jackc/pgx · error
failed to decode sslkey
Error message
failed to decode sslkey
What it means
The file given by sslkey was read successfully but pem.Decode could not find any PEM block in it — the key file is not valid PEM (e.g. it is DER-encoded, a PKCS#12 bundle, or corrupted). The key file's contents are the faulty input.
Solutions
- Convert the key to PEM format (e.g. openssl rsa -in key.der -out key.pem)
- Verify the file actually contains a PRIVATE KEY block
- Ensure sslkey points to the key matching sslcert, not a certificate or CSR
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at pgconn/config.go:932 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- Parsing and encoding errors: unexpected token, malformed input — why parsers reject input and how to find the real culprit.
AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04).
Data as JSON: /api/errors/a17b6e51bef06b70.
Report an issue: GitHub.
Appendix: source
Thrown at pgconn/config.go:932
}
case "verify-full":
tlsConfig.ServerName = host
default:
return nil, errors.New("sslmode is invalid")
}
if (sslcert != "" && sslkey == "") || (sslcert == "" && sslkey != "") {
return nil, errors.New(`both "sslcert" and "sslkey" are required`)
}
if sslcert != "" && sslkey != "" {
buf, err := os.ReadFile(sslkey)
if err != nil {
return nil, fmt.Errorf("unable to read sslkey: %w", err)
}
block, _ := pem.Decode(buf)
if block == nil {
return nil, errors.New("failed to decode sslkey")
}
var pemKey []byte
var decryptedKey []byte
var decryptedError error
// If PEM is encrypted, attempt to decrypt using pass phrase
if x509.IsEncryptedPEMBlock(block) {
// Attempt decryption with pass phrase
// NOTE: only supports RSA (PKCS#1)
if sslpassword != "" {
decryptedKey, decryptedError = x509.DecryptPEMBlock(block, []byte(sslpassword)) //nolint:ineffassign
}
// if sslpassword not provided or has decryption error when use it
// try to find sslpassword with callback function
if sslpassword == "" || decryptedError != nil {
if parseConfigOptions.GetSSLPassword != nil {
sslpassword = parseConfigOptions.GetSSLPassword(context.Background())
}
if sslpassword == "" {View on GitHub (pinned to ec1a0befd2)