jackc/pgx · error
unable to load system certificate pool
Error message
unable to load system certificate pool: %w
What it means
The client was configured with sslrootcert=system, meaning the OS certificate store should be used for CA verification, but the system certificate pool could not be loaded. The wrapped error describes the OS-level failure.
Solutions
- Check the wrapped error for the OS-specific cause
- Verify the system CA store is installed and accessible
- On Linux check /etc/ssl/certs; on Windows check the certificate store
- Fall back to an explicit sslrootcert file pointing to your CA bundle
Defensive patterns
Strategy: fallback
When it happens
Trigger: Thrown at pgconn/config.go:842 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04).
Data as JSON: /api/errors/e2169a404ce0d7b5.
Report an issue: GitHub.
Appendix: source
Thrown at pgconn/config.go:842
tlsConfig := &tls.Config{}
if sslnegotiation == "direct" {
tlsConfig.NextProtos = []string{"postgresql"}
if sslmode == "prefer" {
sslmode = "require"
}
}
if sslrootcert != "" {
var caCertPool *x509.CertPool
if sslrootcert == "system" {
var err error
caCertPool, err = x509.SystemCertPool()
if err != nil {
return nil, fmt.Errorf("unable to load system certificate pool: %w", err)
}
sslmode = "verify-full"
} else {
caCertPool = x509.NewCertPool()
caPath := sslrootcert
caCert, err := os.ReadFile(caPath)
if err != nil {
return nil, fmt.Errorf("unable to read CA file: %w", err)
}
if !caCertPool.AppendCertsFromPEM(caCert) {
return nil, errors.New("unable to add CA to cert pool")
}
}
tlsConfig.RootCAs = caCertPoolView on GitHub (pinned to ec1a0befd2)