使用pgjdbc-ng连接PostgreSQL出现SIT环境连接超时问题求助
It sounds like you're hitting a key difference between how pgjdbc-ng and the official PostgreSQL JDBC driver handle SSL/TLS connections, especially since your SIT environment enforces TLS 1.3. Let's break down the likely causes and steps to fix this:
1. Core Difference: SSL Provider Implementation
The official PostgreSQL JDBC driver (pgjdbc) relies on Java's built-in JSSE (Java Secure Socket Extension) for SSL/TLS, which can support TLS 1.3 if your Java version is recent enough (Java 8u261+, Java 11+).
However, pgjdbc-ng defaults to using the system's OpenSSL library for SSL connections. Since your server runs OpenSSL 1.0.1 (which doesn't support TLS 1.3), pgjdbc-ng can't negotiate a valid TLS 1.3 connection with your PostgreSQL 13 instance, leading to the timeout. The official driver works because it's using JSSE instead of system OpenSSL.
Fix: Force pgjdbc-ng to Use JSSE
Modify your connection configuration to explicitly tell pgjdbc-ng to use JSSE instead of OpenSSL:
For DriverManager approach:
var connectionString = String .format("jdbc:pgsql://%s/%s?ssl.mode=require&ssl.provider=jsse", host, database);
For PGDataSource approach:
var dataSource = new PGDataSource(); dataSource.setUrl("jdbc:pgsql://host/dbname"); dataSource.setUser(user); dataSource.setPassword(password); dataSource.setSslMode(SSLMode.Require.name()); dataSource.setSslProvider("jsse"); // Add this line var conn = dataSource.getConnection().unwrap(PGConnection.class);
2. Verify Java Version Compatibility
If you go the JSSE route, make sure your application's Java version supports TLS 1.3:
- Java 8: Requires update 261 or later (Oracle JDK 8u261+, OpenJDK 8u262+)
- Java 11 and above: TLS 1.3 is enabled by default
If your Java version is older than these, even JSSE won't work, so you'll need to upgrade Java.
3. Check PostgreSQL Server Configurations (Work with DBA)
If forcing JSSE doesn't resolve the issue, ask your DBA to verify these settings in the SIT environment:
a. postgresql.conf
- Confirm
ssl_min_protocol_version = TLSv1.3(this enforces TLS 1.3, which you already know, but double-check) - Ensure
ssl_ciphersincludes valid TLS 1.3 cipher suites (e.g.,TLS_AES_256_GCM_SHA384,TLS_CHACHA20_POLY1305_SHA256). PostgreSQL 13's default cipher list should include these, but it's worth verifying.
b. pg_hba.conf
- Make sure there's an entry allowing your application server's IP address to connect via SSL. The entry should look something like:
(Note:hostssl your_database your_user your_app_ip/32 scram-sha-256hostsslensures only SSL connections are allowed for that entry)
c. PostgreSQL Server Logs
Ask your DBA to check the PostgreSQL logs for any errors related to the failing pgjdbc-ng connections. Look for messages like:
SSL error: no cipher matchTLS version not supported
These logs will give you precise details about why the SSL handshake is failing.
4. Rule Out Other Edge Cases
- Port Forwarding/Network Rules: Even though other connections work, double-check that pgjdbc-ng is using the correct port (default 5432) and that there are no network rules blocking specific TLS handshake packets for pgjdbc-ng (unlikely, but worth confirming).
- pgjdbc-ng Version: You're using 0.8.9—while it supports JSSE, consider upgrading to the latest version (0.9.3 as of now) to pick up any SSL-related bug fixes.
Give these steps a try, starting with forcing the JSSE provider—it's the most likely fix given your setup.
内容的提问来源于stack exchange,提问作者Bernie.T

