sslmode
决定是否与服务器协商安全的 SSL TCP/IP 连接,以及协商时的优先级。共有六种模式:
当前查看 PostgreSQL 18.6。
说明
决定是否与服务器协商安全的 SSL TCP/IP 连接,以及协商时的优先级。共有六种模式:
- 客户端库
- libpq 18.6
- 手册定义
- 手册已记载
- 源码中的环境变量回退
- PGSSLMODE
- 编译时回退表达式
- DefaultSSLMode
用法
sslmode默认值解析与服务文件优先级
以下环境变量可用于选择连接参数的默认值,供 PQconnectdb 、 PQsetdbLogin 和 PQsetdb 在调用代码未直接指定参数值时使用。例如,这样可以避免在简单的客户端应用程序中硬编码数据库连接信息。
服务名称可以在每个用户的服务文件或系统范围的文件中定义。如果同一个服务名称存在于用户文件和系统文件中,则用户文件优先。默认情况下,每个用户的服务文件名为 ~/.pg_service.conf 。在Microsoft Windows上,它的名称为 %APPDATA%\postgresql\.pg_service.conf (其中 %APPDATA% 指用户配置文件夹中的应用数据子目录)。可以通过设置环境变量 PGSERVICEFILE 来指定不同的文件名。系统范围的文件名为 pg_service.conf 。默认情况下,在 PostgreSQL 安装的 etc 目录中寻找(使用 pg_config --sysconfdir 来准确识别此目录)。可以通过设置环境变量 PGSYSCONFDIR 来指定另一个目录,但不能指定不同的文件名。
从服务文件中获取的连接参数会与其他来源的参数合并。服务文件中的设置会覆盖相应的环境变量,而连接字符串中直接给出的值又会覆盖服务文件中的设置。例如,使用上述服务文件时,连接字符串 service=mydb port=5434 将使用主机 somehost 、端口 5434 、用户 admin ,以及由环境变量或内置默认值设置的其他参数。
环境变量证据
PGSSLMODE 的行为与 sslmode 连接参数相同。
环境变量回退
| 变量 | 手册记载的行为 |
|---|---|
| PGSSLMODE | PGSSLMODE 的行为与 sslmode 连接参数相同。 |
手册定义
sslmode-
决定是否与服务器协商安全的 SSL TCP/IP 连接,以及协商时的优先级。共有六种模式:
disable-
仅尝试非 SSL 连接。
allow-
先尝试非 SSL 连接,失败后再尝试 SSL 连接。
- prefer(默认值)
-
先尝试 SSL 连接,失败后再尝试非 SSL 连接。
require-
仅尝试 SSL 连接。如果存在根 CA 文件,则按指定 verify-ca 时相同的方式验证证书。
verify-ca-
仅尝试 SSL 连接,并验证服务器证书是否由可信证书颁发机构(CA)签发。
verify-full-
仅尝试 SSL 连接,验证服务器证书是否由可信 CA 签发,并验证请求的服务器主机名与证书中的名称是否匹配。
详细了解这些选项如何工作,请参阅第 32.19 节。
Unix 域套接字通信忽略 sslmode。如果 PostgreSQL 构建时未启用 SSL 支持,require、verify-ca 和 verify-full 会报错;allow 和 prefer 会被接受,但 libpq 实际不会尝试 SSL 连接。
如果可以使用 GSSAPI 加密,无论 sslmode 如何设置,都会优先使用 GSSAPI 加密而非 SSL。在具有可用 GSSAPI 基础设施(如 Kerberos 服务器)的环境中,要强制使用 SSL,还需将 gssencmode 设为 disable。
相关条目
文档与源码
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
来源构建
- 版本
- 18.6
- 构建
- https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
- 来源指纹
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
版本比较
PostgreSQL 16 → 17: 属性变化。
以下差异保留原始字段名与英文源描述。
--- PostgreSQL 16
+++ PostgreSQL 17
@@ -1,7 +1,7 @@
{
"compiled_default_expression": "DefaultSSLMode",
"default_evidence": [],
- "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 34.19 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .",
+ "definition": "This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes: disable only try a non- SSL connection allow first try a non- SSL connection; if that fails, try an SSL connection prefer (default) first try an SSL connection; if that fails, try a non- SSL connection require only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified verify-ca only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority ( CA ) verify-full only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate See Section 32.19 for a detailed description of how these options work. sslmode is ignored for Unix domain socket communication. If PostgreSQL is compiled without SSL support, using options require , verify-ca , or verify-full will cause an error, while options allow and prefer will be accepted but libpq will not actually attempt an SSL connection. Note that if GSSAPI encryption is possible, that will be used in preference to SSL encryption, regardless of the value of sslmode . To force use of SSL encryption in an environment that has working GSSAPI infrastructure (such as a Kerberos server), also set gssencmode to disable .",
"documented": true,
"environment": "PGSSLMODE",
"keyword": "sslmode"
比较已记录的接口与属性,排除来源指纹和构建元数据。某个样本中没有记录,不能据此判断实际引入或移除的版本。
相关条目
导出 JSON · 返回连接参数 · 收录范围为 PostgreSQL 10 至 20;最早采样版本不一定是实际引入版本。