↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 连接参数 / TLS

sslnegotiation

使用 SSL 时,此选项控制与服务器协商 SSL 加密的方式。默认 postgres 模式下,客户端先询问服务器是否支持 SSL;direct 模式下,建立 TCP/IP 连接后立即开始标准 SSL 握手。传统 PostgreSQL 协议协商对不同服务器配置的适应性最强。如果已知服务器支持直接 SSL 连接,则 direct 可减少一次往返,降低连接延迟,还可使用不识别 PostgreSQL 协议的通用 SSL 网络工具。直接 SSL 选项从 PostgreSQL 17 引入。

当前查看 PostgreSQL 18.6。

说明

使用 SSL 时,此选项控制与服务器协商 SSL 加密的方式。默认 postgres 模式下,客户端先询问服务器是否支持 SSL;direct 模式下,建立 TCP/IP 连接后立即开始标准 SSL 握手。传统 PostgreSQL 协议协商对不同服务器配置的适应性最强。如果已知服务器支持直接 SSL 连接,则 direct 可减少一次往返,降低连接延迟,还可使用不识别 PostgreSQL 协议的通用 SSL 网络工具。直接 SSL 选项从 PostgreSQL 17 引入。

客户端库
libpq 18.6
手册定义
手册已记载
源码中的环境变量回退
PGSSLNEGOTIATION
编译时回退表达式
DefaultSSLNegotiation

用法

sslnegotiation

默认值解析与服务文件优先级

以下环境变量可用于选择连接参数的默认值,供 PQconnectdb 、 PQsetdbLogin 和 PQsetdb 在调用代码未直接指定参数值时使用。例如,这样可以避免在简单的客户端应用程序中硬编码数据库连接信息。

服务名称可以在每个用户的服务文件或系统范围的文件中定义。如果同一个服务名称存在于用户文件和系统文件中,则用户文件优先。默认情况下,每个用户的服务文件名为 ~/.pg_service.conf 。在Microsoft Windows上,它的名称为 %APPDATA%\postgresql\.pg_service.conf (其中 %APPDATA% 指用户配置文件夹中的应用数据子目录)。可以通过设置环境变量 PGSERVICEFILE 来指定不同的文件名。系统范围的文件名为 pg_service.conf 。默认情况下,在 PostgreSQL 安装的 etc 目录中寻找(使用 pg_config --sysconfdir 来准确识别此目录)。可以通过设置环境变量 PGSYSCONFDIR 来指定另一个目录,但不能指定不同的文件名。

从服务文件中获取的连接参数会与其他来源的参数合并。服务文件中的设置会覆盖相应的环境变量,而连接字符串中直接给出的值又会覆盖服务文件中的设置。例如,使用上述服务文件时,连接字符串 service=mydb port=5434 将使用主机 somehost 、端口 5434 、用户 admin ,以及由环境变量或内置默认值设置的其他参数。

环境变量证据

PGSSLNEGOTIATION 的行为与 sslnegotiation 连接参数相同。

环境变量回退

变量手册记载的行为
PGSSLNEGOTIATIONPGSSLNEGOTIATION 的行为与 sslnegotiation 连接参数相同。

手册定义

sslnegotiation

使用 SSL 时,此选项控制与服务器协商 SSL 加密的方式。默认 postgres 模式下,客户端先询问服务器是否支持 SSL;direct 模式下,建立 TCP/IP 连接后立即开始标准 SSL 握手。传统 PostgreSQL 协议协商对不同服务器配置的适应性最强。如果已知服务器支持直接 SSL 连接,则 direct 可减少一次往返,降低连接延迟,还可使用不识别 PostgreSQL 协议的通用 SSL 网络工具。直接 SSL 选项从 PostgreSQL 17 引入。

postgres

执行PostgreSQL协议协商。如果未提供该选项,这是默认值。

direct

在建立 TCP/IP 连接后直接开始 SSL 握手。仅当sslmode=require或更高时才允许使用该模式,因为更弱的设置可能在服务器不支持直接 SSL 握手时导致意外回退到明文认证。

相关条目

文档与源码

来源构建
版本
18.6
构建
https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
来源指纹
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8

版本比较

PostgreSQL 16 → 17: 新增收录。

以下差异保留原始字段名与英文源描述。

--- PostgreSQL 16
+++ PostgreSQL 17
@@ -1 +1,11 @@
-该版未收录
+{
+  "compiled_default_expression": "DefaultSSLNegotiation",
+  "default_evidence": [
+    "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.",
+    "perform PostgreSQL protocol negotiation. This is the default if the option is not provided."
+  ],
+  "definition": "This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17. postgres perform PostgreSQL protocol negotiation. This is the default if the option is not provided. direct start SSL handshake directly after establishing the TCP/IP connection. This is only allowed with sslmode=require or higher, because the weaker settings could lead to unintended fallback to plaintext authentication when the server does not support direct SSL handshake.",
+  "documented": true,
+  "environment": "PGSSLNEGOTIATION",
+  "keyword": "sslnegotiation"
+}

比较已记录的接口与属性,排除来源指纹和构建元数据。某个样本中没有记录,不能据此判断实际引入或移除的版本。

相关条目

导出 JSON · 返回连接参数 · 收录范围为 PostgreSQL 17 至 20;最早采样版本不一定是实际引入版本。