jackc/pgx · error
unable to read cert
Error message
unable to read cert: %w
What it means
The SSL client certificate file (sslcert) could not be read from disk. The wrapped error is the os.ReadFile failure, typically a missing file or a permissions issue.
Solutions
- Verify the sslcert path points to a valid PEM certificate
- Check file existence and read permissions
- Ensure both sslcert and sslkey are provided
- Confirm paths are relative to the client machine or $HOME/.postgresql
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at pgconn/config.go:970 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04).
Data as JSON: /api/errors/dd5857965c9c36de.
Report an issue: GitHub.
Appendix: source
Thrown at pgconn/config.go:970
}
}
decryptedKey, decryptedError = x509.DecryptPEMBlock(block, []byte(sslpassword))
// Should we also provide warning for PKCS#1 needed?
if decryptedError != nil {
return nil, fmt.Errorf("unable to decrypt key: %w", decryptedError)
}
pemBytes := pem.Block{
Type: "RSA PRIVATE KEY",
Bytes: decryptedKey,
}
pemKey = pem.EncodeToMemory(&pemBytes)
} else {
pemKey = pem.EncodeToMemory(block)
}
certfile, err := os.ReadFile(sslcert)
if err != nil {
return nil, fmt.Errorf("unable to read cert: %w", err)
}
cert, err := tls.X509KeyPair(certfile, pemKey)
if err != nil {
return nil, fmt.Errorf("unable to load cert: %w", err)
}
tlsConfig.Certificates = []tls.Certificate{cert}
}
// Set Server Name Indication (SNI), if enabled by connection parameters.
// Per RFC 6066, do not set it if the host is a literal IP address (IPv4
// or IPv6).
if sslsni == "1" && net.ParseIP(host) == nil {
tlsConfig.ServerName = host
}
switch sslmode {
case "allow":
return []*tls.Config{nil, tlsConfig}, nilView on GitHub (pinned to ec1a0befd2)