jackc/pgx · error
unable to read sslkey
Error message
unable to read sslkey: %w
What it means
The SSL client key file (sslkey) could not be read from disk. The wrapped error is the file read error, usually a missing file or wrong permissions. Note that PostgreSQL also requires the key file to have 0600 permissions.
Solutions
- Verify the sslkey path is correct
- Check file permissions (should be readable by the client, ideally 0600)
- Confirm the file exists on the client machine
- Ensure both sslcert and sslkey are set together
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at pgconn/config.go:928 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04).
Data as JSON: /api/errors/33870cebaeec239a.
Report an issue: GitHub.
Appendix: source
Thrown at pgconn/config.go:928
opts.Intermediates.AddCert(cert)
}
_, err := certs[0].Verify(opts)
return err
}
case "verify-full":
tlsConfig.ServerName = host
default:
return nil, errors.New("sslmode is invalid")
}
if (sslcert != "" && sslkey == "") || (sslcert == "" && sslkey != "") {
return nil, errors.New(`both "sslcert" and "sslkey" are required`)
}
if sslcert != "" && sslkey != "" {
buf, err := os.ReadFile(sslkey)
if err != nil {
return nil, fmt.Errorf("unable to read sslkey: %w", err)
}
block, _ := pem.Decode(buf)
if block == nil {
return nil, errors.New("failed to decode sslkey")
}
var pemKey []byte
var decryptedKey []byte
var decryptedError error
// If PEM is encrypted, attempt to decrypt using pass phrase
if x509.IsEncryptedPEMBlock(block) {
// Attempt decryption with pass phrase
// NOTE: only supports RSA (PKCS#1)
if sslpassword != "" {
decryptedKey, decryptedError = x509.DecryptPEMBlock(block, []byte(sslpassword)) //nolint:ineffassign
}
// if sslpassword not provided or has decryption error when use it
// try to find sslpassword with callback function
if sslpassword == "" || decryptedError != nil {View on GitHub (pinned to ec1a0befd2)