↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 连接参数 / TLS

sslmode

决定是否与服务器协商安全的 SSL TCP/IP 连接,以及协商时的优先级。共有六种模式:

当前查看 PostgreSQL 18.6。

说明

决定是否与服务器协商安全的 SSL TCP/IP 连接,以及协商时的优先级。共有六种模式:

客户端库
libpq 18.6
手册定义
手册已记载
源码中的环境变量回退
PGSSLMODE
编译时回退表达式
DefaultSSLMode

用法

sslmode

默认值解析与服务文件优先级

以下环境变量可用于选择连接参数的默认值,供 PQconnectdb 、 PQsetdbLogin 和 PQsetdb 在调用代码未直接指定参数值时使用。例如,这样可以避免在简单的客户端应用程序中硬编码数据库连接信息。

服务名称可以在每个用户的服务文件或系统范围的文件中定义。如果同一个服务名称存在于用户文件和系统文件中,则用户文件优先。默认情况下,每个用户的服务文件名为 ~/.pg_service.conf 。在Microsoft Windows上,它的名称为 %APPDATA%\postgresql\.pg_service.conf (其中 %APPDATA% 指用户配置文件夹中的应用数据子目录)。可以通过设置环境变量 PGSERVICEFILE 来指定不同的文件名。系统范围的文件名为 pg_service.conf 。默认情况下,在 PostgreSQL 安装的 etc 目录中寻找(使用 pg_config --sysconfdir 来准确识别此目录)。可以通过设置环境变量 PGSYSCONFDIR 来指定另一个目录,但不能指定不同的文件名。

从服务文件中获取的连接参数会与其他来源的参数合并。服务文件中的设置会覆盖相应的环境变量,而连接字符串中直接给出的值又会覆盖服务文件中的设置。例如,使用上述服务文件时,连接字符串 service=mydb port=5434 将使用主机 somehost 、端口 5434 、用户 admin ,以及由环境变量或内置默认值设置的其他参数。

环境变量证据

PGSSLMODE 的行为与 sslmode 连接参数相同。

环境变量回退

变量手册记载的行为
PGSSLMODEPGSSLMODE 的行为与 sslmode 连接参数相同。

手册定义

sslmode

决定是否与服务器协商安全的 SSL TCP/IP 连接,以及协商时的优先级。共有六种模式:

disable

仅尝试非 SSL 连接。

allow

先尝试非 SSL 连接,失败后再尝试 SSL 连接。

prefer(默认值)

先尝试 SSL 连接,失败后再尝试非 SSL 连接。

require

仅尝试 SSL 连接。如果存在根 CA 文件,则按指定 verify-ca 时相同的方式验证证书。

verify-ca

仅尝试 SSL 连接,并验证服务器证书是否由可信证书颁发机构(CA)签发。

verify-full

仅尝试 SSL 连接,验证服务器证书是否由可信 CA 签发,并验证请求的服务器主机名与证书中的名称是否匹配。

详细了解这些选项如何工作,请参阅第 32.19 节。

Unix 域套接字通信忽略 sslmode。如果 PostgreSQL 构建时未启用 SSL 支持,require、verify-ca 和 verify-full 会报错;allow 和 prefer 会被接受,但 libpq 实际不会尝试 SSL 连接。

如果可以使用 GSSAPI 加密,无论 sslmode 如何设置,都会优先使用 GSSAPI 加密而非 SSL。在具有可用 GSSAPI 基础设施(如 Kerberos 服务器)的环境中,要强制使用 SSL,还需将 gssencmode 设为 disable。

相关条目

文档与源码

来源构建
版本
18.6
构建
https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
来源指纹
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8

版本比较

PostgreSQL 10 → 11: 属性变化。

以下差异保留原始字段名与英文源描述。

--- PostgreSQL 10
+++ PostgreSQL 11
@@ -1,7 +1,7 @@
 {
   "compiled_default_expression": "DefaultSSLMode",
   "default_evidence": [],
-  "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 33.18 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection.",
+  "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 34.18 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection.",
   "documented": true,
   "environment": "PGSSLMODE",
   "keyword": "sslmode"

比较已记录的接口与属性,排除来源指纹和构建元数据。某个样本中没有记录,不能据此判断实际引入或移除的版本。

相关条目

导出 JSON · 返回连接参数 · 收录范围为 PostgreSQL 10 至 20;最早采样版本不一定是实际引入版本。