jackc/pgx · error
failed to parse certificate from server
Error message
failed to parse certificate from server: {err} What it means
Returned inside the verify-ca TLS callback after crypto/tls handed the server's certificate chain to pgx and x509 certificate chain verification failed against the configured root CAs. The wrapper adds context around the underlying x509 error, which is chained via %w and remains inspectable with errors.As.
Solutions
- Check that the server's certificate is signed by a CA present in sslrootcert
- Verify the server certificate has not expired
- Inspect the wrapped x509.CertificateInvalidError/SystemRootsError for the precise reason
Defensive patterns
Strategy: try-catch
When it happens
Trigger: Thrown at pgconn/config.go:897 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
- Parsing and encoding errors: unexpected token, malformed input — why parsers reject input and how to find the real culprit.
AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04).
Data as JSON: /api/errors/13c2c9fee118b44a.
Report an issue: GitHub.
Appendix: source
Thrown at pgconn/config.go:897
nextCase:
fallthrough
case "verify-ca":
// Don't perform the default certificate verification because it
// will verify the hostname. Instead, verify the server's
// certificate chain ourselves in VerifyPeerCertificate and
// ignore the server name. This emulates libpq's verify-ca
// behavior.
//
// See https://github.com/golang/go/issues/21971#issuecomment-332693931
// and https://pkg.go.dev/crypto/tls?tab=doc#example-Config-VerifyPeerCertificate
// for more info.
tlsConfig.InsecureSkipVerify = true
tlsConfig.VerifyPeerCertificate = func(certificates [][]byte, _ [][]*x509.Certificate) error {
certs := make([]*x509.Certificate, len(certificates))
for i, asn1Data := range certificates {
cert, err := x509.ParseCertificate(asn1Data)
if err != nil {
return errors.New("failed to parse certificate from server: " + err.Error())
}
certs[i] = cert
}
// Leave DNSName empty to skip hostname verification.
opts := x509.VerifyOptions{
Roots: tlsConfig.RootCAs,
Intermediates: x509.NewCertPool(),
}
// Skip the first cert because it's the leaf. All others
// are intermediates.
for _, cert := range certs[1:] {
opts.Intermediates.AddCert(cert)
}
_, err := certs[0].Verify(opts)
return err
}
case "verify-full":View on GitHub (pinned to ec1a0befd2)