Skip to content

ssl_key_file

ssl_key_file is the PostgreSQL setting that identifies the location of the SSL server private key file.
Note

Fact — official short description: “Location of the SSL server private key file.”

Identity

Type , Valuestring
Upstream pg_settings type
Context , Valuesighup
Takes effect after configuration reload
Unit , Value
Raw unit
Range , Value
Raw limits in the last observed version
Enum values , Value
— for non-enum types
Category , ValueConnections and Authentication / SSL
Upstream classification
Latest boot value , Valueserver.key
server.key

Lifecycle

Fact Value
First observed PG9.2
Present in PG9.2–19 Beta 3
Removed in No
Introduction commit a445cb92ef5b — Add parameters for controlling locations of server-side SSL files
Commit date 2012-02-22
Discussion

Default history

Measured PG9.0–19 Beta 3 boot defaults
Versions Raw boot_val Unit Human value
PG9.2–19 Beta 3 server.key server.key

How it works

ssl_key_file identifies the location of the SSL server private key file. The file contains the private key matching ssl_cert_file; PostgreSQL enforces restrictive ownership and permissions before accepting it.

ssl_key_file is a SIGHUP-context setting: a configuration reload activates the new server value without a restart; subsequent operations that consult it use the refreshed value. Existing TLS sessions are not renegotiated.

It participates in the TLS context used for new handshakes. ssl enables transport, pg_hba.conf decides which connection classes require it, and the certificate, key, CA, revocation, protocol, and cipher settings must form one valid policy.

Tuning advice

Tip

Advice. These are workload-specific starting points and must be validated with measurements.

Workload Guidance
OLTP Keep ssl_key_file owned by the PostgreSQL service account with PostgreSQL-accepted restrictive permissions, ensure it matches ssl_cert_file, and rotate it through an audited secret-delivery path.
OLAP Use the same private-key controls for analytical nodes; workload type never justifies a shared, group-writable, or copied key outside the managed PKI process.
Small nodes Prefer one managed key with expiry/renewal tests and protected backups. If it is encrypted, test ssl_passphrase_command and reload behavior before an unattended restart.

Pigsty

Values use the fixed 8-vCPU, 32-GiB, 100-GiB SSD fixture and render the current Pigsty templates for PG19 Beta 3; this does not assert current Pigsty support for that historical or beta release.

Template Effective value Versus upstream boot Source expression
OLTP /pg/cert/server.key different '/pg/cert/server.key'
OLAP /pg/cert/server.key different '/pg/cert/server.key'
CRIT /pg/cert/server.key different '/pg/cert/server.key'
TINY /pg/cert/server.key different '/pg/cert/server.key'
Caution

Advice — pending human review. Fact from the current Pigsty template projection: OLTP: PG9.2–19 Beta 3 = /pg/cert/server.key (dcs); OLAP: PG9.2–19 Beta 3 = /pg/cert/server.key (dcs); CRIT: PG9.2–19 Beta 3 = /pg/cert/server.key (dcs); TINY: PG9.2–19 Beta 3 = /pg/cert/server.key (dcs). Advice, pending human review — Editorial inference: The common managed private-key path pairs with the server certificate and centralizes ownership and renewal conventions.

Common pitfalls

  • Editing ssl_key_file without reloading configuration and verifying the effective value and subsequent behavior.
  • Updating only one TLS file or policy knob and leaving an invalid chain, unreadable key, or incompatible protocol set.
  • Assuming a reload renegotiates existing sessions; TLS policy changes affect new handshakes.
  • Installing a private key with ownership or permissions that PostgreSQL rejects, or leaking it to a readable group.

ssl · ssl_cert_file · ssl_ca_file · ssl_crl_file · ssl_min_protocol_version

References