{"Entry":{"collection":"guc","key":"ssl_tls13_ciphers","name":"ssl_tls13_ciphers","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / SSL","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"17","status":"added","to":"18"},{"documentation_changed":true,"fields":{},"from":"18","status":"changed","to":"19"}],"content_hash":"8de8d0ea7f0036ef1f591c6b5ba549918d5725c7f69628e47a5157160b76af82","context":"","default_changed_in":[],"default_history":[{"from":"18","to":"19","value":"Empty string"}],"editorial":{"advice":{"olap":"Use the same TLS floor for analytical traffic; benchmark only after correctness because bulk transfer may expose CPU cost but is not a reason to accept obsolete protocols.","oltp":"Treat ssl_tls13_ciphers as transport-security policy rather than a performance knob. Follow the organization's TLS baseline and test certificate rotation, reload, and every client class.","small":"Keep ssl_tls13_ciphers simple and secure, using managed certificates and library defaults reviewed for the installed OpenSSL version. Rehearse renewal before expiry."},"mechanism":["ssl_tls13_ciphers sets the list of allowed TLSv1.3 cipher suites. An empty string means use the default cipher suites. An empty value delegates TLS 1.3 suite selection to the SSL library default, and the syntax is distinct from ssl_ciphers.","ssl_tls13_ciphers is a SIGHUP-context setting: a configuration reload activates the new server value without a restart; subsequent operations that consult it use the refreshed value. Existing TLS sessions are not renegotiated.","It participates in the TLS context used for new handshakes. ssl enables transport, pg_hba.conf decides which connection classes require it, and the certificate, key, CA, revocation, protocol, and cipher settings must form one valid policy."],"pitfalls":["Editing ssl_tls13_ciphers without reloading configuration and verifying the effective value and subsequent behavior.","Updating only one TLS file or policy knob and leaving an invalid chain, unreadable key, or incompatible protocol set.","Assuming a reload renegotiates existing sessions; TLS policy changes affect new handshakes.","Using ssl_ciphers syntax or names for TLS 1.3 and unintentionally rejecting every intended suite."],"references":[{"title":"PostgreSQL 19 Beta 4: ssl_tls13_ciphers","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-SSL-TLS13-CIPHERS"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["ssl_ciphers","ssl_min_protocol_version","ssl_max_protocol_version","ssl_prefer_server_ciphers","ssl_groups"],"summary":"ssl_tls13_ciphers is the PostgreSQL setting that defines the list of allowed TLSv1.3 cipher suites."},"enumvals":[],"first_version":"18","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:32.051292+08:00","intro_commit":{"authored_at":"2024-10-24T15:20:32+02:00","discussion":["https://postgr.es/m/tencent_063F89FA72CCF2E48A0DF5338841988E9809@qq.com"],"hash":"45188c2ea2391b7b24039e1632c726e2fc6b8008","subject":"Support configuring TLSv1.3 cipher suites","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=45188c2ea2391b7b24039e1632c726e2fc6b8008"},"key":"ssl_tls13_ciphers","last_version":"20","max_val":"","min_val":"","name":"ssl_tls13_ciphers","position":383,"present_in":["18","19","20"],"short_desc":"Specifies a list of cipher suites that are allowed by connections using TLS version 1.3.","short_desc_zh":"","source_rev":"english-manuals:6e76eb8ab9c7544811eab6f1ad38f8129dabe4564ea4d3f9bebe3a145dbe68e4","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"ssl_tls13_ciphers","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"ssl_tls13_ciphers","SourceRevision":"english-manuals:6e76eb8ab9c7544811eab6f1ad38f8129dabe4564ea4d3f9bebe3a145dbe68e4","Facts":{"boot_val":"","category":"Connections and Authentication / SSL","context":"sighup","description":"Specifies a list of cipher suites that are allowed by connections using TLS version 1.3. Multiple cipher suites can be specified by using a colon separated list. If left blank, the default set of cipher suites in OpenSSL will be used. This parameter can only be set in the postgresql.conf file or on the server command line.","doc":{"anchor":"GUC-SSL-TLS13-CIPHERS","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"An empty string means use the default cipher suites.","lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"ssl_tls13_ciphers","short_desc":"Sets the list of allowed TLSv1.3 cipher suites.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-SSL-TLS13-CIPHERS","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"ssl_tls13_ciphers","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"ssl_tls13_ciphers","Summary":"","BodyHTML":"\u003cp\u003e指定允许用于 TLS 版本 1.3 连接的密码套件列表。可以使用冒号分隔的列表指定多个密码套件。如果留空，将使用\u003cspan\u003eOpenSSL\u003c/span\u003e的默认密码套件集。\u003c/p\u003e\u003cp\u003e这个参数只能在\u003ccode\u003epostgresql.conf\u003c/code\u003e文件中或者服务器命令行上设置。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"b3f78f615af0c305d444c560fe6fd12b726a636a415cd5de25009c7e0d11e7ed","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e指定允许用于 TLS 版本 1.3 连接的密码套件列表。可以使用冒号分隔的列表指定多个密码套件。如果留空，将使用\u003cspan class=\"productname\"\u003eOpenSSL\u003c/span\u003e的默认密码套件集。\u003c/p\u003e\u003cp\u003e这个参数只能在\u003ccode class=\"filename\"\u003epostgresql.conf\u003c/code\u003e文件中或者服务器命令行上设置。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["18","19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
