{"kind": "conn", "major": "18", "item": {"slug": "sslnegotiation", "name": "sslnegotiation", "name_zh": "", "category": "TLS", "summary": "\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002", "aliases": ["PGSSLNEGOTIATION", "sslnegotiation"], "content_hash": "dc2248a3c86b77cf0a87d1cf08af73adfdd7eb68ec6d228a7b320e14eb5c0e1d", "versions": {"17": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 17.11"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLNEGOTIATION"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLNegotiation"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/17/libpq-envars.html", "text": "PGSSLNEGOTIATION"}, "description": "PGSSLNEGOTIATION \u7684\u884c\u4e3a\u4e0e sslnegotiation \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslnegotiation", "related": [{"url": "/docs/17/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/17/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/17/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "label": "17.11", "major": "17", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/17/postgresql-17-A4.pdf", "bytes": 15521293, "pages": 3099, "sha256": "1991354df0dc89e70ec39328c28988ef8b19c6a93671dab3893650b63e9f4e36", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/17/postgresql-17-US.pdf", "bytes": 15398150, "pages": 3270, "sha256": "07696c8f38abf31babf22d2db337093936e7c472d2af36d050b000c49bbcf52c", "built_at": "2026-09-26"}}, "tree": "17", "index": "index.html", "major": "17", "pages": 1143, "release": "17.11", "source_url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, "revision": "58419c9b0dd42cb34c8d53695bb025a7e582edf55ccd4c5bcb1c2c7c71a37487", "evidence_kind": "English manual and source declarations", "source_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, "sources": [{"url": "https://pg.center/docs/17/libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION", "file": "libpq-connect.html", "label": "17.11 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLNEGOTIATION", "sha256": "7f15cf88e7854d7e92b57bdcb85ce566543eee5783ebc8eb2972cd6aaca8e7a1", "language": "en", "original_url": "/docs/17/libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION"}, {"url": "https://ftp.postgresql.org/pub/source/v17.11/postgresql-17.11.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "17.11 libpq connection option declarations", "sha256": "9c189446b1b18faf81823636067c9cf9fb01215bdae5b036cc3bb0ebc84971a2", "archive_sha256": "dd27f2b3c59e73ed14aa3324901242bf69a032a6347805f274e6260322d42979"}, {"url": "https://pg.center/docs/17/libpq-envars.html", "file": "libpq-envars.html", "label": "17.11 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "48fb76414267a67473ccb901e64320de2e73fb0dc8ade8fcea38edf3628d2c21", "language": "en", "original_url": "/docs/17/libpq-envars.html"}, {"url": "https://pg.center/docs/17/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "17.11 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "1447c3836f348d6d0ea59ab68fe17ef604eb913938eed81c1e2cb081a36e2d8d", "language": "en", "original_url": "/docs/17/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLNEGOTIATION \u7684\u884c\u4e3a\u4e0e sslnegotiation \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslnegotiation", "documented": true, "description": ["\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002"], "environment": [{"name": "PGSSLNEGOTIATION", "source_url": "/docs/17/libpq-envars.html", "description": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLNEGOTIATION\"><span class=\"term\"><code class=\"literal\">sslnegotiation</code></span> </dt><dd>\n<p lang=\"zh\">\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">postgres</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6267\u884c<span class=\"productname\">PostgreSQL</span>\u534f\u8bae\u534f\u5546\u3002\u5982\u679c\u672a\u63d0\u4f9b\u8be5\u9009\u9879\uff0c\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">direct</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u76f4\u63a5\u5f00\u59cb SSL \u63e1\u624b\u3002\u4ec5\u5f53sslmode=require\u6216\u66f4\u9ad8\u65f6\u624d\u5141\u8bb8\u4f7f\u7528\u8be5\u6a21\u5f0f\uff0c\u56e0\u4e3a\u66f4\u5f31\u7684\u8bbe\u7f6e\u53ef\u80fd\u5728\u670d\u52a1\u5668\u4e0d\u652f\u6301\u76f4\u63a5 SSL \u63e1\u624b\u65f6\u5bfc\u81f4\u610f\u5916\u56de\u9000\u5230\u660e\u6587\u8ba4\u8bc1\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION", "localization": {"status": "complete", "sources": [{"url": "/docs/17/libpq-connect.html", "method": "same-major semantic node", "sha256": "41bb236b80f7c23464be2555c7d20d19551e13f7107cb1d36d58821cbb2f41f1", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[47]/div[1]/dl[0]/dd[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[47]/div[1]/dl[0]/dd[3]"]}, {"url": "/docs/17/libpq-envars.html", "method": "same-major semantic node", "sha256": "5f1014f4afd40210bc05e52c10a62fe34fcaf5cc4445cb809ec8cdacb003cf1c", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[1]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/17/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "0544512734d86673b69ac05be91d417df85476fe6048c6d4b197c65a7d566bbe", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/17/description/0": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "/versions/17/facts/0/label": "Client library", "/versions/17/facts/1/label": "Manual definition", "/versions/17/facts/1/value": "Documented", "/versions/17/facts/2/label": "Source environment fallback", "/versions/17/facts/3/label": "Compiled fallback expression", "/versions/17/tables/0/title": "Environment fallback", "/versions/17/related/0/label": "Connection service file", "/versions/17/related/1/label": "Password file", "/versions/17/related/2/label": "All libpq environment variables", "/versions/17/sections/0/title": "Default resolution and service-file precedence", "/versions/17/sections/1/title": "Environment variable evidence", "/versions/17/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/17/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/17/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/17/sections/1/paragraphs/0": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter.", "/versions/17/tables/0/columns/0/label": "Variable", "/versions/17/tables/0/columns/1/label": "Documented behavior", "/versions/17/tables/0/rows/0/description": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "4b854cc67421704193eefc764506a8a14dd2c25321f7dcfada9ce3f1ed198e9c"}, "source_option": {"keyword": "sslnegotiation", "declaration": "\"sslnegotiation\", \"PGSSLNEGOTIATION\", DefaultSSLNegotiation, NULL, \"SSL-Negotiation\", \"\", 9, offsetof(struct pg_conn, sslnegotiation)", "environment": "PGSSLNEGOTIATION", "source_notes": [], "compiled_default_expression": "DefaultSSLNegotiation"}, "comparison_data": {"keyword": "sslnegotiation", "definition": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17. postgres perform PostgreSQL protocol negotiation. This is the default if the option is not provided. direct start SSL handshake directly after establishing the TCP/IP connection. This is only allowed with sslmode=require or higher, because the weaker settings could lead to unintended fallback to plaintext authentication when the server does not support direct SSL handshake.", "documented": true, "environment": "PGSSLNEGOTIATION", "default_evidence": ["This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."], "compiled_default_expression": "DefaultSSLNegotiation"}, "comparison_hash": "689f6cf691345735854fbeef2bdc05e6e429ffdf8aaab4d9b03c3cc187c1c304", "manual_language": "zh", "default_evidence": ["This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "18": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 18.6"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLNEGOTIATION"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLNegotiation"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/18/libpq-envars.html", "text": "PGSSLNEGOTIATION"}, "description": "PGSSLNEGOTIATION \u7684\u884c\u4e3a\u4e0e sslnegotiation \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslnegotiation", "related": [{"url": "/docs/18/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/18/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/18/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/18/postgresql-18-A4.pdf", "bytes": 15865106, "pages": 3154, "sha256": "19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/18/postgresql-18-US.pdf", "bytes": 15748059, "pages": 3328, "sha256": "facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319", "built_at": "2026-09-26"}}, "tree": "18", "index": "index.html", "major": "18", "pages": 1148, "release": "18.6", "source_url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "revision": "ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8", "evidence_kind": "English manual and source declarations", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "sources": [{"url": "https://pg.center/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION", "file": "libpq-connect.html", "label": "18.6 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLNEGOTIATION", "sha256": "c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f", "language": "en", "original_url": "/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION"}, {"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "18.6 libpq connection option declarations", "sha256": "44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5", "archive_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/libpq-envars.html", "file": "libpq-envars.html", "label": "18.6 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363", "language": "en", "original_url": "/docs/18/libpq-envars.html"}, {"url": "https://pg.center/docs/18/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "18.6 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7", "language": "en", "original_url": "/docs/18/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLNEGOTIATION \u7684\u884c\u4e3a\u4e0e sslnegotiation \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslnegotiation", "documented": true, "description": ["\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002"], "environment": [{"name": "PGSSLNEGOTIATION", "source_url": "/docs/18/libpq-envars.html", "description": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLNEGOTIATION\"><span class=\"term\"><code class=\"literal\">sslnegotiation</code></span> </dt><dd>\n<p lang=\"zh\">\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">postgres</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6267\u884c<span class=\"productname\">PostgreSQL</span>\u534f\u8bae\u534f\u5546\u3002\u5982\u679c\u672a\u63d0\u4f9b\u8be5\u9009\u9879\uff0c\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">direct</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u76f4\u63a5\u5f00\u59cb SSL \u63e1\u624b\u3002\u4ec5\u5f53<code class=\"literal\">sslmode=require</code>\u6216\u66f4\u9ad8\u65f6\u624d\u5141\u8bb8\u4f7f\u7528\u8be5\u6a21\u5f0f\uff0c\u56e0\u4e3a\u66f4\u5f31\u7684\u8bbe\u7f6e\u53ef\u80fd\u5728\u670d\u52a1\u5668\u4e0d\u652f\u6301\u76f4\u63a5 SSL \u63e1\u624b\u65f6\u5bfc\u81f4\u610f\u5916\u56de\u9000\u5230\u660e\u6587\u8ba4\u8bc1\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION", "localization": {"status": "complete", "sources": [{"url": "/docs/18/libpq-connect.html", "method": "same-major semantic node", "sha256": "bae58c13a65be235aa0408ef12f8bcc7e48f2908cd71080a7dedec225a74c083", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[47]/div[1]/dl[0]/dd[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[47]/div[1]/dl[0]/dd[3]"]}, {"url": "/docs/18/libpq-envars.html", "method": "same-major semantic node", "sha256": "8423affb67ef7d4f700d7ccc8c0ef66629341568c8d72530a0c765f3d155da2f", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[1]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/18/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "a06dfcdffbbdf6bd55987cade2d9ff1db6cbfd9f75eb80c7866e8792cd70463e", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "/versions/18/facts/0/label": "Client library", "/versions/18/facts/1/label": "Manual definition", "/versions/18/facts/1/value": "Documented", "/versions/18/facts/2/label": "Source environment fallback", "/versions/18/facts/3/label": "Compiled fallback expression", "/versions/18/tables/0/title": "Environment fallback", "/versions/18/related/0/label": "Connection service file", "/versions/18/related/1/label": "Password file", "/versions/18/related/2/label": "All libpq environment variables", "/versions/18/sections/0/title": "Default resolution and service-file precedence", "/versions/18/sections/1/title": "Environment variable evidence", "/versions/18/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/18/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/18/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/18/sections/1/paragraphs/0": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter.", "/versions/18/tables/0/columns/0/label": "Variable", "/versions/18/tables/0/columns/1/label": "Documented behavior", "/versions/18/tables/0/rows/0/description": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "efcc7176896aee3d006e520dbc49021c3e53d5fb0af7ba549f4220fe27bfc462"}, "source_option": {"keyword": "sslnegotiation", "declaration": "\"sslnegotiation\", \"PGSSLNEGOTIATION\", DefaultSSLNegotiation, NULL, \"SSL-Negotiation\", \"\", 9, offsetof(struct pg_conn, sslnegotiation)", "environment": "PGSSLNEGOTIATION", "source_notes": [], "compiled_default_expression": "DefaultSSLNegotiation"}, "comparison_data": {"keyword": "sslnegotiation", "definition": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17. postgres perform PostgreSQL protocol negotiation. This is the default if the option is not provided. direct start SSL handshake directly after establishing the TCP/IP connection. This is only allowed with sslmode=require or higher, because the weaker settings could lead to unintended fallback to plaintext authentication when the server does not support direct SSL handshake.", "documented": true, "environment": "PGSSLNEGOTIATION", "default_evidence": ["This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."], "compiled_default_expression": "DefaultSSLNegotiation"}, "comparison_hash": "689f6cf691345735854fbeef2bdc05e6e429ffdf8aaab4d9b03c3cc187c1c304", "manual_language": "zh", "default_evidence": ["This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "19": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 19beta4"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLNEGOTIATION"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLNegotiation"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/19/libpq-envars.html", "text": "PGSSLNEGOTIATION"}, "description": "PGSSLNEGOTIATION \u7684\u884c\u4e3a\u4e0e sslnegotiation \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslnegotiation", "related": [{"url": "/docs/19/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/19/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/19/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/19/postgresql-19-A4.pdf", "bytes": 16064841, "pages": 3052, "sha256": "4dd099e4125c591128fc5f3ebd02178dc24781f9e5ae629f96d67c4c8547427b", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/19/postgresql-19-US.pdf", "bytes": 15974616, "pages": 3225, "sha256": "61971fa857f0956d47341a0388fa6af9ae10acf691d4b2fc009007d384b0342b", "built_at": "2026-09-26"}}, "tree": "19", "index": "index.html", "major": "19", "pages": 1155, "release": "19beta4", "source_url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "svg_assets": 5, "source_mode": "en SGML built with pinned official archive", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, "revision": "1bbbbf4133d426f0e4304010688d2984c30fb67df0cc3a61b3e37eb3f6f37833", "evidence_kind": "English manual and source declarations", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, "sources": [{"url": "https://pg.center/docs/19/libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION", "file": "libpq-connect.html", "label": "19beta4 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLNEGOTIATION", "sha256": "14917417235a95d969bf3642c347dea7ae548c5f73b0dd00991a580ebcfbb47e", "language": "en", "original_url": "/docs/19/libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION"}, {"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "19beta4 libpq connection option declarations", "sha256": "ae8005372c570ff47a4922c942238653a034f01f9db40c9e0f57cb48915ffd98", "archive_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "https://pg.center/docs/19/libpq-envars.html", "file": "libpq-envars.html", "label": "19beta4 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d8f0afee19bae6323942ea5415649fbd66e3880fe8c8415350fcf3915f7c7047", "language": "en", "original_url": "/docs/19/libpq-envars.html"}, {"url": "https://pg.center/docs/19/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "19beta4 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "4c858fe55701d703cc00e7adf55eeac09cafcfdc37929b8e23ccf8ba42af9f98", "language": "en", "original_url": "/docs/19/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u5728 libpq \u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u4f7f\u7528 servicefile \u5173\u952e\u5b57\uff0c\u6216\u8005\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLNEGOTIATION \u7684\u884c\u4e3a\u4e0e sslnegotiation \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslnegotiation", "documented": true, "description": ["\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002"], "environment": [{"name": "PGSSLNEGOTIATION", "source_url": "/docs/19/libpq-envars.html", "description": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLNEGOTIATION\"><span class=\"term\"><code class=\"literal\">sslnegotiation</code></span> </dt><dd>\n<p lang=\"zh\">\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">postgres</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6267\u884c<span class=\"productname\">PostgreSQL</span>\u534f\u8bae\u534f\u5546\u3002\u5982\u679c\u672a\u63d0\u4f9b\u8be5\u9009\u9879\uff0c\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">direct</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u76f4\u63a5\u5f00\u59cb SSL \u63e1\u624b\u3002\u4ec5\u5f53<code class=\"literal\">sslmode=require</code>\u6216\u66f4\u9ad8\u65f6\u624d\u5141\u8bb8\u4f7f\u7528\u8be5\u6a21\u5f0f\uff0c\u56e0\u4e3a\u66f4\u5f31\u7684\u8bbe\u7f6e\u53ef\u80fd\u5728\u670d\u52a1\u5668\u4e0d\u652f\u6301\u76f4\u63a5 SSL \u63e1\u624b\u65f6\u5bfc\u81f4\u610f\u5916\u56de\u9000\u5230\u660e\u6587\u8ba4\u8bc1\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION", "localization": {"status": "complete", "sources": [{"url": "/docs/19/libpq-connect.html", "method": "same-major semantic node", "sha256": "8a146554e35097ee5bd56228b90d2a83442c7bd6ca303bdd01de148d06928cd3", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[47]/div[1]/dl[0]/dd[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[47]/div[1]/dl[0]/dd[3]"]}, {"url": "/docs/19/libpq-envars.html", "method": "same-major semantic node", "sha256": "1c8f71428ae8cd8acf564cb581b51a0bce2bf0102680e44c1ced261aa3ec55f7", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[1]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/19/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "ed80600a221e79a10c683341a2d8b9fa12c84e00c638b7969a72feb8b3c467d3", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/19/description/0": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "/versions/19/facts/0/label": "Client library", "/versions/19/facts/1/label": "Manual definition", "/versions/19/facts/1/value": "Documented", "/versions/19/facts/2/label": "Source environment fallback", "/versions/19/facts/3/label": "Compiled fallback expression", "/versions/19/tables/0/title": "Environment fallback", "/versions/19/related/0/label": "Connection service file", "/versions/19/related/1/label": "Password file", "/versions/19/related/2/label": "All libpq environment variables", "/versions/19/sections/0/title": "Default resolution and service-file precedence", "/versions/19/sections/1/title": "Environment variable evidence", "/versions/19/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/19/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/19/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/19/sections/1/paragraphs/0": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter.", "/versions/19/tables/0/columns/0/label": "Variable", "/versions/19/tables/0/columns/1/label": "Documented behavior", "/versions/19/tables/0/rows/0/description": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "0ed75f5e171798ade76363f3c2b7dcca9dbe2b0b3c632c9933bb7d099cf397c2"}, "source_option": {"keyword": "sslnegotiation", "declaration": "\"sslnegotiation\", \"PGSSLNEGOTIATION\", DefaultSSLNegotiation, NULL, \"SSL-Negotiation\", \"\", 9, offsetof(struct pg_conn, sslnegotiation)", "environment": "PGSSLNEGOTIATION", "source_notes": [], "compiled_default_expression": "DefaultSSLNegotiation"}, "comparison_data": {"keyword": "sslnegotiation", "definition": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17. postgres perform PostgreSQL protocol negotiation. This is the default if the option is not provided. direct start SSL handshake directly after establishing the TCP/IP connection. This is only allowed with sslmode=require or higher, because the weaker settings could lead to unintended fallback to plaintext authentication when the server does not support direct SSL handshake.", "documented": true, "environment": "PGSSLNEGOTIATION", "default_evidence": ["This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."], "compiled_default_expression": "DefaultSSLNegotiation"}, "comparison_hash": "689f6cf691345735854fbeef2bdc05e6e429ffdf8aaab4d9b03c3cc187c1c304", "manual_language": "zh", "default_evidence": ["This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "20": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 20devel"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLNEGOTIATION"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLNegotiation"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/devel/libpq-envars.html", "text": "PGSSLNEGOTIATION"}, "description": "PGSSLNEGOTIATION \u7684\u884c\u4e3a\u4e0e sslnegotiation \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslnegotiation", "related": [{"url": "/docs/devel/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/devel/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/devel/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/20/postgresql-20-A4.pdf", "bytes": 16030631, "pages": 3052, "sha256": "bd5d82c0ce38fc18f92a0447818a91a193a261776bca1c37564bf9a683e177d0", "built_at": "2026-09-28"}, "US": {"url": "/files/documentation/pdf/20/postgresql-20-US.pdf", "bytes": 15936613, "pages": 3223, "sha256": "d97d9e0db479a02f4234b175f50fcad70c3661619afc8d6df9b9437882e3c299", "built_at": "2026-09-28"}}, "tree": "0", "index": "index.html", "major": "20", "pages": 1156, "release": "20devel", "source_url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "svg_assets": 6, "source_mode": "en SGML built with pinned official archive", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_snapshot_utc": "26-Sep-2026 20:22"}, "revision": "2eba5e0fd4c3bffb2803247b6cd537878e9d6ee5a6dfbe3c50ece8b421b80918", "evidence_kind": "English manual and source declarations", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, "sources": [{"url": "https://pg.center/docs/devel/libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION", "file": "libpq-connect.html", "label": "20devel English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLNEGOTIATION", "sha256": "eeb28ce798c0f99c3581400b4baaae7687ee5d4176fcb9f5d2fd28809282d48f", "language": "en", "original_url": "/docs/devel/libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION"}, {"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "20devel libpq connection option declarations", "sha256": "d6eab6e2f37054b32a7ee7039b53beae603316f8ec3f0a14716061e042fc4aa1", "archive_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "https://pg.center/docs/devel/libpq-envars.html", "file": "libpq-envars.html", "label": "20devel English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "7c49cf204e26ea86654491db5ea06c4f558c670e2e60a60b1dbf708ce682accc", "language": "en", "original_url": "/docs/devel/libpq-envars.html"}, {"url": "https://pg.center/docs/devel/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "20devel English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "a1ccd63a6e307a5541d58eabd57be5b467dff2480770838ec9b6a59a3ef110dc", "language": "en", "original_url": "/docs/devel/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u5728 libpq \u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u4f7f\u7528 servicefile \u5173\u952e\u5b57\uff0c\u6216\u8005\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLNEGOTIATION \u7684\u884c\u4e3a\u4e0e sslnegotiation \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslnegotiation", "documented": true, "description": ["\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002"], "environment": [{"name": "PGSSLNEGOTIATION", "source_url": "/docs/devel/libpq-envars.html", "description": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLNEGOTIATION\"><span class=\"term\"><code class=\"literal\">sslnegotiation</code></span> </dt><dd>\n<p lang=\"zh\">\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">postgres</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6267\u884c<span class=\"productname\">PostgreSQL</span>\u534f\u8bae\u534f\u5546\u3002\u5982\u679c\u672a\u63d0\u4f9b\u8be5\u9009\u9879\uff0c\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">direct</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u76f4\u63a5\u5f00\u59cb SSL \u63e1\u624b\u3002\u4ec5\u5f53<code class=\"literal\">sslmode=require</code>\u6216\u66f4\u9ad8\u65f6\u624d\u5141\u8bb8\u4f7f\u7528\u8be5\u6a21\u5f0f\uff0c\u56e0\u4e3a\u66f4\u5f31\u7684\u8bbe\u7f6e\u53ef\u80fd\u5728\u670d\u52a1\u5668\u4e0d\u652f\u6301\u76f4\u63a5 SSL \u63e1\u624b\u65f6\u5bfc\u81f4\u610f\u5916\u56de\u9000\u5230\u660e\u6587\u8ba4\u8bc1\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION", "localization": {"status": "complete", "sources": [{"url": "/docs/devel/libpq-connect.html", "method": "same-major semantic node", "sha256": "80a1ddba976c7228bb9d179e08545f0a6328ffc9b880481df17a53fdebf42bb5", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[47]/div[1]/dl[0]/dd[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[47]/div[1]/dl[0]/dd[3]"]}, {"url": "/docs/devel/libpq-envars.html", "method": "same-major semantic node", "sha256": "b4afd6d100d2be289d48e1a6f6fb9804dd0b684798b7dabf8bae7d3db074117f", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[1]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/devel/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "acea589bbba517979fe815bd3bff32cd6d5e6323e1d5b4f395d7864338868b26", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/summary": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "/versions/20/description/0": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "/versions/20/facts/0/label": "Client library", "/versions/20/facts/1/label": "Manual definition", "/versions/20/facts/1/value": "Documented", "/versions/20/facts/2/label": "Source environment fallback", "/versions/20/facts/3/label": "Compiled fallback expression", "/versions/20/tables/0/title": "Environment fallback", "/versions/20/related/0/label": "Connection service file", "/versions/20/related/1/label": "Password file", "/versions/20/related/2/label": "All libpq environment variables", "/versions/20/sections/0/title": "Default resolution and service-file precedence", "/versions/20/sections/1/title": "Environment variable evidence", "/versions/20/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/20/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/20/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/20/sections/1/paragraphs/0": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter.", "/versions/20/tables/0/columns/0/label": "Variable", "/versions/20/tables/0/columns/1/label": "Documented behavior", "/versions/20/tables/0/rows/0/description": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "30c1740435ff4cc461cea75a67aea9bccb024382c1a208f40799ce4ed91b85b4"}, "source_option": {"keyword": "sslnegotiation", "declaration": "\"sslnegotiation\", \"PGSSLNEGOTIATION\", DefaultSSLNegotiation, NULL, \"SSL-Negotiation\", \"\", 9, offsetof(struct pg_conn, sslnegotiation)", "environment": "PGSSLNEGOTIATION", "source_notes": [], "compiled_default_expression": "DefaultSSLNegotiation"}, "comparison_data": {"keyword": "sslnegotiation", "definition": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17. postgres perform PostgreSQL protocol negotiation. This is the default if the option is not provided. direct start SSL handshake directly after establishing the TCP/IP connection. This is only allowed with sslmode=require or higher, because the weaker settings could lead to unintended fallback to plaintext authentication when the server does not support direct SSL handshake.", "documented": true, "environment": "PGSSLNEGOTIATION", "default_evidence": ["This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."], "compiled_default_expression": "DefaultSSLNegotiation"}, "comparison_hash": "689f6cf691345735854fbeef2bdc05e6e429ffdf8aaab4d9b03c3cc187c1c304", "manual_language": "zh", "default_evidence": ["This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}}}, "snapshot": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 18.6"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "PGSSLNEGOTIATION"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "DefaultSSLNegotiation"}], "tables": [{"key": "environment", "rows": [{"name": {"url": "/docs/18/libpq-envars.html", "text": "PGSSLNEGOTIATION"}, "description": "PGSSLNEGOTIATION \u7684\u884c\u4e3a\u4e0e sslnegotiation \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"}], "title": "\u73af\u5883\u53d8\u91cf\u56de\u9000", "columns": [{"key": "name", "label": "\u53d8\u91cf"}, {"key": "description", "label": "\u624b\u518c\u8bb0\u8f7d\u7684\u884c\u4e3a"}]}], "keyword": "sslnegotiation", "related": [{"url": "/docs/18/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/18/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/18/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/18/postgresql-18-A4.pdf", "bytes": 15865106, "pages": 3154, "sha256": "19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/18/postgresql-18-US.pdf", "bytes": 15748059, "pages": 3328, "sha256": "facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319", "built_at": "2026-09-26"}}, "tree": "18", "index": "index.html", "major": "18", "pages": 1148, "release": "18.6", "source_url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "revision": "ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8", "evidence_kind": "English manual and source declarations", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "sources": [{"url": "https://pg.center/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION", "file": "libpq-connect.html", "label": "18.6 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-SSLNEGOTIATION", "sha256": "c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f", "language": "en", "original_url": "/docs/18/libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION"}, {"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "18.6 libpq connection option declarations", "sha256": "44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5", "archive_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/libpq-envars.html", "file": "libpq-envars.html", "label": "18.6 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363", "language": "en", "original_url": "/docs/18/libpq-envars.html"}, {"url": "https://pg.center/docs/18/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "18.6 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7", "language": "en", "original_url": "/docs/18/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": ["PGSSLNEGOTIATION \u7684\u884c\u4e3a\u4e0e sslnegotiation \u8fde\u63a5\u53c2\u6570\u76f8\u540c\u3002"]}], "signature": "sslnegotiation", "documented": true, "description": ["\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002"], "environment": [{"name": "PGSSLNEGOTIATION", "source_url": "/docs/18/libpq-envars.html", "description": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter."}], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-SSLNEGOTIATION\"><span class=\"term\"><code class=\"literal\">sslnegotiation</code></span> </dt><dd>\n<p lang=\"zh\">\u4f7f\u7528 SSL \u65f6\uff0c\u6b64\u9009\u9879\u63a7\u5236\u4e0e\u670d\u52a1\u5668\u534f\u5546 SSL \u52a0\u5bc6\u7684\u65b9\u5f0f\u3002\u9ed8\u8ba4 postgres \u6a21\u5f0f\u4e0b\uff0c\u5ba2\u6237\u7aef\u5148\u8be2\u95ee\u670d\u52a1\u5668\u662f\u5426\u652f\u6301 SSL\uff1bdirect \u6a21\u5f0f\u4e0b\uff0c\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u7acb\u5373\u5f00\u59cb\u6807\u51c6 SSL \u63e1\u624b\u3002\u4f20\u7edf PostgreSQL \u534f\u8bae\u534f\u5546\u5bf9\u4e0d\u540c\u670d\u52a1\u5668\u914d\u7f6e\u7684\u9002\u5e94\u6027\u6700\u5f3a\u3002\u5982\u679c\u5df2\u77e5\u670d\u52a1\u5668\u652f\u6301\u76f4\u63a5 SSL \u8fde\u63a5\uff0c\u5219 direct \u53ef\u51cf\u5c11\u4e00\u6b21\u5f80\u8fd4\uff0c\u964d\u4f4e\u8fde\u63a5\u5ef6\u8fdf\uff0c\u8fd8\u53ef\u4f7f\u7528\u4e0d\u8bc6\u522b PostgreSQL \u534f\u8bae\u7684\u901a\u7528 SSL \u7f51\u7edc\u5de5\u5177\u3002\u76f4\u63a5 SSL \u9009\u9879\u4ece PostgreSQL 17 \u5f15\u5165\u3002</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">postgres</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6267\u884c<span class=\"productname\">PostgreSQL</span>\u534f\u8bae\u534f\u5546\u3002\u5982\u679c\u672a\u63d0\u4f9b\u8be5\u9009\u9879\uff0c\u8fd9\u662f\u9ed8\u8ba4\u503c\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">direct</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u5efa\u7acb TCP/IP \u8fde\u63a5\u540e\u76f4\u63a5\u5f00\u59cb SSL \u63e1\u624b\u3002\u4ec5\u5f53<code class=\"literal\">sslmode=require</code>\u6216\u66f4\u9ad8\u65f6\u624d\u5141\u8bb8\u4f7f\u7528\u8be5\u6a21\u5f0f\uff0c\u56e0\u4e3a\u66f4\u5f31\u7684\u8bbe\u7f6e\u53ef\u80fd\u5728\u670d\u52a1\u5668\u4e0d\u652f\u6301\u76f4\u63a5 SSL \u63e1\u624b\u65f6\u5bfc\u81f4\u610f\u5916\u56de\u9000\u5230\u660e\u6587\u8ba4\u8bc1\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-SSLNEGOTIATION", "localization": {"status": "complete", "sources": [{"url": "/docs/18/libpq-connect.html", "method": "same-major semantic node", "sha256": "bae58c13a65be235aa0408ef12f8bcc7e48f2908cd71080a7dedec225a74c083", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[47]/div[1]/dl[0]/dd[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[47]/div[1]/dl[0]/dd[3]"]}, {"url": "/docs/18/libpq-envars.html", "method": "same-major semantic node", "sha256": "8423affb67ef7d4f700d7ccc8c0ef66629341568c8d72530a0c765f3d155da2f", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/div[3]/ul[0]/li[1]", "#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/18/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "a06dfcdffbbdf6bd55987cade2d9ff1db6cbfd9f75eb80c7866e8792cd70463e", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "/versions/18/facts/0/label": "Client library", "/versions/18/facts/1/label": "Manual definition", "/versions/18/facts/1/value": "Documented", "/versions/18/facts/2/label": "Source environment fallback", "/versions/18/facts/3/label": "Compiled fallback expression", "/versions/18/tables/0/title": "Environment fallback", "/versions/18/related/0/label": "Connection service file", "/versions/18/related/1/label": "Password file", "/versions/18/related/2/label": "All libpq environment variables", "/versions/18/sections/0/title": "Default resolution and service-file precedence", "/versions/18/sections/1/title": "Environment variable evidence", "/versions/18/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/18/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/18/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.", "/versions/18/sections/1/paragraphs/0": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter.", "/versions/18/tables/0/columns/0/label": "Variable", "/versions/18/tables/0/columns/1/label": "Documented behavior", "/versions/18/tables/0/rows/0/description": "PGSSLNEGOTIATION behaves the same as the sslnegotiation connection parameter."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "efcc7176896aee3d006e520dbc49021c3e53d5fb0af7ba549f4220fe27bfc462"}, "source_option": {"keyword": "sslnegotiation", "declaration": "\"sslnegotiation\", \"PGSSLNEGOTIATION\", DefaultSSLNegotiation, NULL, \"SSL-Negotiation\", \"\", 9, offsetof(struct pg_conn, sslnegotiation)", "environment": "PGSSLNEGOTIATION", "source_notes": [], "compiled_default_expression": "DefaultSSLNegotiation"}, "comparison_data": {"keyword": "sslnegotiation", "definition": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17. postgres perform PostgreSQL protocol negotiation. This is the default if the option is not provided. direct start SSL handshake directly after establishing the TCP/IP connection. This is only allowed with sslmode=require or higher, because the weaker settings could lead to unintended fallback to plaintext authentication when the server does not support direct SSL handshake.", "documented": true, "environment": "PGSSLNEGOTIATION", "default_evidence": ["This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."], "compiled_default_expression": "DefaultSSLNegotiation"}, "comparison_hash": "689f6cf691345735854fbeef2bdc05e6e429ffdf8aaab4d9b03c3cc187c1c304", "manual_language": "zh", "default_evidence": ["This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.", "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "comparison": {"left": "17", "right": "18", "status": "unchanged", "diff": ""}}