jackc/pgx · error
tls-server-end-point channel binding is undefined for…
Error message
tls-server-end-point channel binding is undefined for certificate signature algorithm %v
What it means
TLS channel binding (tls-server-end-point, RFC 5929) requires hashing the server certificate with an algorithm derived from its signature algorithm. The certificate uses a signature algorithm for which RFC 5929 defines no hash, so channel binding is impossible and the connection fails.
Solutions
- Reissue the server certificate with a standard signature algorithm (e.g. SHA-256 RSA or ECDSA)
- Use a different channel binding type if the server supports it
- Disable channel binding if the deployment allows
- Verify the certificate chain is using modern algorithms
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at pgconn/auth_scram.go:402 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04).
Data as JSON: /api/errors/1482e3e3028682d5.
Report an issue: GitHub.
Appendix: source
Thrown at pgconn/auth_scram.go:402
cert := state.PeerCertificates[0]
// Per RFC 5929 section 4.1: If the certificate's signatureAlgorithm uses
// MD5 or SHA-1, use SHA-256. Otherwise use the hash from the signature
// algorithm.
//
// See: https://www.rfc-editor.org/rfc/rfc5929.html#section-4.1
var h hash.Hash
switch cert.SignatureAlgorithm {
case x509.MD5WithRSA, x509.SHA1WithRSA, x509.ECDSAWithSHA1:
h = sha256.New()
case x509.SHA256WithRSA, x509.SHA256WithRSAPSS, x509.ECDSAWithSHA256:
h = sha256.New()
case x509.SHA384WithRSA, x509.SHA384WithRSAPSS, x509.ECDSAWithSHA384:
h = sha512.New384()
case x509.SHA512WithRSA, x509.SHA512WithRSAPSS, x509.ECDSAWithSHA512:
h = sha512.New()
default:
return nil, fmt.Errorf("tls-server-end-point channel binding is undefined for certificate signature algorithm %v", cert.SignatureAlgorithm)
}
h.Write(cert.Raw)
return h.Sum(nil), nil
}
View on GitHub (pinned to ec1a0befd2)