{"record":{"id":"e2169a404ce0d7b5","repo":"jackc/pgx","slug":"unable-to-load-system-certificate-pool-w","errorCode":null,"errorMessage":"unable to load system certificate pool: %w","messagePattern":"unable to load system certificate pool: %w","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"pgconn/config.go","lineNumber":842,"sourceCode":"\n\ttlsConfig := &tls.Config{}\n\n\tif sslnegotiation == \"direct\" {\n\t\ttlsConfig.NextProtos = []string{\"postgresql\"}\n\t\tif sslmode == \"prefer\" {\n\t\t\tsslmode = \"require\"\n\t\t}\n\t}\n\n\tif sslrootcert != \"\" {\n\t\tvar caCertPool *x509.CertPool\n\n\t\tif sslrootcert == \"system\" {\n\t\t\tvar err error\n\n\t\t\tcaCertPool, err = x509.SystemCertPool()\n\t\t\tif err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"unable to load system certificate pool: %w\", err)\n\t\t\t}\n\n\t\t\tsslmode = \"verify-full\"\n\t\t} else {\n\t\t\tcaCertPool = x509.NewCertPool()\n\n\t\t\tcaPath := sslrootcert\n\t\t\tcaCert, err := os.ReadFile(caPath)\n\t\t\tif err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"unable to read CA file: %w\", err)\n\t\t\t}\n\n\t\t\tif !caCertPool.AppendCertsFromPEM(caCert) {\n\t\t\t\treturn nil, errors.New(\"unable to add CA to cert pool\")\n\t\t\t}\n\t\t}\n\n\t\ttlsConfig.RootCAs = caCertPool","sourceCodeStart":824,"sourceCodeEnd":860,"githubUrl":"https://github.com/jackc/pgx/blob/ec1a0befd22592cffffdeeb0a50311b506372f4c/pgconn/config.go#L824-L860","documentation":"The client was configured with sslrootcert=system, meaning the OS certificate store should be used for CA verification, but the system certificate pool could not be loaded. The wrapped error describes the OS-level failure.","triggerScenarios":"Thrown at pgconn/config.go:842 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Check the wrapped error for the OS-specific cause","Verify the system CA store is installed and accessible","On Linux check /etc/ssl/certs; on Windows check the certificate store","Fall back to an explicit sslrootcert file pointing to your CA bundle"],"exampleFix":null,"handlingStrategy":"fallback","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"ec1a0befd22592cffffdeeb0a50311b506372f4c","analyzedAt":"2026-08-04T22:52:11.263Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}