jackc/pgx · error

failed to decode sslkey

Error message

failed to decode sslkey

What it means

The file given by sslkey was read successfully but pem.Decode could not find any PEM block in it — the key file is not valid PEM (e.g. it is DER-encoded, a PKCS#12 bundle, or corrupted). The key file's contents are the faulty input.

Solutions

  1. Convert the key to PEM format (e.g. openssl rsa -in key.der -out key.pem)
  2. Verify the file actually contains a PRIVATE KEY block
  3. Ensure sslkey points to the key matching sslcert, not a certificate or CSR
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at pgconn/config.go:932 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/a17b6e51bef06b70. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/config.go:932

		}
	case "verify-full":
		tlsConfig.ServerName = host
	default:
		return nil, errors.New("sslmode is invalid")
	}

	if (sslcert != "" && sslkey == "") || (sslcert == "" && sslkey != "") {
		return nil, errors.New(`both "sslcert" and "sslkey" are required`)
	}

	if sslcert != "" && sslkey != "" {
		buf, err := os.ReadFile(sslkey)
		if err != nil {
			return nil, fmt.Errorf("unable to read sslkey: %w", err)
		}
		block, _ := pem.Decode(buf)
		if block == nil {
			return nil, errors.New("failed to decode sslkey")
		}
		var pemKey []byte
		var decryptedKey []byte
		var decryptedError error
		// If PEM is encrypted, attempt to decrypt using pass phrase
		if x509.IsEncryptedPEMBlock(block) {
			// Attempt decryption with pass phrase
			// NOTE: only supports RSA (PKCS#1)
			if sslpassword != "" {
				decryptedKey, decryptedError = x509.DecryptPEMBlock(block, []byte(sslpassword)) //nolint:ineffassign
			}
			// if sslpassword not provided or has decryption error when use it
			// try to find sslpassword with callback function
			if sslpassword == "" || decryptedError != nil {
				if parseConfigOptions.GetSSLPassword != nil {
					sslpassword = parseConfigOptions.GetSSLPassword(context.Background())
				}
				if sslpassword == "" {

View on GitHub (pinned to ec1a0befd2)