jackc/pgx · error
unable to decrypt key
Error message
unable to decrypt key: %w
What it means
The encrypted SSL client key could not be decrypted with the supplied password. The wrapped error is from x509.DecryptPEMBlock, typically a wrong password or an unsupported encryption scheme (only RSA PKCS#1 is supported).
Solutions
- Verify the sslpassword is correct for this key
- Regenerate the key if it uses an unsupported format; only RSA PKCS#1 PEM encryption is supported
- Use openssl rsa -in key.pem -check to validate the key/password pair
- Consider supplying the password via the GetSSLPassword callback
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at pgconn/config.go:957 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04).
Data as JSON: /api/errors/bfe936ba3fe49379.
Report an issue: GitHub.
Appendix: source
Thrown at pgconn/config.go:957
// Attempt decryption with pass phrase
// NOTE: only supports RSA (PKCS#1)
if sslpassword != "" {
decryptedKey, decryptedError = x509.DecryptPEMBlock(block, []byte(sslpassword)) //nolint:ineffassign
}
// if sslpassword not provided or has decryption error when use it
// try to find sslpassword with callback function
if sslpassword == "" || decryptedError != nil {
if parseConfigOptions.GetSSLPassword != nil {
sslpassword = parseConfigOptions.GetSSLPassword(context.Background())
}
if sslpassword == "" {
return nil, fmt.Errorf("unable to find sslpassword")
}
}
decryptedKey, decryptedError = x509.DecryptPEMBlock(block, []byte(sslpassword))
// Should we also provide warning for PKCS#1 needed?
if decryptedError != nil {
return nil, fmt.Errorf("unable to decrypt key: %w", decryptedError)
}
pemBytes := pem.Block{
Type: "RSA PRIVATE KEY",
Bytes: decryptedKey,
}
pemKey = pem.EncodeToMemory(&pemBytes)
} else {
pemKey = pem.EncodeToMemory(block)
}
certfile, err := os.ReadFile(sslcert)
if err != nil {
return nil, fmt.Errorf("unable to read cert: %w", err)
}
cert, err := tls.X509KeyPair(certfile, pemKey)
if err != nil {
return nil, fmt.Errorf("unable to load cert: %w", err)
}View on GitHub (pinned to ec1a0befd2)