sslpassword
指定 sslkey 所指私钥的密码,使客户端证书私钥即使在不便交互输入密码时,也能以加密形式存储在磁盘上。
当前查看 PostgreSQL 18.6。
说明
指定 sslkey 所指私钥的密码,使客户端证书私钥即使在不便交互输入密码时,也能以加密形式存储在磁盘上。
- 客户端库
- libpq 18.6
- 手册定义
- 手册已记载
- 源码中的环境变量回退
- 选项表中未声明
- 编译时回退表达式
- NULL
用法
sslpassword默认值解析与服务文件优先级
以下环境变量可用于选择连接参数的默认值,供 PQconnectdb 、 PQsetdbLogin 和 PQsetdb 在调用代码未直接指定参数值时使用。例如,这样可以避免在简单的客户端应用程序中硬编码数据库连接信息。
服务名称可以在每个用户的服务文件或系统范围的文件中定义。如果同一个服务名称存在于用户文件和系统文件中,则用户文件优先。默认情况下,每个用户的服务文件名为 ~/.pg_service.conf 。在Microsoft Windows上,它的名称为 %APPDATA%\postgresql\.pg_service.conf (其中 %APPDATA% 指用户配置文件夹中的应用数据子目录)。可以通过设置环境变量 PGSERVICEFILE 来指定不同的文件名。系统范围的文件名为 pg_service.conf 。默认情况下,在 PostgreSQL 安装的 etc 目录中寻找(使用 pg_config --sysconfdir 来准确识别此目录)。可以通过设置环境变量 PGSYSCONFDIR 来指定另一个目录,但不能指定不同的文件名。
从服务文件中获取的连接参数会与其他来源的参数合并。服务文件中的设置会覆盖相应的环境变量,而连接字符串中直接给出的值又会覆盖服务文件中的设置。例如,使用上述服务文件时,连接字符串 service=mydb port=5434 将使用主机 somehost 、端口 5434 、用户 admin ,以及由环境变量或内置默认值设置的其他参数。
环境变量证据
手册定义
sslpassword-
指定 sslkey 所指私钥的密码,使客户端证书私钥即使在不便交互输入密码时,也能以加密形式存储在磁盘上。
提供给 libpq 的客户端证书密钥已加密时,OpenSSL 默认会显示 Enter PEM pass phrase: 提示。将此参数设为任意非空值即可抑制该提示。
密钥未加密时,此参数被忽略。对于通过 OpenSSL 引擎指定的密钥,除非引擎使用 OpenSSL 密码回调机制提示输入,否则此参数无效。
此选项没有对应的环境变量,也不能从 .pgpass 中查找,但可用于服务文件的连接定义。对于更复杂的需求,应考虑使用 OpenSSL 引擎、PKCS#11 等工具或 USB 加密卸载设备。
相关条目
文档与源码
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
来源构建
- 版本
- 18.6
- 构建
- https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
- 来源指纹
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
版本比较
PostgreSQL 13 → 14: 属性变化。
以下差异保留原始字段名与英文源描述。
--- PostgreSQL 13
+++ PostgreSQL 14
@@ -3,7 +3,7 @@
"default_evidence": [
"Specifying this parameter with any non-empty value suppresses the Enter PEM pass phrase: prompt that OpenSSL will emit by default when an encrypted client certificate key is provided to libpq ."
],
- "definition": "This parameter specifies the password for the secret key specified in sslkey , allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical. Specifying this parameter with any non-empty value suppresses the Enter PEM pass phrase: prompt that OpenSSL will emit by default when an encrypted client certificate key is provided to libpq . If the key is not encrypted this parameter is ignored. The parameter has no effect on keys specified by OpenSSL engines unless the engine uses the OpenSSL password callback mechanism for prompts. There is no environment variable equivalent to this option, and no facility for looking it up in .pgpass . It can be used in a service file connection definition. Users with more sophisticated uses should consider using openssl engines and tools like PKCS#11 or USB crypto offload devices.",
+ "definition": "This parameter specifies the password for the secret key specified in sslkey , allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical. Specifying this parameter with any non-empty value suppresses the Enter PEM pass phrase: prompt that OpenSSL will emit by default when an encrypted client certificate key is provided to libpq . If the key is not encrypted this parameter is ignored. The parameter has no effect on keys specified by OpenSSL engines unless the engine uses the OpenSSL password callback mechanism for prompts. There is no environment variable equivalent to this option, and no facility for looking it up in .pgpass . It can be used in a service file connection definition. Users with more sophisticated uses should consider using OpenSSL engines and tools like PKCS#11 or USB crypto offload devices.",
"documented": true,
"environment": "",
"keyword": "sslpassword"
比较已记录的接口与属性,排除来源指纹和构建元数据。某个样本中没有记录,不能据此判断实际引入或移除的版本。
相关条目
导出 JSON · 返回连接参数 · 收录范围为 PostgreSQL 13 至 20;最早采样版本不一定是实际引入版本。