Testing the SSL JDBC Connection¶
If you are using Java’s default mechanism (not LibPQFactory) to create
the SSL connection, you need to make the server certificate available to
Java, which can be achieved by implementing steps given below:
- Set the below property in the Java program.
props.setProperty(“ssl”,“true”);Or, you can set the property in the connection url:
String url=“jdbc:edb://localhost/test?user=fred&password=secret&ssl=true”;
- Convert the server certificate to Java format:
$ openssl x509 -in server.crt -out server.crt.der -outform der
- Import this certificate into Java’s system truststore.
$ keytool -keystore $JAVA_HOME/lib/security/cacerts -alias postgresql -import -file server.crt.derNote
The default password for the cacerts keystore is changeit. The alias to postgresql is not important and you may select any name you desire.
If you do not have access to the system cacerts truststore, create your own truststore as below:
$ keytool -keystore mystore -alias postgresql -import -file server.crt.der
Start your Java application and test the program.
$ java -Djavax.net.ssl.trustStore=mystore com.mycompany.MyApp
For example:
$java -classpath .:/usr/edb/jdbc/edb-jdbc18.jar– Djavax.net.ssl.trustStore=mystore pg_test2 public
Note
For troubleshooting connection issues, add -Djavax.net.debug=ssl to the java command.
Using SSL without Certificate Validation¶
By default the combination of SSL=true and setting the connection URL
parameter sslfactory=com.edb.ssl.NonValidatingFactory encrypts the
connection but does not validate the SSL certificate. To enforce
certificate validation, you must use a Custom SSLSocketFactory.
For more details about writing a Custom SSLSocketFactory, refer to:
https://jdbc.postgresql.org/documentation/head/ssl-factory.html