SSL/TLS and SSH tunnel
Two different problems, two different tabs in the connection dialog. SSL/TLS encrypts the database connection itself. An SSH tunnel carries an unencrypted connection through a server you already trust.
You can use both at once.
SSL/TLS
Cloud databases — AWS RDS, Supabase, PlanetScale, Azure SQL — generally require it.
Tick Enable SSL/TLS, then pick a mode:
| Mode | What it does |
|---|---|
| Disable | No encryption. Not recommended |
| Prefer | Use SSL if the server supports it, plain otherwise |
| Require | Always use SSL, but do not verify the certificate |
| Verify CA | SSL, and verify the certificate against the CA |
| Full verification | SSL, verify the CA and the hostname |
For SQL Server the same setting is labelled Encryption level.
Certificates
Three optional file paths let you supply your own material:
- CA certificate — needed for Verify CA and Full verification when the server uses a private CA.
- Client certificate and Private key — for servers that require mutual TLS.
Accept self-signed certificates skips certificate validation entirely. It gets a development box working in seconds, and it removes the protection TLS was there to give — do not leave it on for a production connection.
SSH tunnel
With a tunnel, NabuSQL connects to the SSH server first and routes the database connection through it. This is how you reach a database that only listens on localhost on a remote machine.
Host and port are resolved on the SSH server
The host and port on the Basic tab are interpreted from the SSH server's point of view. For a database running on the same machine as the SSH server, that means localhost and the normal database port — not the server's public address.
Tick Enable SSH tunnel and fill in:
- Host, Port and Username of the SSH server.
- Authentication: Password, or Key.
- For key authentication: the path to the private key file, plus a passphrase if the key is encrypted.
A worked example
A PostgreSQL server on db.example.com accepts SSH but the database itself listens only on 127.0.0.1:5432:
| Tab | Field | Value |
|---|---|---|
| Basic | Host | 127.0.0.1 |
| Basic | Port | 5432 |
| SSH Tunnel | Host | db.example.com |
| SSH Tunnel | Port | 22 |
| SSH Tunnel | Username | your SSH user |
Troubleshooting
Connection refused through a tunnel — the database host is being resolved on the SSH server. Check that the value works when you run psql -h <host> while logged into that server.
Certificate verify failed — the server presents a certificate signed by a CA your system does not know. Supply the CA certificate rather than switching to Require.
SSH key rejected — check that the private key file is the one matching the public key in authorized_keys, and that a passphrase is entered if the key has one.
