003ca href=\"/docs/devel/runtime-config-file-locations.html#GUC-HOSTS-FILE\"\u003ehosts_file\u003c/a\u003e的主机配置；更多细节参见\u003ca href=\"/docs/devel/ssl-tcp.html#SSL-SNI\" title=\"18.9.6. SNI 配置\"\u003e第 18.9.6 节\u003c/a\u003e。\u003c/p\u003e\u003cp\u003e此参数只能在\u003ccode class=\"filename\"\u003epostgresql.conf\u003c/code\u003e文件中或者服务器命令行上设置。默认值为\u003ccode class=\"literal\"\u003eoff\u003c/code\u003e。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
