{"kind": "conn", "major": "18", "item": {"slug": "sslmode", "name": "sslmode", "name_zh": "", "category": "TLS", "summary": "\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a", "aliases": ["PGSSLMODE", "sslmode"], "content_hash": "4c36407295b7cedcc8afd2ce4bf71ff4bd6dfb2f1a96457e7a65e6c243ac6e92", "versions": {"10": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 10.23"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/10/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/10/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/10/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/10/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "label": "10.23", "major": "10", "channel": "historical", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/10/postgresql-10-A4.pdf", "bytes": 12631706, "pages": 2591, "sha256": "34497ab9efb45c5bdf1bd11b9016b5451354feb462fa029cf74557a5fa5fbbc1", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/10/postgresql-10-US.pdf", "bytes": 12531684, "pages": 2724, "sha256": "429cc7133ddf4f97c560aa466dc9caea4b718721a8321e293357037cf0af4733", "built_at": "2026-09-26"}}, "tree": "10", "index": "index.html", "major": "10", "pages": 1085, "release": "10.23", "source_url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "svg_assets": 0, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, "revision": "f9301feba91e2e2566038a36b8cee0e4402db68989538f88670fddd20b1f78ea", "evidence_kind": "English manual and source declarations", "source_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, "sources": [{"url": "https://pg.center/docs/10/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "10.23 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "153ad57ac835922140534bebdbfc61776676beddc59f85c240e039721e514699", "language": "en", "original_url": "/docs/10/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v10.23/postgresql-10.23.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "10.23 libpq connection option declarations", "sha256": "de8b800e515b3bf4dfe66cafcdfbb34133ec7c5848f255eabb2a1d4c0855d214", "archive_sha256": "94a4b2528372458e5662c18d406629266667c437198160a18cdfd2c4a4d6eee9"}, {"url": "https://pg.center/docs/10/libpq-envars.html", "file": "libpq-envars.html", "label": "10.23 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "241a428dcfcac6131f39c8d9f1f178fa15a8ebe331381fe738f1ceb12ca22c54", "language": "en", "original_url": "/docs/10/libpq-envars.html"}, {"url": "https://pg.center/docs/10/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "10.23 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "9b317c875bed047e3baba0da1777c71257c0d4a636392624f4e4f3c3337b0912", "language": "en", "original_url": "/docs/10/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/10/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span></dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8fd9\u4e9b\u9009\u9879\u7684\u8be6\u7ec6\u5de5\u4f5c\u65b9\u5f0f\u89c1\u7b2c 33.18 \u8282\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/10/libpq-envars.html", "method": "same-major semantic node", "sha256": "56efca8d413009f717bd99f94ab808040a7eb49606882cc85485bbfec4619f1a", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[11]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/10/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "6b8334d15f0f994e6ff4d5737cd83a42dd99bb9df772cc68e9a52f4334fcdbdf", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/10/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/10/facts/0/label": "Client library", "/versions/10/facts/1/label": "Manual definition", "/versions/10/facts/1/value": "Documented", "/versions/10/facts/2/label": "Source environment fallback", "/versions/10/facts/3/label": "Compiled fallback expression", "/versions/10/tables/0/title": "Environment fallback", "/versions/10/related/0/label": "Connection service file", "/versions/10/related/1/label": "Password file", "/versions/10/related/2/label": "All libpq environment variables", "/versions/10/sections/0/title": "Default resolution and service-file precedence", "/versions/10/sections/1/title": "Environment variable evidence", "/versions/10/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/10/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/10/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/10/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/10/tables/0/columns/0/label": "Variable", "/versions/10/tables/0/columns/1/label": "Documented behavior", "/versions/10/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "61e16ed724e82e3815f959f02105e895108b6e694d9f7b0c5ca03f7dc519f24c"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 33.18 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection.", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "bf125181fac40b07538111a7f0f86b9efb5de0ae505d04a7221a59b546bb06f1", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "11": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 11.22"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/11/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/11/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/11/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/11/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "label": "11.22", "major": "11", "channel": "historical", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/11/postgresql-11-A4.pdf", "bytes": 13057499, "pages": 2732, "sha256": "41d75855e610d0d9b8802b87dc5b080bef8d7e91c7cf69401fbf8d3cf801b4b5", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/11/postgresql-11-US.pdf", "bytes": 12961189, "pages": 2883, "sha256": "6a8899ef36935a5b7ed2b436207564a567a4ef1eb1c2200195876b8de4d4fa30", "built_at": "2026-09-26"}}, "tree": "11", "index": "index.html", "major": "11", "pages": 1125, "release": "11.22", "source_url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "svg_assets": 0, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, "revision": "53315ddaf3b3f9e6669fd1edc096bbb2cd4a65ea3e836c89e542b43af9ba3a7f", "evidence_kind": "English manual and source declarations", "source_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, "sources": [{"url": "https://pg.center/docs/11/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "11.22 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "51609c4e32eec49656c45de2c14a8ad69e10c9b3300bc9c57658857fcee1d824", "language": "en", "original_url": "/docs/11/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v11.22/postgresql-11.22.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "11.22 libpq connection option declarations", "sha256": "89673096491d2ff370af0e614e035336cba52c14107a4ea22bb0ed234fa1c684", "archive_sha256": "2cb7c97d7a0d7278851bbc9c61f467b69c094c72b81740b751108e7892ebe1f0"}, {"url": "https://pg.center/docs/11/libpq-envars.html", "file": "libpq-envars.html", "label": "11.22 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "0012607dbb5e04e9ed34fd34a0eb8de14f0a6f5cb07fe95ca868fb2fddf426b5", "language": "en", "original_url": "/docs/11/libpq-envars.html"}, {"url": "https://pg.center/docs/11/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "11.22 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "c0f63b0b0757a3ca6f35c8f6617ee3850d5536c11fabc4fa747ad18467a26f6f", "language": "en", "original_url": "/docs/11/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/11/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span></dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8fd9\u4e9b\u9009\u9879\u7684\u8be6\u7ec6\u5de5\u4f5c\u65b9\u5f0f\u89c1\u7b2c 34.18 \u8282\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/11/libpq-envars.html", "method": "same-major semantic node", "sha256": "241bdfa477deab32c613f06960089b27077afab17eb7b335b76d77a3bdfa2b43", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[11]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/11/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "75b71911d8a339c968c0b84531b4ac1922b3eac509a3aa0f899773ed1ad6d494", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/11/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/11/facts/0/label": "Client library", "/versions/11/facts/1/label": "Manual definition", "/versions/11/facts/1/value": "Documented", "/versions/11/facts/2/label": "Source environment fallback", "/versions/11/facts/3/label": "Compiled fallback expression", "/versions/11/tables/0/title": "Environment fallback", "/versions/11/related/0/label": "Connection service file", "/versions/11/related/1/label": "Password file", "/versions/11/related/2/label": "All libpq environment variables", "/versions/11/sections/0/title": "Default resolution and service-file precedence", "/versions/11/sections/1/title": "Environment variable evidence", "/versions/11/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/11/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/11/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/11/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/11/tables/0/columns/0/label": "Variable", "/versions/11/tables/0/columns/1/label": "Documented behavior", "/versions/11/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "3fc78aba815c92dd3b70252fa48d6328a5c3d282550269236bcd8b6a8ec78a4b"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 34.18 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection.", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "28e56ade1492b805b5b1b0693ba850df9e7e4eefe6c3daab8da1d7a71fa8d533", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "12": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 12.22"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/12/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/12/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/12/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/12/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "label": "12.22", "major": "12", "channel": "historical", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/12/postgresql-12-A4.pdf", "bytes": 13424351, "pages": 2803, "sha256": "7422cf53fd1939e7a3d2925231a88b0330e468afa5393627cac0ff86158a0621", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/12/postgresql-12-US.pdf", "bytes": 13322565, "pages": 2958, "sha256": "51f3b04e72907fc38512685946223452ea65f84419c60c66241dfa3396035e77", "built_at": "2026-09-26"}}, "tree": "12", "index": "index.html", "major": "12", "pages": 1131, "release": "12.22", "source_url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "svg_assets": 2, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, "revision": "7a827e97cbfacd7febff75f34443e2043e40723de5b6d8c9d81a9430b65a37e4", "evidence_kind": "English manual and source declarations", "source_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, "sources": [{"url": "https://pg.center/docs/12/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "12.22 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "600a43dc93518d62d1c83c8b09d4b695bf1a04e4a5a58b239dc9aa287e83f3d2", "language": "en", "original_url": "/docs/12/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v12.22/postgresql-12.22.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "12.22 libpq connection option declarations", "sha256": "c7b1ad8e03dd5655cabab7572b0a3dc3c9d0f8f1646a5d03a92cd4edbb1d021b", "archive_sha256": "8df3c0474782589d3c6f374b5133b1bd14d168086edbc13c6e72e67dd4527a3b"}, {"url": "https://pg.center/docs/12/libpq-envars.html", "file": "libpq-envars.html", "label": "12.22 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "e4c92c7bbed845b27426c607f96d549f30096a977454ed19608451a26bfb93cb", "language": "en", "original_url": "/docs/12/libpq-envars.html"}, {"url": "https://pg.center/docs/12/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "12.22 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "dc1adeb371e8a783b184c80e9708982e1e44a9da311604009643b12cb41a600c", "language": "en", "original_url": "/docs/12/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/12/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span></dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8fd9\u4e9b\u9009\u9879\u7684\u8be6\u7ec6\u5de5\u4f5c\u65b9\u5f0f\u89c1\u7b2c 33.18 \u8282\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u5982\u679c\u53ef\u4ee5\u4f7f\u7528 GSSAPI \u52a0\u5bc6\uff0c\u65e0\u8bba sslmode \u5982\u4f55\u8bbe\u7f6e\uff0c\u90fd\u4f1a\u4f18\u5148\u4f7f\u7528 GSSAPI \u52a0\u5bc6\u800c\u975e SSL\u3002\u5728\u5177\u6709\u53ef\u7528 GSSAPI \u57fa\u7840\u8bbe\u65bd\uff08\u5982 Kerberos \u670d\u52a1\u5668\uff09\u7684\u73af\u5883\u4e2d\uff0c\u8981\u5f3a\u5236\u4f7f\u7528 SSL\uff0c\u8fd8\u9700\u5c06 gssencmode \u8bbe\u4e3a disable\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/12/libpq-envars.html", "method": "same-major semantic node", "sha256": "9bba02c535ea735e2ff43bd82abaded83cea478820a503ba3403efd95091d864", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[11]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/12/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "7c85a7191f248107e24b48136836ccf7d6b47dfb718db2f8673ea5e19056492b", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/12/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/12/facts/0/label": "Client library", "/versions/12/facts/1/label": "Manual definition", "/versions/12/facts/1/value": "Documented", "/versions/12/facts/2/label": "Source environment fallback", "/versions/12/facts/3/label": "Compiled fallback expression", "/versions/12/tables/0/title": "Environment fallback", "/versions/12/related/0/label": "Connection service file", "/versions/12/related/1/label": "Password file", "/versions/12/related/2/label": "All libpq environment variables", "/versions/12/sections/0/title": "Default resolution and service-file precedence", "/versions/12/sections/1/title": "Environment variable evidence", "/versions/12/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/12/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/12/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/12/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/12/tables/0/columns/0/label": "Variable", "/versions/12/tables/0/columns/1/label": "Documented behavior", "/versions/12/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "dd4847db9274402963ce440bdaccd09ff2cdd0c437c3cb7e7082e8903f41c8a0"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 33.18 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "38794556e5c17260bc16d5edeadb50f04215a636905a7d42df500810e55cd5c2", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "13": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 13.23"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/13/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/13/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/13/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/13/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "label": "13.23", "major": "13", "channel": "historical", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/13/postgresql-13-A4.pdf", "bytes": 13843239, "pages": 2826, "sha256": "171cc09f90936dbc1cbd503a98ff07ae72ea58ab9771ff051313f1217737799c", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/13/postgresql-13-US.pdf", "bytes": 13739572, "pages": 2984, "sha256": "48d09c6e197d9db4220f41afe83efe848a8661b1b168d3b89419751ecaf6c24d", "built_at": "2026-09-26"}}, "tree": "13", "index": "index.html", "major": "13", "pages": 1139, "release": "13.23", "source_url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "svg_assets": 3, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, "revision": "614ee3133270254e476c118cdf6f72af78d4e4b8bbd9b28ed9ab1e14e4e9c0f6", "evidence_kind": "English manual and source declarations", "source_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, "sources": [{"url": "https://pg.center/docs/13/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "13.23 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "2e9c70e9aed0c3850c1af1c7680be465582020bb8c2dfcb009fb9ffe3cd194b6", "language": "en", "original_url": "/docs/13/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v13.23/postgresql-13.23.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "13.23 libpq connection option declarations", "sha256": "406a116bf54e8afc41f76cf0ad669713e981140c9940b54afad98e7393467e9d", "archive_sha256": "6ec3c82726af92b7dec873fa1cdf881eca92a4219787dfad05acb6b10e041fd6"}, {"url": "https://pg.center/docs/13/libpq-envars.html", "file": "libpq-envars.html", "label": "13.23 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "1125e5a919204ff2f54691c1558a08efd818f206f6175cadba3cf6cbc17679bb", "language": "en", "original_url": "/docs/13/libpq-envars.html"}, {"url": "https://pg.center/docs/13/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "13.23 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "d31c36b3039250e7d190706f7b777328c01980795deb0440063c4bfcef125794", "language": "en", "original_url": "/docs/13/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/13/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span></dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8fd9\u4e9b\u9009\u9879\u7684\u8be6\u7ec6\u5de5\u4f5c\u65b9\u5f0f\u89c1\u7b2c 33.18 \u8282\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u5982\u679c\u53ef\u4ee5\u4f7f\u7528 GSSAPI \u52a0\u5bc6\uff0c\u65e0\u8bba sslmode \u5982\u4f55\u8bbe\u7f6e\uff0c\u90fd\u4f1a\u4f18\u5148\u4f7f\u7528 GSSAPI \u52a0\u5bc6\u800c\u975e SSL\u3002\u5728\u5177\u6709\u53ef\u7528 GSSAPI \u57fa\u7840\u8bbe\u65bd\uff08\u5982 Kerberos \u670d\u52a1\u5668\uff09\u7684\u73af\u5883\u4e2d\uff0c\u8981\u5f3a\u5236\u4f7f\u7528 SSL\uff0c\u8fd8\u9700\u5c06 gssencmode \u8bbe\u4e3a disable\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/13/libpq-envars.html", "method": "same-major semantic node", "sha256": "37579b6a9d7ad440f343971936ecd2c3935b572a9b756ae5dd257c4004f3f008", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[12]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/13/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "e9f777dc2f7218013fb5d63e3b2c81acf8a8c2e6fe7c0c7f6dd82f15f9632bf4", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/13/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/13/facts/0/label": "Client library", "/versions/13/facts/1/label": "Manual definition", "/versions/13/facts/1/value": "Documented", "/versions/13/facts/2/label": "Source environment fallback", "/versions/13/facts/3/label": "Compiled fallback expression", "/versions/13/tables/0/title": "Environment fallback", "/versions/13/related/0/label": "Connection service file", "/versions/13/related/1/label": "Password file", "/versions/13/related/2/label": "All libpq environment variables", "/versions/13/sections/0/title": "Default resolution and service-file precedence", "/versions/13/sections/1/title": "Environment variable evidence", "/versions/13/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/13/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/13/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/13/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/13/tables/0/columns/0/label": "Variable", "/versions/13/tables/0/columns/1/label": "Documented behavior", "/versions/13/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "b3cadac466080857e6d4293ba46c2dd189cb29f5bf7e9acf7ce2d9936d3c8688"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 33.18 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "38794556e5c17260bc16d5edeadb50f04215a636905a7d42df500810e55cd5c2", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "14": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 14.24"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/14/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/14/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/14/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/14/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "label": "14.24", "major": "14", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/14/postgresql-14-A4.pdf", "bytes": 14354704, "pages": 2944, "sha256": "8bc6b9dd7b246888bb77f0a5e8c39a2eae52e9926569832669c7d1600becb27c", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/14/postgresql-14-US.pdf", "bytes": 14242178, "pages": 3102, "sha256": "b7ecb5a5f62d8b9f73a69e25a7d26ba285373bc53168a553bff7b77955506db4", "built_at": "2026-09-26"}}, "tree": "14", "index": "index.html", "major": "14", "pages": 1158, "release": "14.24", "source_url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "svg_assets": 3, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, "revision": "588700d46356d8837c77c7c0a4e71e645fe6535983b8f1830aa8f2e4e41c40ae", "evidence_kind": "English manual and source declarations", "source_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, "sources": [{"url": "https://pg.center/docs/14/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "14.24 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "4cacc729dd3093cfa7b6528d9a22800392070b8eba1106da9a3d540629ae98a8", "language": "en", "original_url": "/docs/14/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v14.24/postgresql-14.24.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "14.24 libpq connection option declarations", "sha256": "8dbe7c41927bd93713fce72495616fab20f888775fc95c01a6f2f710087caff7", "archive_sha256": "a7fa7ed3d558172355f51406097a7bd4f6b473be80f311ef7cda96bf383d8897"}, {"url": "https://pg.center/docs/14/libpq-envars.html", "file": "libpq-envars.html", "label": "14.24 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "0222834e8076ac3a09545133c2a98dbfdd094dc589bcea847934931d1903a76f", "language": "en", "original_url": "/docs/14/libpq-envars.html"}, {"url": "https://pg.center/docs/14/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "14.24 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "0208611ef07704d22d30b69db7132fb062f8caf3a3bd38a77f23c3696a447cb9", "language": "en", "original_url": "/docs/14/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/14/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span></dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8fd9\u4e9b\u9009\u9879\u7684\u8be6\u7ec6\u5de5\u4f5c\u65b9\u5f0f\u89c1\u7b2c 34.19 \u8282\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u5982\u679c\u53ef\u4ee5\u4f7f\u7528 GSSAPI \u52a0\u5bc6\uff0c\u65e0\u8bba sslmode \u5982\u4f55\u8bbe\u7f6e\uff0c\u90fd\u4f1a\u4f18\u5148\u4f7f\u7528 GSSAPI \u52a0\u5bc6\u800c\u975e SSL\u3002\u5728\u5177\u6709\u53ef\u7528 GSSAPI \u57fa\u7840\u8bbe\u65bd\uff08\u5982 Kerberos \u670d\u52a1\u5668\uff09\u7684\u73af\u5883\u4e2d\uff0c\u8981\u5f3a\u5236\u4f7f\u7528 SSL\uff0c\u8fd8\u9700\u5c06 gssencmode \u8bbe\u4e3a disable\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/14/libpq-envars.html", "method": "same-major semantic node", "sha256": "7730429c9ed41dfd04210ac6c4c11ecb7dae5cd8ef5e7f5224e53a02eb8e7219", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[12]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/14/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "ca623924f7c1365661a6549a08305bb467cd63207e63c2fff50f51124d070ace", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/14/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/14/facts/0/label": "Client library", "/versions/14/facts/1/label": "Manual definition", "/versions/14/facts/1/value": "Documented", "/versions/14/facts/2/label": "Source environment fallback", "/versions/14/facts/3/label": "Compiled fallback expression", "/versions/14/tables/0/title": "Environment fallback", "/versions/14/related/0/label": "Connection service file", "/versions/14/related/1/label": "Password file", "/versions/14/related/2/label": "All libpq environment variables", "/versions/14/sections/0/title": "Default resolution and service-file precedence", "/versions/14/sections/1/title": "Environment variable evidence", "/versions/14/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/14/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/14/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/14/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/14/tables/0/columns/0/label": "Variable", "/versions/14/tables/0/columns/1/label": "Documented behavior", "/versions/14/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "0e7aa7a44e9755bbbc19ce928e20bb6691e87309ede47734d6e59dad599a0ee4"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 34.19 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "4d20c905793a5b4ccea1d7d61f7e0b9ae13e62051c1892e4f266befa09d319cd", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "15": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 15.19"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/15/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/15/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/15/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/15/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "label": "15.19", "major": "15", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/15/postgresql-15-A4.pdf", "bytes": 14609140, "pages": 2987, "sha256": "66228564a4d16efb47d6a914085716ecfe22ca1566db56bc7c3d82f790646d72", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/15/postgresql-15-US.pdf", "bytes": 14495690, "pages": 3153, "sha256": "645a498c2390d47a6223ec74770631185807a19c484edb0fc5a295d9f460bc02", "built_at": "2026-09-26"}}, "tree": "15", "index": "index.html", "major": "15", "pages": 1168, "release": "15.19", "source_url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "svg_assets": 3, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, "revision": "6af958c6520151fc7697d56e0616b03fb00522c4568158674d452ae0644ba545", "evidence_kind": "English manual and source declarations", "source_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, "sources": [{"url": "https://pg.center/docs/15/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "15.19 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "64a9c015aa67f085bd343fc47439d7a15fd8b6583b0d6f3cf94d7bb94b6f544a", "language": "en", "original_url": "/docs/15/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v15.19/postgresql-15.19.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "15.19 libpq connection option declarations", "sha256": "63bd4ab01b7161916c0a86a4510f36d287c3ef4e78910568cde611bb925dd9f2", "archive_sha256": "e1a64a87a46b825b88c082e4518161a47aab53c45694964f8ba1df28f7859f89"}, {"url": "https://pg.center/docs/15/libpq-envars.html", "file": "libpq-envars.html", "label": "15.19 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "2744c085549e5c53c9cde2147b57b93387276297bb0f545bdf7838595878100d", "language": "en", "original_url": "/docs/15/libpq-envars.html"}, {"url": "https://pg.center/docs/15/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "15.19 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "7081175cdd79775d0be65f2af8751f386ea5a006c3f185699be5f7bd1097321b", "language": "en", "original_url": "/docs/15/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/15/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span></dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8fd9\u4e9b\u9009\u9879\u7684\u8be6\u7ec6\u5de5\u4f5c\u65b9\u5f0f\u89c1\u7b2c 34.19 \u8282\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u5982\u679c\u53ef\u4ee5\u4f7f\u7528 GSSAPI \u52a0\u5bc6\uff0c\u65e0\u8bba sslmode \u5982\u4f55\u8bbe\u7f6e\uff0c\u90fd\u4f1a\u4f18\u5148\u4f7f\u7528 GSSAPI \u52a0\u5bc6\u800c\u975e SSL\u3002\u5728\u5177\u6709\u53ef\u7528 GSSAPI \u57fa\u7840\u8bbe\u65bd\uff08\u5982 Kerberos \u670d\u52a1\u5668\uff09\u7684\u73af\u5883\u4e2d\uff0c\u8981\u5f3a\u5236\u4f7f\u7528 SSL\uff0c\u8fd8\u9700\u5c06 gssencmode \u8bbe\u4e3a disable\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/15/libpq-envars.html", "method": "same-major semantic node", "sha256": "9cc15a47821a9748b9115ad8cbe122178c733cf61ffd24595efd8a31fe10caea", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[12]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/15/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "26185a5568858f5dd3ac13624ca83483003538fdce81ed3d60749cfa52a4f47d", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/15/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/15/facts/0/label": "Client library", "/versions/15/facts/1/label": "Manual definition", "/versions/15/facts/1/value": "Documented", "/versions/15/facts/2/label": "Source environment fallback", "/versions/15/facts/3/label": "Compiled fallback expression", "/versions/15/tables/0/title": "Environment fallback", "/versions/15/related/0/label": "Connection service file", "/versions/15/related/1/label": "Password file", "/versions/15/related/2/label": "All libpq environment variables", "/versions/15/sections/0/title": "Default resolution and service-file precedence", "/versions/15/sections/1/title": "Environment variable evidence", "/versions/15/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/15/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/15/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/15/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/15/tables/0/columns/0/label": "Variable", "/versions/15/tables/0/columns/1/label": "Documented behavior", "/versions/15/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "9e37c93f6cef7f11f19eb2b4f85c6caa3cb3146064f970e30b8cfec02968f8f0"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 34.19 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "4d20c905793a5b4ccea1d7d61f7e0b9ae13e62051c1892e4f266befa09d319cd", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "16": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 16.15"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/16/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/16/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/16/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/16/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "label": "16.15", "major": "16", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/16/postgresql-16-A4.pdf", "bytes": 15282337, "pages": 3055, "sha256": "4bb6c1f63deedac98736d8c4c7bc0fad0ac24e85b07e21ee10411872f06afd06", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/16/postgresql-16-US.pdf", "bytes": 15164148, "pages": 3220, "sha256": "5b6b6166c89991199e144bb0ae34c17a5f29826251dbf19db1abc0df3a3e771b", "built_at": "2026-09-26"}}, "tree": "16", "index": "index.html", "major": "16", "pages": 1169, "release": "16.15", "source_url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "svg_assets": 3, "source_mode": "en HTML verified against the pinned official archive", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, "revision": "3c21e58b35318021716440e67bb8bafd392b6a2b965a244d90e9e33c99e0bdef", "evidence_kind": "English manual and source declarations", "source_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, "sources": [{"url": "https://pg.center/docs/16/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "16.15 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "a88a6c8f0e2229b1e469ca3fcf95d6cba163af369f2c232c04c07ba0a5b64242", "language": "en", "original_url": "/docs/16/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v16.15/postgresql-16.15.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "16.15 libpq connection option declarations", "sha256": "ccc43473f7a01820f1ef625a8704548db03499bdee02ef943adbd1329f17f9e7", "archive_sha256": "c1575341fa7bd40f5274ea465b34390f4dc64cdd0770af327005caaeb9f6b7ed"}, {"url": "https://pg.center/docs/16/libpq-envars.html", "file": "libpq-envars.html", "label": "16.15 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "2dd3190c2f6b9e0d3051b7cc325bb30dad84b29e53035680aa622409ad00fe28", "language": "en", "original_url": "/docs/16/libpq-envars.html"}, {"url": "https://pg.center/docs/16/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "16.15 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "d636639599c1db7c0eb9da6c188abfbf7c590bb2ae9367e7fff05863bb9bd0db", "language": "en", "original_url": "/docs/16/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/16/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span> </dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8fd9\u4e9b\u9009\u9879\u7684\u8be6\u7ec6\u5de5\u4f5c\u65b9\u5f0f\u89c1\u7b2c 34.19 \u8282\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u5982\u679c\u53ef\u4ee5\u4f7f\u7528 GSSAPI \u52a0\u5bc6\uff0c\u65e0\u8bba sslmode \u5982\u4f55\u8bbe\u7f6e\uff0c\u90fd\u4f1a\u4f18\u5148\u4f7f\u7528 GSSAPI \u52a0\u5bc6\u800c\u975e SSL\u3002\u5728\u5177\u6709\u53ef\u7528 GSSAPI \u57fa\u7840\u8bbe\u65bd\uff08\u5982 Kerberos \u670d\u52a1\u5668\uff09\u7684\u73af\u5883\u4e2d\uff0c\u8981\u5f3a\u5236\u4f7f\u7528 SSL\uff0c\u8fd8\u9700\u5c06 gssencmode \u8bbe\u4e3a disable\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/16/libpq-envars.html", "method": "same-major semantic node", "sha256": "841a7b2a5d33a812cca40c163dcc0a97350d036c7a31d73230803a40d5c8e917", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[13]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/16/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "6facaad2a42331e2d577d3abc10e1cd4a7af12acb08715071c1996e2caa39239", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/16/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/16/facts/0/label": "Client library", "/versions/16/facts/1/label": "Manual definition", "/versions/16/facts/1/value": "Documented", "/versions/16/facts/2/label": "Source environment fallback", "/versions/16/facts/3/label": "Compiled fallback expression", "/versions/16/tables/0/title": "Environment fallback", "/versions/16/related/0/label": "Connection service file", "/versions/16/related/1/label": "Password file", "/versions/16/related/2/label": "All libpq environment variables", "/versions/16/sections/0/title": "Default resolution and service-file precedence", "/versions/16/sections/1/title": "Environment variable evidence", "/versions/16/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/16/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/16/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/16/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/16/tables/0/columns/0/label": "Variable", "/versions/16/tables/0/columns/1/label": "Documented behavior", "/versions/16/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "250ca32a3a60e466c26621b436d967d8cf5c027e24ce748d063c3f5f826c4b67"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 34.19 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "4d20c905793a5b4ccea1d7d61f7e0b9ae13e62051c1892e4f266befa09d319cd", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "17": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 17.11"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/17/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/17/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/17/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/17/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/17/postgresql-17-A4.pdf", "bytes": 15521293, "pages": 3099, "sha256": "1991354df0dc89e70ec39328c28988ef8b19c6a93671dab3893650b63e9f4e36", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/17/postgresql-17-US.pdf", "bytes": 15398150, "pages": 3270, "sha256": "07696c8f38abf31babf22d2db337093936e7c472d2af36d050b000c49bbcf52c", "built_at": "2026-09-26"}}, "tree": "17", "index": "index.html", "major": "17", "pages": 1143, "release": "17.11", "source_url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, "revision": "58419c9b0dd42cb34c8d53695bb025a7e582edf55ccd4c5bcb1c2c7c71a37487", "evidence_kind": "English manual and source declarations", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, "sources": [{"url": "https://pg.center/docs/17/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "17.11 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "7f15cf88e7854d7e92b57bdcb85ce566543eee5783ebc8eb2972cd6aaca8e7a1", "language": "en", "original_url": "/docs/17/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "17.11 libpq connection option declarations", "sha256": "9c189446b1b18faf81823636067c9cf9fb01215bdae5b036cc3bb0ebc84971a2", "archive_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "https://pg.center/docs/17/libpq-envars.html", "file": "libpq-envars.html", "label": "17.11 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "48fb76414267a67473ccb901e64320de2e73fb0dc8ade8fcea38edf3628d2c21", "language": "en", "original_url": "/docs/17/libpq-envars.html"}, {"url": "https://pg.center/docs/17/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "17.11 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "1447c3836f348d6d0ea59ab68fe17ef604eb913938eed81c1e2cb081a36e2d8d", "language": "en", "original_url": "/docs/17/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/17/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span> </dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8be6\u7ec6\u4e86\u89e3\u8fd9\u4e9b\u9009\u9879\u5982\u4f55\u5de5\u4f5c\uff0c\u8bf7\u53c2\u9605<a class=\"xref\" href=\"/docs/17/libpq-ssl.html\" title=\"32.19.\u00a0SSL \u652f\u6301\">\u7b2c\u00a032.19\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u5982\u679c\u53ef\u4ee5\u4f7f\u7528 GSSAPI \u52a0\u5bc6\uff0c\u65e0\u8bba sslmode \u5982\u4f55\u8bbe\u7f6e\uff0c\u90fd\u4f1a\u4f18\u5148\u4f7f\u7528 GSSAPI \u52a0\u5bc6\u800c\u975e SSL\u3002\u5728\u5177\u6709\u53ef\u7528 GSSAPI \u57fa\u7840\u8bbe\u65bd\uff08\u5982 Kerberos \u670d\u52a1\u5668\uff09\u7684\u73af\u5883\u4e2d\uff0c\u8981\u5f3a\u5236\u4f7f\u7528 SSL\uff0c\u8fd8\u9700\u5c06 gssencmode \u8bbe\u4e3a disable\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/17/libpq-connect.html", "method": "same-major semantic node", "sha256": "41bb236b80f7c23464be2555c7d20d19551e13f7107cb1d36d58821cbb2f41f1", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[43]/p[2]"]}, {"url": "/docs/17/libpq-envars.html", "method": "same-major semantic node", "sha256": "5f1014f4afd40210bc05e52c10a62fe34fcaf5cc4445cb809ec8cdacb003cf1c", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[14]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/17/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "0544512734d86673b69ac05be91d417df85476fe6048c6d4b197c65a7d566bbe", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/17/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/17/facts/0/label": "Client library", "/versions/17/facts/1/label": "Manual definition", "/versions/17/facts/1/value": "Documented", "/versions/17/facts/2/label": "Source environment fallback", "/versions/17/facts/3/label": "Compiled fallback expression", "/versions/17/tables/0/title": "Environment fallback", "/versions/17/related/0/label": "Connection service file", "/versions/17/related/1/label": "Password file", "/versions/17/related/2/label": "All libpq environment variables", "/versions/17/sections/0/title": "Default resolution and service-file precedence", "/versions/17/sections/1/title": "Environment variable evidence", "/versions/17/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/17/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/17/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/17/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/17/tables/0/columns/0/label": "Variable", "/versions/17/tables/0/columns/1/label": "Documented behavior", "/versions/17/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "f3d009c9a932d74561011b1914278c7366725b32275b2afaaa0502f7f302ab43"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 32.19 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "8cee88b057502e1ab1559e9a8b0b8bdc555df07335cf7edfdd1c462963812a19", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "18": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 18.6"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/18/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/18/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/18/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/18/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/18/postgresql-18-A4.pdf", "bytes": 15865106, "pages": 3154, "sha256": "19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/18/postgresql-18-US.pdf", "bytes": 15748059, "pages": 3328, "sha256": "facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319", "built_at": "2026-09-26"}}, "tree": "18", "index": "index.html", "major": "18", "pages": 1148, "release": "18.6", "source_url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "revision": "ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8", "evidence_kind": "English manual and source declarations", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "sources": [{"url": "https://pg.center/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "18.6 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f", "language": "en", "original_url": "/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "18.6 libpq connection option declarations", "sha256": "44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5", "archive_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/libpq-envars.html", "file": "libpq-envars.html", "label": "18.6 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363", "language": "en", "original_url": "/docs/18/libpq-envars.html"}, {"url": "https://pg.center/docs/18/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "18.6 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7", "language": "en", "original_url": "/docs/18/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/18/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span> </dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8be6\u7ec6\u4e86\u89e3\u8fd9\u4e9b\u9009\u9879\u5982\u4f55\u5de5\u4f5c\uff0c\u8bf7\u53c2\u9605<a class=\"xref\" href=\"/docs/18/libpq-ssl.html\" title=\"32.19.\u00a0SSL \u652f\u6301\">\u7b2c\u00a032.19\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u5982\u679c\u53ef\u4ee5\u4f7f\u7528 GSSAPI \u52a0\u5bc6\uff0c\u65e0\u8bba sslmode \u5982\u4f55\u8bbe\u7f6e\uff0c\u90fd\u4f1a\u4f18\u5148\u4f7f\u7528 GSSAPI \u52a0\u5bc6\u800c\u975e SSL\u3002\u5728\u5177\u6709\u53ef\u7528 GSSAPI \u57fa\u7840\u8bbe\u65bd\uff08\u5982 Kerberos \u670d\u52a1\u5668\uff09\u7684\u73af\u5883\u4e2d\uff0c\u8981\u5f3a\u5236\u4f7f\u7528 SSL\uff0c\u8fd8\u9700\u5c06 gssencmode \u8bbe\u4e3a disable\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/18/libpq-connect.html", "method": "same-major semantic node", "sha256": "bae58c13a65be235aa0408ef12f8bcc7e48f2908cd71080a7dedec225a74c083", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[43]/p[2]"]}, {"url": "/docs/18/libpq-envars.html", "method": "same-major semantic node", "sha256": "8423affb67ef7d4f700d7ccc8c0ef66629341568c8d72530a0c765f3d155da2f", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[14]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/18/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "a06dfcdffbbdf6bd55987cade2d9ff1db6cbfd9f75eb80c7866e8792cd70463e", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/18/facts/0/label": "Client library", "/versions/18/facts/1/label": "Manual definition", "/versions/18/facts/1/value": "Documented", "/versions/18/facts/2/label": "Source environment fallback", "/versions/18/facts/3/label": "Compiled fallback expression", "/versions/18/tables/0/title": "Environment fallback", "/versions/18/related/0/label": "Connection service file", "/versions/18/related/1/label": "Password file", "/versions/18/related/2/label": "All libpq environment variables", "/versions/18/sections/0/title": "Default resolution and service-file precedence", "/versions/18/sections/1/title": "Environment variable evidence", "/versions/18/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/18/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/18/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/18/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/18/tables/0/columns/0/label": "Variable", "/versions/18/tables/0/columns/1/label": "Documented behavior", "/versions/18/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "49745d62011d41f0f6db92ea8cb0f285e222d89388df484eeec8316f998ed4ad"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 32.19 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "8cee88b057502e1ab1559e9a8b0b8bdc555df07335cf7edfdd1c462963812a19", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "19": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 19beta4"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/19/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/19/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/19/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/19/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/19/postgresql-19-A4.pdf", "bytes": 16064841, "pages": 3052, "sha256": "4dd099e4125c591128fc5f3ebd02178dc24781f9e5ae629f96d67c4c8547427b", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/19/postgresql-19-US.pdf", "bytes": 15974616, "pages": 3225, "sha256": "61971fa857f0956d47341a0388fa6af9ae10acf691d4b2fc009007d384b0342b", "built_at": "2026-09-26"}}, "tree": "19", "index": "index.html", "major": "19", "pages": 1155, "release": "19beta4", "source_url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "svg_assets": 5, "source_mode": "en SGML built with pinned official archive", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, "revision": "1bbbbf4133d426f0e4304010688d2984c30fb67df0cc3a61b3e37eb3f6f37833", "evidence_kind": "English manual and source declarations", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, "sources": [{"url": "https://pg.center/docs/19/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "19beta4 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "14917417235a95d969bf3642c347dea7ae548c5f73b0dd00991a580ebcfbb47e", "language": "en", "original_url": "/docs/19/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "19beta4 libpq connection option declarations", "sha256": "ae8005372c570ff47a4922c942238653a034f01f9db40c9e0f57cb48915ffd98", "archive_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "https://pg.center/docs/19/libpq-envars.html", "file": "libpq-envars.html", "label": "19beta4 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d8f0afee19bae6323942ea5415649fbd66e3880fe8c8415350fcf3915f7c7047", "language": "en", "original_url": "/docs/19/libpq-envars.html"}, {"url": "https://pg.center/docs/19/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "19beta4 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "4c858fe55701d703cc00e7adf55eeac09cafcfdc37929b8e23ccf8ba42af9f98", "language": "en", "original_url": "/docs/19/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u5728 libpq \u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u4f7f\u7528 servicefile \u5173\u952e\u5b57\uff0c\u6216\u8005\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/19/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span> </dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8be6\u7ec6\u4e86\u89e3\u8fd9\u4e9b\u9009\u9879\u5982\u4f55\u5de5\u4f5c\uff0c\u8bf7\u53c2\u9605<a class=\"xref\" href=\"/docs/19/libpq-ssl.html\" title=\"32.19.\u00a0SSL \u652f\u6301\">\u7b2c\u00a032.19\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u5982\u679c\u53ef\u4ee5\u4f7f\u7528 GSSAPI \u52a0\u5bc6\uff0c\u65e0\u8bba sslmode \u5982\u4f55\u8bbe\u7f6e\uff0c\u90fd\u4f1a\u4f18\u5148\u4f7f\u7528 GSSAPI \u52a0\u5bc6\u800c\u975e SSL\u3002\u5728\u5177\u6709\u53ef\u7528 GSSAPI \u57fa\u7840\u8bbe\u65bd\uff08\u5982 Kerberos \u670d\u52a1\u5668\uff09\u7684\u73af\u5883\u4e2d\uff0c\u8981\u5f3a\u5236\u4f7f\u7528 SSL\uff0c\u8fd8\u9700\u5c06 gssencmode \u8bbe\u4e3a disable\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/19/libpq-connect.html", "method": "same-major semantic node", "sha256": "8a146554e35097ee5bd56228b90d2a83442c7bd6ca303bdd01de148d06928cd3", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[43]/p[2]"]}, {"url": "/docs/19/libpq-envars.html", "method": "same-major semantic node", "sha256": "1c8f71428ae8cd8acf564cb581b51a0bce2bf0102680e44c1ced261aa3ec55f7", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[14]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/19/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "ed80600a221e79a10c683341a2d8b9fa12c84e00c638b7969a72feb8b3c467d3", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/19/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/19/facts/0/label": "Client library", "/versions/19/facts/1/label": "Manual definition", "/versions/19/facts/1/value": "Documented", "/versions/19/facts/2/label": "Source environment fallback", "/versions/19/facts/3/label": "Compiled fallback expression", "/versions/19/tables/0/title": "Environment fallback", "/versions/19/related/0/label": "Connection service file", "/versions/19/related/1/label": "Password file", "/versions/19/related/2/label": "All libpq environment variables", "/versions/19/sections/0/title": "Default resolution and service-file precedence", "/versions/19/sections/1/title": "Environment variable evidence", "/versions/19/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/19/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/19/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/19/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/19/tables/0/columns/0/label": "Variable", "/versions/19/tables/0/columns/1/label": "Documented behavior", "/versions/19/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "3ff66beabbb0165eac7a62ab2911c00a060f1b6b43ff7582f20229cee7ee5d3e"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 32.19 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "8cee88b057502e1ab1559e9a8b0b8bdc555df07335cf7edfdd1c462963812a19", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "20": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 20devel"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/devel/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/devel/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/devel/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/devel/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/20/postgresql-20-A4.pdf", "bytes": 16030631, "pages": 3052, "sha256": "bd5d82c0ce38fc18f92a0447818a91a193a261776bca1c37564bf9a683e177d0", "built_at": "2026-09-28"}, "US": {"url": "/files/documentation/pdf/20/postgresql-20-US.pdf", "bytes": 15936613, "pages": 3223, "sha256": "d97d9e0db479a02f4234b175f50fcad70c3661619afc8d6df9b9437882e3c299", "built_at": "2026-09-28"}}, "tree": "0", "index": "index.html", "major": "20", "pages": 1156, "release": "20devel", "source_url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "svg_assets": 6, "source_mode": "en SGML built with pinned official archive", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_snapshot_utc": "26-Sep-2026 20:22"}, "revision": "2eba5e0fd4c3bffb2803247b6cd537878e9d6ee5a6dfbe3c50ece8b421b80918", "evidence_kind": "English manual and source declarations", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, "sources": [{"url": "https://pg.center/docs/devel/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "20devel English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "eeb28ce798c0f99c3581400b4baaae7687ee5d4176fcb9f5d2fd28809282d48f", "language": "en", "original_url": "/docs/devel/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "20devel libpq connection option declarations", "sha256": "d6eab6e2f37054b32a7ee7039b53beae603316f8ec3f0a14716061e042fc4aa1", "archive_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "https://pg.center/docs/devel/libpq-envars.html", "file": "libpq-envars.html", "label": "20devel English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "7c49cf204e26ea86654491db5ea06c4f558c670e2e60a60b1dbf708ce682accc", "language": "en", "original_url": "/docs/devel/libpq-envars.html"}, {"url": "https://pg.center/docs/devel/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "20devel English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "a1ccd63a6e307a5541d58eabd57be5b467dff2480770838ec9b6a59a3ef110dc", "language": "en", "original_url": "/docs/devel/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u5728 libpq \u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u4f7f\u7528 servicefile \u5173\u952e\u5b57\uff0c\u6216\u8005\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/devel/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span> </dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8be6\u7ec6\u4e86\u89e3\u8fd9\u4e9b\u9009\u9879\u5982\u4f55\u5de5\u4f5c\uff0c\u8bf7\u53c2\u9605<a class=\"xref\" href=\"/docs/devel/libpq-ssl.html\" title=\"32.18.\u00a0SSL \u652f\u6301\">\u7b2c\u00a032.18\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u5982\u679c\u53ef\u4ee5\u4f7f\u7528 GSSAPI \u52a0\u5bc6\uff0c\u65e0\u8bba sslmode \u5982\u4f55\u8bbe\u7f6e\uff0c\u90fd\u4f1a\u4f18\u5148\u4f7f\u7528 GSSAPI \u52a0\u5bc6\u800c\u975e SSL\u3002\u5728\u5177\u6709\u53ef\u7528 GSSAPI \u57fa\u7840\u8bbe\u65bd\uff08\u5982 Kerberos \u670d\u52a1\u5668\uff09\u7684\u73af\u5883\u4e2d\uff0c\u8981\u5f3a\u5236\u4f7f\u7528 SSL\uff0c\u8fd8\u9700\u5c06 gssencmode \u8bbe\u4e3a disable\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/devel/libpq-connect.html", "method": "same-major semantic node", "sha256": "80a1ddba976c7228bb9d179e08545f0a6328ffc9b880481df17a53fdebf42bb5", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[43]/p[2]"]}, {"url": "/docs/devel/libpq-envars.html", "method": "same-major semantic node", "sha256": "b4afd6d100d2be289d48e1a6f6fb9804dd0b684798b7dabf8bae7d3db074117f", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[14]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/devel/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "acea589bbba517979fe815bd3bff32cd6d5e6323e1d5b4f395d7864338868b26", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/summary": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/20/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/20/facts/0/label": "Client library", "/versions/20/facts/1/label": "Manual definition", "/versions/20/facts/1/value": "Documented", "/versions/20/facts/2/label": "Source environment fallback", "/versions/20/facts/3/label": "Compiled fallback expression", "/versions/20/tables/0/title": "Environment fallback", "/versions/20/related/0/label": "Connection service file", "/versions/20/related/1/label": "Password file", "/versions/20/related/2/label": "All libpq environment variables", "/versions/20/sections/0/title": "Default resolution and service-file precedence", "/versions/20/sections/1/title": "Environment variable evidence", "/versions/20/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/20/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/20/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/20/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/20/tables/0/columns/0/label": "Variable", "/versions/20/tables/0/columns/1/label": "Documented behavior", "/versions/20/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "454f1fac79db14b787f91d713f58daa9b144f3abc07236e539adcb125dc5c2a9"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 32.18 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "dede55281820600f051891279d911d3d76ecda6a0ffaaf5c1318682e4324bea7", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}}}, "snapshot": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 18.6"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLMODE"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLMode"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/18/libpq-envars.html", "text": "PGSSLMODE"}, "description": "PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslmode", "related": [{"url": "/docs/18/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/18/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/18/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/18/postgresql-18-A4.pdf", "bytes": 15865106, "pages": 3154, "sha256": "19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/18/postgresql-18-US.pdf", "bytes": 15748059, "pages": 3328, "sha256": "facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319", "built_at": "2026-09-26"}}, "tree": "18", "index": "index.html", "major": "18", "pages": 1148, "release": "18.6", "source_url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "revision": "ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8", "evidence_kind": "English manual and source declarations", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "sources": [{"url": "https://pg.center/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "file": "libpq-connect.html", "label": "18.6 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLMODE", "sha256": "c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f", "language": "en", "original_url": "/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLMODE"}, {"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "18.6 libpq connection option declarations", "sha256": "44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5", "archive_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/libpq-envars.html", "file": "libpq-envars.html", "label": "18.6 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363", "language": "en", "original_url": "/docs/18/libpq-envars.html"}, {"url": "https://pg.center/docs/18/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "18.6 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7", "language": "en", "original_url": "/docs/18/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLMODE \u7684\u884c\u4e3a\u4e0e sslmode \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslmode", "documented": true, "description": ["\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a"], "environment": [{"name": "PGSSLMODE", "source_url": "/docs/18/libpq-envars.html", "description": "PGSSLMODE behaves the same as the sslmode connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLMODE\"><span class=\"term\"><code class=\"literal\">sslmode</code></span> </dt><dd>\n<p lang=\"zh\">\u51b3\u5b9a\u662f\u5426\u4e0e\u670d\u52a1\u5668\u534f\u5546\u5b89\u5168\u7684 SSL TCP/IP \u8fde\u63a5\uff0c\u4ee5\u53ca\u534f\u5546\u65f6\u7684\u4f18\u5148\u7ea7\u3002\u5171\u6709\u516d\u79cd\u6a21\u5f0f\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">disable</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">allow</code></span></dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt lang=\"zh\">prefer\uff08\u9ed8\u8ba4\u503c\uff09</dt>\n<dd>\n<p lang=\"zh\">\u5148\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5931\u8d25\u540e\u518d\u5c1d\u8bd5\u975e SSL \u8fde\u63a5\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">require</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002\u5982\u679c\u5b58\u5728\u6839 CA \u6587\u4ef6\uff0c\u5219\u6309\u6307\u5b9a verify-ca \u65f6\u76f8\u540c\u7684\u65b9\u5f0f\u9a8c\u8bc1\u8bc1\u4e66\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-ca</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u5e76\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1\u8bc1\u4e66\u9881\u53d1\u673a\u6784\uff08CA\uff09\u7b7e\u53d1\u3002</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">verify-full</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4ec5\u5c1d\u8bd5 SSL \u8fde\u63a5\uff0c\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u7531\u53ef\u4fe1 CA \u7b7e\u53d1\uff0c\u5e76\u9a8c\u8bc1\u8bf7\u6c42\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d\u4e0e\u8bc1\u4e66\u4e2d\u7684\u540d\u79f0\u662f\u5426\u5339\u914d\u3002</p>\n</dd>\n</dl>\n</div>\n<p lang=\"zh\">\u8be6\u7ec6\u4e86\u89e3\u8fd9\u4e9b\u9009\u9879\u5982\u4f55\u5de5\u4f5c\uff0c\u8bf7\u53c2\u9605<a class=\"xref\" href=\"/docs/18/libpq-ssl.html\" title=\"32.19.\u00a0SSL \u652f\u6301\">\u7b2c\u00a032.19\u00a0\u8282</a>\u3002</p>\n<p lang=\"zh\">Unix \u57df\u5957\u63a5\u5b57\u901a\u4fe1\u5ffd\u7565 sslmode\u3002\u5982\u679c PostgreSQL \u6784\u5efa\u65f6\u672a\u542f\u7528 SSL \u652f\u6301\uff0crequire\u3001verify-ca \u548c verify-full \u4f1a\u62a5\u9519\uff1ballow \u548c prefer \u4f1a\u88ab\u63a5\u53d7\uff0c\u4f46 libpq \u5b9e\u9645\u4e0d\u4f1a\u5c1d\u8bd5 SSL \u8fde\u63a5\u3002</p>\n<p lang=\"zh\">\u5982\u679c\u53ef\u4ee5\u4f7f\u7528 GSSAPI \u52a0\u5bc6\uff0c\u65e0\u8bba sslmode \u5982\u4f55\u8bbe\u7f6e\uff0c\u90fd\u4f1a\u4f18\u5148\u4f7f\u7528 GSSAPI \u52a0\u5bc6\u800c\u975e SSL\u3002\u5728\u5177\u6709\u53ef\u7528 GSSAPI \u57fa\u7840\u8bbe\u65bd\uff08\u5982 Kerberos \u670d\u52a1\u5668\uff09\u7684\u73af\u5883\u4e2d\uff0c\u8981\u5f3a\u5236\u4f7f\u7528 SSL\uff0c\u8fd8\u9700\u5c06 gssencmode \u8bbe\u4e3a disable\u3002</p>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLMODE", "localization": {"status": "complete", "sources": [{"url": "/docs/18/libpq-connect.html", "method": "same-major semantic node", "sha256": "bae58c13a65be235aa0408ef12f8bcc7e48f2908cd71080a7dedec225a74c083", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[43]/p[2]"]}, {"url": "/docs/18/libpq-envars.html", "method": "same-major semantic node", "sha256": "8423affb67ef7d4f700d7ccc8c0ef66629341568c8d72530a0c765f3d155da2f", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[14]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/18/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "a06dfcdffbbdf6bd55987cade2d9ff1db6cbfd9f75eb80c7866e8792cd70463e", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:", "/versions/18/facts/0/label": "Client library", "/versions/18/facts/1/label": "Manual definition", "/versions/18/facts/1/value": "Documented", "/versions/18/facts/2/label": "Source environment fallback", "/versions/18/facts/3/label": "Compiled fallback expression", "/versions/18/tables/0/title": "Environment fallback", "/versions/18/related/0/label": "Connection service file", "/versions/18/related/1/label": "Password file", "/versions/18/related/2/label": "All libpq environment variables", "/versions/18/sections/0/title": "Default resolution and service-file precedence", "/versions/18/sections/1/title": "Environment variable evidence", "/versions/18/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/18/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/18/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/18/sections/1/paragraphs/0": "PGSSLMODE behaves the same as the sslmode connection parameter.", "/versions/18/tables/0/columns/0/label": "Variable", "/versions/18/tables/0/columns/1/label": "Documented behavior", "/versions/18/tables/0/rows/0/description": "PGSSLMODE behaves the same as the sslmode connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "49745d62011d41f0f6db92ea8cb0f285e222d89388df484eeec8316f998ed4ad"}, "source_option": {"keyword": "sslmode", "declaration": "\"sslmode\", \"PGSSLMODE\", DefaultSSLMode, NULL, \"SSL-Mode\", \"\", 12, offsetof(struct pg_conn, sslmode)", "environment": "PGSSLMODE", "source_notes": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_data": {"keyword": "sslmode", "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 32.19 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .", "documented": true, "environment": "PGSSLMODE", "default_evidence": [], "compiled_default_expression": "DefaultSSLMode"}, "comparison_hash": "8cee88b057502e1ab1559e9a8b0b8bdc555df07335cf7edfdd1c462963812a19", "manual_language": "zh", "default_evidence": [], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "comparison": {"left": "11", "right": "12", "status": "changed", "diff": "--- PostgreSQL 11\n+++ PostgreSQL 12\n@@ -1,7 +1,7 @@\n {\n   \"compiled_default_expression\": \"DefaultSSLMode\",\n   \"default_evidence\": [],\n-  \"definition\": \"This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 34.18 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection.\",\n+  \"definition\": \"This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 33.18 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .\",\n   \"documented\": true,\n   \"environment\": \"PGSSLMODE\",\n   \"keyword\": \"sslmode\""}}