jackc/pgx · error

tls-server-end-point channel binding is undefined for…

Error message

tls-server-end-point channel binding is undefined for certificate signature algorithm %v

What it means

TLS channel binding (tls-server-end-point, RFC 5929) requires hashing the server certificate with an algorithm derived from its signature algorithm. The certificate uses a signature algorithm for which RFC 5929 defines no hash, so channel binding is impossible and the connection fails.

Solutions

  1. Reissue the server certificate with a standard signature algorithm (e.g. SHA-256 RSA or ECDSA)
  2. Use a different channel binding type if the server supports it
  3. Disable channel binding if the deployment allows
  4. Verify the certificate chain is using modern algorithms
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at pgconn/auth_scram.go:402 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/1482e3e3028682d5. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/auth_scram.go:402

	cert := state.PeerCertificates[0]

	// Per RFC 5929 section 4.1: If the certificate's signatureAlgorithm uses
	// MD5 or SHA-1, use SHA-256. Otherwise use the hash from the signature
	// algorithm.
	//
	// See: https://www.rfc-editor.org/rfc/rfc5929.html#section-4.1
	var h hash.Hash
	switch cert.SignatureAlgorithm {
	case x509.MD5WithRSA, x509.SHA1WithRSA, x509.ECDSAWithSHA1:
		h = sha256.New()
	case x509.SHA256WithRSA, x509.SHA256WithRSAPSS, x509.ECDSAWithSHA256:
		h = sha256.New()
	case x509.SHA384WithRSA, x509.SHA384WithRSAPSS, x509.ECDSAWithSHA384:
		h = sha512.New384()
	case x509.SHA512WithRSA, x509.SHA512WithRSAPSS, x509.ECDSAWithSHA512:
		h = sha512.New()
	default:
		return nil, fmt.Errorf("tls-server-end-point channel binding is undefined for certificate signature algorithm %v", cert.SignatureAlgorithm)
	}

	h.Write(cert.Raw)
	return h.Sum(nil), nil
}

View on GitHub (pinned to ec1a0befd2)