Skip to main content

SSL/TLS

TablePro supports five SSL modes that map to each driver’s native TLS capabilities. New connections start with the mode that matches the driver’s documented default.

Modes

SSL mode and certificate settings in the connection form

SSL tab in the connection form

Per-driver defaults

New connections pick the mode that matches each driver’s native behavior. Open the SSL tab on any connection to see the driver-specific guidance. Managed services (AWS RDS and Aurora, Google Cloud SQL, Azure, Heroku, Supabase, Neon, PlanetScale, MongoDB Atlas, Redis Cloud, Upstash, ElastiCache, DataStax Astra, Oracle Autonomous Database, ClickHouse Cloud) require TLS out of the box. Pick Required, or Preferred where the driver falls back.

Preferred fallback behavior

Preferred mode tries TLS first. What happens if the server doesn’t support TLS depends on the driver:
  • PostgreSQL, Redshift, CockroachDB: libpq falls back to plain TCP natively
  • SQL Server: FreeTDS encryption=request falls back to plain
  • MySQL, MariaDB: 2-pass connect tries TLS, then plain on SSL-specific handshake errors (CR_SSL_CONNECTION_ERROR, CR_SERVER_HANDSHAKE_ERR, ER_HANDSHAKE_ERROR). Auth and network errors are not retried.
  • MongoDB, Redis, Cassandra, ClickHouse, etcd, Elasticsearch, SurrealDB: no fallback. Preferred forces TLS, same as Required. The SSL pane shows a warning when you pick Preferred.
  • Oracle: no opportunistic TLS. Preferred connects in plain TCP, so it behaves like Disabled. The SSL pane shows a red warning; use Required to enforce TCPS.

Troubleshooting

”FATAL: no pg_hba.conf entry for host … no encryption”

PostgreSQL server requires SSL. Switch SSL Mode to Preferred or Required.

”Connections using insecure transport are prohibited”

MySQL server has require_secure_transport=ON. Switch SSL Mode to Preferred or Required.

”SSL handshake failed” / “tls handshake failed”

Driver and server can’t agree on a TLS version or cipher. Update the server, or for development try Required instead of Verify CA/Verify Identity to skip certificate validation.

”certificate verify failed” / “self-signed certificate”

Server uses a certificate that isn’t in your system trust store. Set SSL Mode to Verify CA and provide the CA certificate path, or use Required to skip certificate validation entirely.

”hostname does not match certificate”

The certificate’s CN/SAN doesn’t include the host you’re connecting to. Switch from Verify Identity to Verify CA (validates the chain but skips hostname), or update the host field to match the certificate.

”client certificate required”

Server requires mutual TLS. Fill in the Client Certificate and Client Key paths in the SSL tab.

”client private key is encrypted” / “passphrase is incorrect”

The client key is password-protected. Enter the Key Passphrase in the SSL tab. The field appears once a client key path is set, and the passphrase is stored in the Keychain. Currently supported by the Cassandra driver.

Connection failures

When a connection fails because of an SSL handshake problem, TablePro shows a structured message that names the cause and recommends a specific SSL Mode to switch to. The original driver error is shown below the suggestion. For example, connecting to AWS RDS PostgreSQL with SSL Mode = Disabled produces: