为何sslrootcert=system在Ubuntu版psql 15.5中无法生效?
问题:Ubuntu环境下psql 15.5使用
sslrootcert=system报错的原因 我有两台主机,均已下载并安装AWS RDS证书包。尝试通过以下命令连接PostgreSQL数据库:
psql "postgresql://user@example.com/user?sslmode=verify-full&sslrootcert=system"
根据PostgreSQL官方文档,sslrootcert=system是合法配置,且会默认将sslmode设为verify-full。但Debian发行版的psql 15.5(版本标识:15.5-1.pgdg120+1)可正常连接,而Ubuntu发行版的同版本psql(版本标识:15.5-0ubuntu0.23.10.1)却报错:
psql: error: connection to server at "example.com" (x.y.z.a), port 5432 failed: root certificate file "system" does not exist Either provide the file or change sslmode to disable server certificate verification.
请问为何sslrootcert=system在Ubuntu环境的该版本中无法正常工作?
原因分析与解决办法
核心原因
问题源于两个发行版的PostgreSQL包维护差异:
- Debian使用的是PostgreSQL官方维护的PGDG仓库包(版本标识中的
pgdg是明显标志),这类包已集成PostgreSQL社区对sslrootcert=system特性的支持,能正确识别该参数并调用系统根证书存储。 - Ubuntu官方打包的psql版本(版本标识带
ubuntu)尚未将该特性的支持补丁合并到发行版包中,因此会把system当作普通的证书文件名去查找,找不到就抛出错误。
sslrootcert=system是PostgreSQL 15引入的新特性,允许客户端直接使用系统级根证书池验证服务器证书,但该特性需要打包时启用对应配置才能生效,不同发行版的打包节奏不一致导致了这个差异。
解决办法
- 更换为PGDG仓库的PostgreSQL包:在Ubuntu上添加PostgreSQL官方的PGDG仓库,安装对应版本的psql,即可和Debian环境一样支持
sslrootcert=system参数。 - 指定具体证书路径:放弃使用
sslrootcert=system,直接指定已安装的AWS RDS证书文件路径,示例:psql "postgresql://user@example.com/user?sslmode=verify-full&sslrootcert=/usr/share/ca-certificates/aws/rds-ca-2019-root.pem" - 依赖系统信任的证书:如果AWS RDS的根证书已被添加到系统信任存储中,可仅设置
sslmode=verify-full,不指定sslrootcert,psql会自动使用系统根证书完成验证。
内容的提问来源于stack exchange,提问作者Eugen Konkov
相关产品推荐
相关产品推荐

