Skip to content

SSL/TLS and SSH tunnel ​

Two different problems, two different tabs in the connection dialog. SSL/TLS encrypts the database connection itself. An SSH tunnel carries an unencrypted connection through a server you already trust.

You can use both at once.

SSL/TLS ​

Cloud databases — AWS RDS, Supabase, PlanetScale, Azure SQL — generally require it.

Tick Enable SSL/TLS, then pick a mode:

ModeWhat it does
DisableNo encryption. Not recommended
PreferUse SSL if the server supports it, plain otherwise
RequireAlways use SSL, but do not verify the certificate
Verify CASSL, and verify the certificate against the CA
Full verificationSSL, verify the CA and the hostname

For SQL Server the same setting is labelled Encryption level.

Certificates ​

Three optional file paths let you supply your own material:

  • CA certificate — needed for Verify CA and Full verification when the server uses a private CA.
  • Client certificate and Private key — for servers that require mutual TLS.

Accept self-signed certificates skips certificate validation entirely. It gets a development box working in seconds, and it removes the protection TLS was there to give — do not leave it on for a production connection.

SSH tunnel ​

With a tunnel, NabuSQL connects to the SSH server first and routes the database connection through it. This is how you reach a database that only listens on localhost on a remote machine.

Host and port are resolved on the SSH server

The host and port on the Basic tab are interpreted from the SSH server's point of view. For a database running on the same machine as the SSH server, that means localhost and the normal database port — not the server's public address.

Tick Enable SSH tunnel and fill in:

  • Host, Port and Username of the SSH server.
  • Authentication: Password, or Key.
  • For key authentication: the path to the private key file, plus a passphrase if the key is encrypted.

A worked example ​

A PostgreSQL server on db.example.com accepts SSH but the database itself listens only on 127.0.0.1:5432:

TabFieldValue
BasicHost127.0.0.1
BasicPort5432
SSH TunnelHostdb.example.com
SSH TunnelPort22
SSH TunnelUsernameyour SSH user

Troubleshooting ​

Connection refused through a tunnel — the database host is being resolved on the SSH server. Check that the value works when you run psql -h <host> while logged into that server.

Certificate verify failed — the server presents a certificate signed by a CA your system does not know. Supply the CA certificate rather than switching to Require.

SSH key rejected — check that the private key file is the one matching the public key in authorized_keys, and that a passphrase is entered if the key has one.