jackc/pgx · error

unable to load system certificate pool

Error message

unable to load system certificate pool: %w

What it means

The client was configured with sslrootcert=system, meaning the OS certificate store should be used for CA verification, but the system certificate pool could not be loaded. The wrapped error describes the OS-level failure.

Solutions

  1. Check the wrapped error for the OS-specific cause
  2. Verify the system CA store is installed and accessible
  3. On Linux check /etc/ssl/certs; on Windows check the certificate store
  4. Fall back to an explicit sslrootcert file pointing to your CA bundle
Defensive patterns

Strategy: fallback

When it happens

Trigger: Thrown at pgconn/config.go:842 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/e2169a404ce0d7b5. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/config.go:842

	tlsConfig := &tls.Config{}

	if sslnegotiation == "direct" {
		tlsConfig.NextProtos = []string{"postgresql"}
		if sslmode == "prefer" {
			sslmode = "require"
		}
	}

	if sslrootcert != "" {
		var caCertPool *x509.CertPool

		if sslrootcert == "system" {
			var err error

			caCertPool, err = x509.SystemCertPool()
			if err != nil {
				return nil, fmt.Errorf("unable to load system certificate pool: %w", err)
			}

			sslmode = "verify-full"
		} else {
			caCertPool = x509.NewCertPool()

			caPath := sslrootcert
			caCert, err := os.ReadFile(caPath)
			if err != nil {
				return nil, fmt.Errorf("unable to read CA file: %w", err)
			}

			if !caCertPool.AppendCertsFromPEM(caCert) {
				return nil, errors.New("unable to add CA to cert pool")
			}
		}

		tlsConfig.RootCAs = caCertPool

View on GitHub (pinned to ec1a0befd2)