jackc/pgx · error

unable to read CA file

Error message

unable to read CA file: %w

What it means

The CA certificate file specified via sslrootcert could not be read from disk. The wrapped error is the os.ReadFile error, typically a missing file or permission problem.

Solutions

  1. Verify the sslrootcert path is correct and absolute
  2. Check file permissions allow read access by the application user
  3. Confirm the file exists on the machine running the client
  4. Use a relative path from the working directory or $HOME/.postgresql rootcert
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at pgconn/config.go:852 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/67a43c993517cda3. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/config.go:852

	if sslrootcert != "" {
		var caCertPool *x509.CertPool

		if sslrootcert == "system" {
			var err error

			caCertPool, err = x509.SystemCertPool()
			if err != nil {
				return nil, fmt.Errorf("unable to load system certificate pool: %w", err)
			}

			sslmode = "verify-full"
		} else {
			caCertPool = x509.NewCertPool()

			caPath := sslrootcert
			caCert, err := os.ReadFile(caPath)
			if err != nil {
				return nil, fmt.Errorf("unable to read CA file: %w", err)
			}

			if !caCertPool.AppendCertsFromPEM(caCert) {
				return nil, errors.New("unable to add CA to cert pool")
			}
		}

		tlsConfig.RootCAs = caCertPool
		tlsConfig.ClientCAs = caCertPool
	}

	switch sslmode {
	case "disable":
		return []*tls.Config{nil}, nil
	case "allow", "prefer":
		tlsConfig.InsecureSkipVerify = true
	case "require":
		// According to PostgreSQL documentation, if a root CA file exists,

View on GitHub (pinned to ec1a0befd2)