Skip to content

TLS modes

  • PostgreSQL
  • MySQL
  • MariaDB
  • MongoDB
  • Redis / Valkey
  • Elasticsearch
  • CLI

Every connection has a TLS mode, set on the TLS tab of the connection dialog. A new connection starts with TLS off, since most servers you add first (on your computer, in a container or in a private network) have none. A URI that asks for TLS, an SRV record or an Elastic Cloud ID turns it on. For a server across a network, choose the strictest mode the server passes.

Choose the mode under TLS mode. The hint under it says what the mode checks.

TLS mode Mode What Querybara checks
Disable TLS disable No TLS. The password and all data travel unencrypted.
Require TLS, no verification require Encrypts; accepts any server certificate.
Verify certificate only verify-ca Encrypts; verifies the certificate chain, not the host name.
Verify certificate and host name verify-full Encrypts; verifies the certificate chain and that it names the host.

disable is the default for new connections, for URIs that say nothing about TLS, and in the command line. The TLS tab shows a green dot while TLS is on.

  • A pasted URI that states TLS: sslmode, ssl-mode, ssl or tls parameters, a rediss:// Redis URI, an https:// Elasticsearch URL, or a mongodb+srv:// URI. See TLS from a pasted URI.
  • Choosing SRV record (mongodb+srv) or Cloud ID (Elastic Cloud) under Connect with: the dialog sets Verify certificate and host name. You can turn it off again.

While TLS is on, the TLS tab shows three file fields. Type a path or choose Browse…:

Field Use it for
CA certificate A certificate authority the server’s certificate chains to, such as a private CA.
Client certificate Your certificate, for servers that ask for one. Required for MongoDB X.509 sign-in.
Client key The private key of the client certificate.

The file picker suggests .pem, .crt, .cer, .key and .der files. For MongoDB X.509, one PEM file holding both the certificate and the key can be chosen for each field.

A connection that crosses a network with TLS off, or with a mode other than Verify certificate and host name, gets a warning. On the TLS tab it reads “TLS is disabled: the password and all data travel unencrypted.” for Disable TLS, and “The server certificate is not fully verified, so the connection can be intercepted.” for the other two. The warning stays with the connection:

  • the side bar shows a warning sign next to the connection;
  • each query tab on it shows a banner.

A local server has nothing to intercept, so it gets no warning; the TLS tab shows a note instead. Querybara counts as local:

  • a Unix socket;
  • localhost, 127.0.0.1 and the other 127.x.x.x addresses, ::1, and names ending in .localhost, when every host of the endpoint is one of them;
  • such an address at the far end of an SSH tunnel, whose own leg is encrypted.

A proxy without an SSH tunnel carries the traffic over the network, so it still gets the warning.

Some endpoints carry their own TLS setting, and the dialog checks that the mode agrees:

  • MongoDB SRV record: an SRV record implies TLS, as in MongoDB drivers. Choose Disable TLS only for a server that has none.
  • Redis URI: rediss:// connects with TLS in the mode you choose; redis:// needs Disable TLS.
  • Elasticsearch node URLs: https:// connects with TLS in the mode chosen here; http:// needs Disable TLS. An Elastic Cloud ID always connects over TLS.
  • MongoDB X.509 sign-in needs TLS on.

If the mode does not agree, Save and Test Connection open the TLS tab and say why, for example “X.509 authentication needs TLS”.

Fill from URI reads the TLS setting a URI states and sets the matching mode:

The URI has Mode Querybara uses
sslmode or ssl-mode (disable, require, verify-ca, verify-full, and MySQL’s spellings) the same mode
sslmode=prefer require
sslmode=allow disable
rediss://, https:// or mongodb+srv:// verify-full
MongoDB tls=true verify-full
MongoDB tlsAllowInvalidHostnames=true verify-ca
MongoDB tlsAllowInvalidCertificates=true or tlsInsecure=true require
nothing about TLS disable

prefer and allow have no exact match: Querybara uses the nearest mode that does not silently change whether the connection is encrypted.

TLS is off unless the URI says otherwise (?sslmode=…, rediss://, https://, mongodb+srv://) or --tls is given. --tls sets the mode for one run, over what the profile or URI says:

Terminal window
querybara test shop-dev --tls verify-ca
querybara query "postgres://[email protected]/shop?sslmode=verify-full" -e "select 1"

Documents Querybara 0.1.1 · built frombc9f5aa