TLS modes
- PostgreSQL
- MySQL
- MariaDB
- MongoDB
- Redis / Valkey
- Elasticsearch
- CLI
Every connection has a TLS mode, set on the TLS tab of the connection dialog. A new connection starts with TLS off, since most servers you add first (on your computer, in a container or in a private network) have none. A URI that asks for TLS, an SRV record or an Elastic Cloud ID turns it on. For a server across a network, choose the strictest mode the server passes.
Choose the mode under TLS mode. The hint under it says what the mode checks.
| TLS mode | Mode | What Querybara checks |
|---|---|---|
| Disable TLS | disable |
No TLS. The password and all data travel unencrypted. |
| Require TLS, no verification | require |
Encrypts; accepts any server certificate. |
| Verify certificate only | verify-ca |
Encrypts; verifies the certificate chain, not the host name. |
| Verify certificate and host name | verify-full |
Encrypts; verifies the certificate chain and that it names the host. |
disable is the default for new connections, for URIs that say nothing about TLS, and in the
command line. The TLS tab shows a green dot while TLS is on.
What turns TLS on
Section titled “What turns TLS on”- A pasted URI that states TLS:
sslmode,ssl-mode,sslortlsparameters, arediss://Redis URI, anhttps://Elasticsearch URL, or amongodb+srv://URI. See TLS from a pasted URI. - Choosing SRV record (mongodb+srv) or Cloud ID (Elastic Cloud) under Connect with: the dialog sets Verify certificate and host name. You can turn it off again.
Certificates
Section titled “Certificates”While TLS is on, the TLS tab shows three file fields. Type a path or choose Browse…:
| Field | Use it for |
|---|---|
| CA certificate | A certificate authority the server’s certificate chains to, such as a private CA. |
| Client certificate | Your certificate, for servers that ask for one. Required for MongoDB X.509 sign-in. |
| Client key | The private key of the client certificate. |
The file picker suggests .pem, .crt, .cer, .key and .der files. For MongoDB X.509, one
PEM file holding both the certificate and the key can be chosen for each field.
Warnings for weak TLS
Section titled “Warnings for weak TLS”A connection that crosses a network with TLS off, or with a mode other than Verify certificate and host name, gets a warning. On the TLS tab it reads “TLS is disabled: the password and all data travel unencrypted.” for Disable TLS, and “The server certificate is not fully verified, so the connection can be intercepted.” for the other two. The warning stays with the connection:
- the side bar shows a warning sign next to the connection;
- each query tab on it shows a banner.
A local server has nothing to intercept, so it gets no warning; the TLS tab shows a note instead. Querybara counts as local:
- a Unix socket;
localhost,127.0.0.1and the other127.x.x.xaddresses,::1, and names ending in.localhost, when every host of the endpoint is one of them;- such an address at the far end of an SSH tunnel, whose own leg is encrypted.
A proxy without an SSH tunnel carries the traffic over the network, so it still gets the warning.
When the endpoint decides
Section titled “When the endpoint decides”Some endpoints carry their own TLS setting, and the dialog checks that the mode agrees:
- MongoDB SRV record: an SRV record implies TLS, as in MongoDB drivers. Choose Disable TLS only for a server that has none.
- Redis URI:
rediss://connects with TLS in the mode you choose;redis://needs Disable TLS. - Elasticsearch node URLs:
https://connects with TLS in the mode chosen here;http://needs Disable TLS. An Elastic Cloud ID always connects over TLS. - MongoDB X.509 sign-in needs TLS on.
If the mode does not agree, Save and Test Connection open the TLS tab and say why, for example “X.509 authentication needs TLS”.
TLS from a pasted URI
Section titled “TLS from a pasted URI”Fill from URI reads the TLS setting a URI states and sets the matching mode:
| The URI has | Mode Querybara uses |
|---|---|
sslmode or ssl-mode (disable, require, verify-ca, verify-full, and MySQL’s spellings) |
the same mode |
sslmode=prefer |
require |
sslmode=allow |
disable |
rediss://, https:// or mongodb+srv:// |
verify-full |
MongoDB tls=true |
verify-full |
MongoDB tlsAllowInvalidHostnames=true |
verify-ca |
MongoDB tlsAllowInvalidCertificates=true or tlsInsecure=true |
require |
| nothing about TLS | disable |
prefer and allow have no exact match: Querybara uses the nearest mode that does not silently
change whether the connection is encrypted.
From the command line
Section titled “From the command line”TLS is off unless the URI says otherwise (?sslmode=…, rediss://, https://,
mongodb+srv://) or --tls is given. --tls sets the mode for one run, over what the profile
or URI says:
querybara test shop-dev --tls verify-caRelated
Section titled “Related”- Test Connection: the TLS handshake step
- Connection profiles
- Replica sets, Sentinel and Cluster: certificates per node
Documents Querybara 0.1.1 · built frombc9f5aa