jackc/pgx · error

failed to parse certificate from server

Error message

failed to parse certificate from server: {err}

What it means

Returned inside the verify-ca TLS callback after crypto/tls handed the server's certificate chain to pgx and x509 certificate chain verification failed against the configured root CAs. The wrapper adds context around the underlying x509 error, which is chained via %w and remains inspectable with errors.As.

Solutions

  1. Check that the server's certificate is signed by a CA present in sslrootcert
  2. Verify the server certificate has not expired
  3. Inspect the wrapped x509.CertificateInvalidError/SystemRootsError for the precise reason
Defensive patterns

Strategy: try-catch

When it happens

Trigger: Thrown at pgconn/config.go:897 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/13c2c9fee118b44a. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/config.go:897

	nextCase:
		fallthrough
	case "verify-ca":
		// Don't perform the default certificate verification because it
		// will verify the hostname. Instead, verify the server's
		// certificate chain ourselves in VerifyPeerCertificate and
		// ignore the server name. This emulates libpq's verify-ca
		// behavior.
		//
		// See https://github.com/golang/go/issues/21971#issuecomment-332693931
		// and https://pkg.go.dev/crypto/tls?tab=doc#example-Config-VerifyPeerCertificate
		// for more info.
		tlsConfig.InsecureSkipVerify = true
		tlsConfig.VerifyPeerCertificate = func(certificates [][]byte, _ [][]*x509.Certificate) error {
			certs := make([]*x509.Certificate, len(certificates))
			for i, asn1Data := range certificates {
				cert, err := x509.ParseCertificate(asn1Data)
				if err != nil {
					return errors.New("failed to parse certificate from server: " + err.Error())
				}
				certs[i] = cert
			}

			// Leave DNSName empty to skip hostname verification.
			opts := x509.VerifyOptions{
				Roots:         tlsConfig.RootCAs,
				Intermediates: x509.NewCertPool(),
			}
			// Skip the first cert because it's the leaf. All others
			// are intermediates.
			for _, cert := range certs[1:] {
				opts.Intermediates.AddCert(cert)
			}
			_, err := certs[0].Verify(opts)
			return err
		}
	case "verify-full":

View on GitHub (pinned to ec1a0befd2)