jackc/pgx · error

unable to read sslkey

Error message

unable to read sslkey: %w

What it means

The SSL client key file (sslkey) could not be read from disk. The wrapped error is the file read error, usually a missing file or wrong permissions. Note that PostgreSQL also requires the key file to have 0600 permissions.

Solutions

  1. Verify the sslkey path is correct
  2. Check file permissions (should be readable by the client, ideally 0600)
  3. Confirm the file exists on the client machine
  4. Ensure both sslcert and sslkey are set together
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at pgconn/config.go:928 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/33870cebaeec239a. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/config.go:928

				opts.Intermediates.AddCert(cert)
			}
			_, err := certs[0].Verify(opts)
			return err
		}
	case "verify-full":
		tlsConfig.ServerName = host
	default:
		return nil, errors.New("sslmode is invalid")
	}

	if (sslcert != "" && sslkey == "") || (sslcert == "" && sslkey != "") {
		return nil, errors.New(`both "sslcert" and "sslkey" are required`)
	}

	if sslcert != "" && sslkey != "" {
		buf, err := os.ReadFile(sslkey)
		if err != nil {
			return nil, fmt.Errorf("unable to read sslkey: %w", err)
		}
		block, _ := pem.Decode(buf)
		if block == nil {
			return nil, errors.New("failed to decode sslkey")
		}
		var pemKey []byte
		var decryptedKey []byte
		var decryptedError error
		// If PEM is encrypted, attempt to decrypt using pass phrase
		if x509.IsEncryptedPEMBlock(block) {
			// Attempt decryption with pass phrase
			// NOTE: only supports RSA (PKCS#1)
			if sslpassword != "" {
				decryptedKey, decryptedError = x509.DecryptPEMBlock(block, []byte(sslpassword)) //nolint:ineffassign
			}
			// if sslpassword not provided or has decryption error when use it
			// try to find sslpassword with callback function
			if sslpassword == "" || decryptedError != nil {

View on GitHub (pinned to ec1a0befd2)