jackc/pgx · error

unable to load cert

Error message

unable to load cert: %w

What it means

The SSL client certificate and key were read successfully but tls.X509KeyPair rejected them — usually a key/certificate mismatch or malformed PEM data. The wrapped error carries the crypto/tls diagnostic.

Solutions

  1. Verify the certificate and key are a matching pair
  2. Regenerate the key/certificate pair if they do not match
  3. Check the PEM files are not corrupted or truncated
  4. Use openssl x509 and openssl rsa to inspect the files
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at pgconn/config.go:974 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/97d6d442292d7cf1. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/config.go:974

			if decryptedError != nil {
				return nil, fmt.Errorf("unable to decrypt key: %w", decryptedError)
			}

			pemBytes := pem.Block{
				Type:  "RSA PRIVATE KEY",
				Bytes: decryptedKey,
			}
			pemKey = pem.EncodeToMemory(&pemBytes)
		} else {
			pemKey = pem.EncodeToMemory(block)
		}
		certfile, err := os.ReadFile(sslcert)
		if err != nil {
			return nil, fmt.Errorf("unable to read cert: %w", err)
		}
		cert, err := tls.X509KeyPair(certfile, pemKey)
		if err != nil {
			return nil, fmt.Errorf("unable to load cert: %w", err)
		}
		tlsConfig.Certificates = []tls.Certificate{cert}
	}

	// Set Server Name Indication (SNI), if enabled by connection parameters.
	// Per RFC 6066, do not set it if the host is a literal IP address (IPv4
	// or IPv6).
	if sslsni == "1" && net.ParseIP(host) == nil {
		tlsConfig.ServerName = host
	}

	switch sslmode {
	case "allow":
		return []*tls.Config{nil, tlsConfig}, nil
	case "prefer":
		return []*tls.Config{tlsConfig, nil}, nil
	case "require", "verify-ca", "verify-full":
		return []*tls.Config{tlsConfig}, nil

View on GitHub (pinned to ec1a0befd2)