InletDownload

PostgreSQL error

server does not support SSL, but SSL was required

Your client was told to require TLS (sslmode=require or stronger), and the server said it doesn’t do TLS, so the client stopped. Either connect without requiring it, which is fine on your own machine, or turn TLS on in the server.

connection to server at "localhost" (::1), port 54318 failed: server does not support SSL, but SSL was required

Tested on PostgreSQL 18.6, psql 18.6 · Updated 9 October 2026

What it means

At the start of a connection, the client asks the server whether it accepts TLS (still called SSL in PostgreSQL’s settings). This server answered no. Because the client’s sslmode was require, verify-ca or verify-full, it refused to continue without encryption, and stopped before sending your user name or password.

libpq, the client library behind psql and most drivers, raises this error itself, so there’s no SQLSTATE. Nothing is wrong with your credentials, and the server didn’t log anything.

sslmode decides what the client accepts:

sslmodeWithout TLS on the server
disableConnects without TLS.
allow, prefer (the default)Connects without TLS.
require, verify-ca, verify-fullFails with this error.

Common causes

  1. The server has TLS turned off. ssl is off by default, including in the official Docker image, so most local and development servers don’t offer it.
  2. TLS was required somewhere you didn’t look: ?sslmode=require in a URL copied from a hosted database, PGSSLMODE=require in your shell profile or CI settings, or an app config that sets it for every environment.
  3. The server tried to turn TLS on and failed. If the certificate or key can’t be loaded, PostgreSQL logs it and carries on without TLS, while SHOW ssl still says on.
  4. A pooler or proxy in between doesn’t offer TLS. PgBouncer, for example, has its own client_tls_sslmode, which is disable unless you set it.

How to fix it

On your own machine, don’t require TLS

For a server on localhost or in a local container, the traffic never leaves your Mac. Use the default prefer, or disable:

psql "host=localhost port=5432 user=<user> dbname=<database> sslmode=prefer"

Check whether your shell is setting it for you:

echo $PGSSLMODE
unset PGSSLMODE

Turn TLS on in the server

For anything reached over a network, turn TLS on rather than turning the client check off. In postgresql.conf (or with ALTER SYSTEM):

ssl = on
ssl_cert_file = '/etc/postgresql/server.crt'
ssl_key_file = '/etc/postgresql/server.key'

The key must be readable only by the server’s user (chmod 600), or owned by root with mode 640 and a group the server’s user is in. Then reload; a restart isn’t needed:

SELECT pg_reload_conf();

Check the server log right after. If the certificate didn’t load, it says so, and TLS stays off:

LOG:  could not load server certificate file "server.crt": No such file or directory
LOG:  SSL configuration was not reloaded

Then confirm from a new connection:

SELECT ssl, version FROM pg_stat_ssl WHERE pid = pg_backend_pid();

For a test server, openssl req -new -x509 -days 365 -nodes -text -out server.crt -keyout server.key -subj "/CN=<host>" makes a self-signed certificate. Clients can use it with sslmode=require, but not verify-full, which needs a certificate from a CA the client trusts.

Behind a pooler

Configure TLS on the pooler as well. For PgBouncer, that’s client_tls_sslmode, client_tls_cert_file and client_tls_key_file.

Reproduce it

The PostgreSQL 18.6 test server on port 54318 has ssl = off. Every mode that requires TLS fails the same way:

psql "host=localhost port=54318 user=inlet dbname=inlet sslmode=require" -c 'select 1'
psql: error: connection to server at "localhost" (::1), port 54318 failed: server does not support SSL, but SSL was required

sslmode=verify-ca, sslmode=verify-full, PGSSLMODE=require and a URL ending in ?sslmode=require print the identical line. With sslmode=prefer the connection succeeds without TLS (pg_stat_ssl.ssl is f).

PostgreSQL 17 and later can also start TLS straight away, without asking first (sslnegotiation=direct). Against this server, that fails with a different message:

psql: error: connection to server at "localhost" (::1), port 54318 failed: SSL error: unexpected eof while reading

On a temporary PostgreSQL 18.6 server, ALTER SYSTEM SET ssl = on and a reload without a certificate left TLS off. SHOW ssl answered on, the log said SSL configuration was not reloaded, and the client still got the error. After pointing ssl_cert_file and ssl_key_file at a certificate and reloading again:

 ssl | version 
-----+---------
 t   | TLSv1.3
(1 row)

In Inlet

Inlet supports every libpq sslmode. For a local server, choose prefer or disable in the connection’s TLS setting; for a remote one, turn TLS on in the server and use verify-full, which Inlet checks against the certificates macOS trusts, or a custom CA file.

Related

Sources