jackc/pgx · error

unable to find sslpassword

Error message

unable to find sslpassword

What it means

The SSL client key is PEM-encrypted but no password could be obtained: sslpassword was not provided and the GetSSLPassword callback either is not set or returned an empty string. Client certificate authentication cannot proceed.

Solutions

  1. Set the sslpassword connection parameter
  2. Provide a ParseConfigWithOptions option with a GetSSLPassword callback
  3. Use an unencrypted key file if security policy allows
  4. Verify the callback returns a non-empty password
Defensive patterns

Strategy: fallback

When it happens

Trigger: Thrown at pgconn/config.go:951 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/a9b7fa29c75c0166. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/config.go:951

		}
		var pemKey []byte
		var decryptedKey []byte
		var decryptedError error
		// If PEM is encrypted, attempt to decrypt using pass phrase
		if x509.IsEncryptedPEMBlock(block) {
			// Attempt decryption with pass phrase
			// NOTE: only supports RSA (PKCS#1)
			if sslpassword != "" {
				decryptedKey, decryptedError = x509.DecryptPEMBlock(block, []byte(sslpassword)) //nolint:ineffassign
			}
			// if sslpassword not provided or has decryption error when use it
			// try to find sslpassword with callback function
			if sslpassword == "" || decryptedError != nil {
				if parseConfigOptions.GetSSLPassword != nil {
					sslpassword = parseConfigOptions.GetSSLPassword(context.Background())
				}
				if sslpassword == "" {
					return nil, fmt.Errorf("unable to find sslpassword")
				}
			}
			decryptedKey, decryptedError = x509.DecryptPEMBlock(block, []byte(sslpassword))
			// Should we also provide warning for PKCS#1 needed?
			if decryptedError != nil {
				return nil, fmt.Errorf("unable to decrypt key: %w", decryptedError)
			}

			pemBytes := pem.Block{
				Type:  "RSA PRIVATE KEY",
				Bytes: decryptedKey,
			}
			pemKey = pem.EncodeToMemory(&pemBytes)
		} else {
			pemKey = pem.EncodeToMemory(block)
		}
		certfile, err := os.ReadFile(sslcert)
		if err != nil {

View on GitHub (pinned to ec1a0befd2)