Testing the SSL JDBC Connection

If you are using Java’s default mechanism (not LibPQFactory) to create the SSL connection, you need to make the server certificate available to Java, which can be achieved by implementing steps given below:

  1. Set the below property in the Java program.

props.setProperty(“ssl”,“true”);

Or, you can set the property in the connection url:

String url=“jdbc:edb://localhost/test?user=fred&password=secret&ssl=true”;

  1. Convert the server certificate to Java format:
$ openssl x509 -in server.crt -out server.crt.der -outform der
  1. Import this certificate into Java’s system truststore.
$ keytool -keystore $JAVA_HOME/lib/security/cacerts -alias postgresql
-import -file server.crt.der

Note

The default password for the cacerts keystore is changeit. The alias to postgresql is not important and you may select any name you desire.

  1. If you do not have access to the system cacerts truststore, create your own truststore as below:

    $ keytool -keystore mystore -alias postgresql -import -file server.crt.der
    
  2. Start your Java application and test the program.

    $ java -Djavax.net.ssl.trustStore=mystore com.mycompany.MyApp
    

For example:

$java -classpath .:/usr/edb/jdbc/edb-jdbc18.jar–
Djavax.net.ssl.trustStore=mystore pg_test2 public

Note

For troubleshooting connection issues, add -Djavax.net.debug=ssl to the java command.

Using SSL without Certificate Validation

By default the combination of SSL=true and setting the connection URL parameter sslfactory=com.edb.ssl.NonValidatingFactory encrypts the connection but does not validate the SSL certificate. To enforce certificate validation, you must use a Custom SSLSocketFactory.

For more details about writing a Custom SSLSocketFactory, refer to:

https://jdbc.postgresql.org/documentation/head/ssl-factory.html