PostgreSQL error
server does not support SSL, but SSL was required
Your client was told to require TLS (sslmode=require or stronger), and the server said it doesn’t do TLS, so the client stopped. Either connect without requiring it, which is fine on your own machine, or turn TLS on in the server.
connection to server at "localhost" (::1), port 54318 failed: server does not support SSL, but SSL was required
Tested on PostgreSQL 18.6, psql 18.6 · Updated 9 October 2026
What it means
At the start of a connection, the client asks the server whether it accepts TLS (still called SSL
in PostgreSQL’s settings). This server answered no. Because the client’s sslmode was require,
verify-ca or verify-full, it refused to continue without encryption, and stopped before sending
your user name or password.
libpq, the client library behind psql and most drivers, raises this error itself, so there’s no
SQLSTATE. Nothing is wrong with your credentials, and the server didn’t log anything.
sslmode decides what the client accepts:
| sslmode | Without TLS on the server |
|---|---|
disable | Connects without TLS. |
allow, prefer (the default) | Connects without TLS. |
require, verify-ca, verify-full | Fails with this error. |
Common causes
- The server has TLS turned off.
sslisoffby default, including in the official Docker image, so most local and development servers don’t offer it. - TLS was required somewhere you didn’t look:
?sslmode=requirein a URL copied from a hosted database,PGSSLMODE=requirein your shell profile or CI settings, or an app config that sets it for every environment. - The server tried to turn TLS on and failed. If the certificate or key can’t be loaded,
PostgreSQL logs it and carries on without TLS, while
SHOW sslstill sayson. - A pooler or proxy in between doesn’t offer TLS. PgBouncer, for example, has its own
client_tls_sslmode, which isdisableunless you set it.
How to fix it
On your own machine, don’t require TLS
For a server on localhost or in a local container, the traffic never leaves your Mac. Use the
default prefer, or disable:
psql "host=localhost port=5432 user=<user> dbname=<database> sslmode=prefer"
Check whether your shell is setting it for you:
echo $PGSSLMODE
unset PGSSLMODE
Turn TLS on in the server
For anything reached over a network, turn TLS on rather than turning the client check off. In
postgresql.conf (or with ALTER SYSTEM):
ssl = on
ssl_cert_file = '/etc/postgresql/server.crt'
ssl_key_file = '/etc/postgresql/server.key'
The key must be readable only by the server’s user (chmod 600), or owned by root with mode 640
and a group the server’s user is in. Then reload; a restart isn’t needed:
SELECT pg_reload_conf();
Check the server log right after. If the certificate didn’t load, it says so, and TLS stays off:
LOG: could not load server certificate file "server.crt": No such file or directory
LOG: SSL configuration was not reloaded
Then confirm from a new connection:
SELECT ssl, version FROM pg_stat_ssl WHERE pid = pg_backend_pid();
For a test server, openssl req -new -x509 -days 365 -nodes -text -out server.crt -keyout server.key -subj "/CN=<host>" makes a self-signed certificate. Clients can use it with sslmode=require, but
not verify-full, which needs a certificate from a CA the client trusts.
Behind a pooler
Configure TLS on the pooler as well. For PgBouncer, that’s client_tls_sslmode,
client_tls_cert_file and client_tls_key_file.
Reproduce it
The PostgreSQL 18.6 test server on port 54318 has ssl = off. Every mode that requires TLS fails the
same way:
psql "host=localhost port=54318 user=inlet dbname=inlet sslmode=require" -c 'select 1'
psql: error: connection to server at "localhost" (::1), port 54318 failed: server does not support SSL, but SSL was required
sslmode=verify-ca, sslmode=verify-full, PGSSLMODE=require and a URL ending in
?sslmode=require print the identical line. With sslmode=prefer the connection succeeds without
TLS (pg_stat_ssl.ssl is f).
PostgreSQL 17 and later can also start TLS straight away, without asking first
(sslnegotiation=direct). Against this server, that fails with a different message:
psql: error: connection to server at "localhost" (::1), port 54318 failed: SSL error: unexpected eof while reading
On a temporary PostgreSQL 18.6 server, ALTER SYSTEM SET ssl = on and a reload without a certificate
left TLS off. SHOW ssl answered on, the log said SSL configuration was not reloaded, and the
client still got the error. After pointing ssl_cert_file and ssl_key_file at a certificate and
reloading again:
ssl | version
-----+---------
t | TLSv1.3
(1 row)
In Inlet
Inlet supports every libpq sslmode. For a local server, choose prefer or disable in the
connection’s TLS setting; for a remote one, turn TLS on in the server and use verify-full, which
Inlet checks against the certificates macOS trusts, or a custom CA file.