sslrootcert
指定包含 SSL 证书颁发机构(CA)证书的文件名。如果文件存在,会验证服务器证书是否由其中某个机构签发。默认为 ~/.postgresql/root.crt。
当前查看 PostgreSQL 18.6。
说明
指定包含 SSL 证书颁发机构(CA)证书的文件名。如果文件存在,会验证服务器证书是否由其中某个机构签发。默认为 ~/.postgresql/root.crt。
- 客户端库
- libpq 18.6
- 手册定义
- 手册已记载
- 源码中的环境变量回退
- PGSSLROOTCERT
- 编译时回退表达式
- NULL
用法
sslrootcert默认值解析与服务文件优先级
以下环境变量可用于选择连接参数的默认值,供 PQconnectdb 、 PQsetdbLogin 和 PQsetdb 在调用代码未直接指定参数值时使用。例如,这样可以避免在简单的客户端应用程序中硬编码数据库连接信息。
服务名称可以在每个用户的服务文件或系统范围的文件中定义。如果同一个服务名称存在于用户文件和系统文件中,则用户文件优先。默认情况下,每个用户的服务文件名为 ~/.pg_service.conf 。在Microsoft Windows上,它的名称为 %APPDATA%\postgresql\.pg_service.conf (其中 %APPDATA% 指用户配置文件夹中的应用数据子目录)。可以通过设置环境变量 PGSERVICEFILE 来指定不同的文件名。系统范围的文件名为 pg_service.conf 。默认情况下,在 PostgreSQL 安装的 etc 目录中寻找(使用 pg_config --sysconfdir 来准确识别此目录)。可以通过设置环境变量 PGSYSCONFDIR 来指定另一个目录,但不能指定不同的文件名。
从服务文件中获取的连接参数会与其他来源的参数合并。服务文件中的设置会覆盖相应的环境变量,而连接字符串中直接给出的值又会覆盖服务文件中的设置。例如,使用上述服务文件时,连接字符串 service=mydb port=5434 将使用主机 somehost 、端口 5434 、用户 admin ,以及由环境变量或内置默认值设置的其他参数。
环境变量证据
PGSSLROOTCERT 的行为与 sslrootcert 连接参数相同。
环境变量回退
| 变量 | 手册记载的行为 |
|---|---|
| PGSSLROOTCERT | PGSSLROOTCERT 的行为与 sslrootcert 连接参数相同。 |
手册定义
sslrootcert-
指定包含 SSL 证书颁发机构(CA)证书的文件名。如果文件存在,会验证服务器证书是否由其中某个机构签发。默认为 ~/.postgresql/root.crt。
也可以指定特殊值
system,此时会加载 SSL 实现提供的受信任 CA 根证书。这些根证书的确切位置因 SSL 实现和平台而异。对于OpenSSL,还可以通过SSL_CERT_DIR和SSL_CERT_FILE环境变量进一步修改这些位置。注意
使用
sslrootcert=system时,默认的sslmode会改为verify-full,任何较弱的设置都会引发错误。在大多数情况下,任何人都很容易为其控制的主机名获取受系统信任的证书,因此verify-ca及所有更弱的模式都无法发挥作用。特殊值
system优先于同名的本地证书文件。如果遇到这种情况,请改用其他路径,例如sslrootcert=./system。
相关条目
文档与源码
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
来源构建
- 版本
- 18.6
- 构建
- https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
- 来源指纹
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
版本比较
PostgreSQL 15 → 16: 属性变化。
以下差异保留原始字段名与英文源描述。
--- PostgreSQL 15
+++ PostgreSQL 16
@@ -1,9 +1,10 @@
{
"compiled_default_expression": "NULL",
"default_evidence": [
- "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt ."
+ "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .",
+ "When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless."
],
- "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .",
+ "definition": "This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt . The special value system may be specified instead, in which case the trusted CA roots from the SSL implementation will be loaded. The exact locations of these root certificates differ by SSL implementation and platform. For OpenSSL in particular, the locations may be further modified by the SSL_CERT_DIR and SSL_CERT_FILE environment variables. Note When using sslrootcert=system , the default sslmode is changed to verify-full , and any weaker setting will result in an error. In most cases it is trivial for anyone to obtain a certificate trusted by the system for a hostname they control, rendering verify-ca and all weaker modes useless. The magic system value will take precedence over a local certificate file with the same name. If for some reason you find yourself in this situation, use an alternative path like sslrootcert=./system instead.",
"documented": true,
"environment": "PGSSLROOTCERT",
"keyword": "sslrootcert"
比较已记录的接口与属性,排除来源指纹和构建元数据。某个样本中没有记录,不能据此判断实际引入或移除的版本。
相关条目
导出 JSON · 返回连接参数 · 收录范围为 PostgreSQL 10 至 20;最早采样版本不一定是实际引入版本。