SSL / TLS
Configure SSL modes for MySQL, MariaDB, and PostgreSQL connections.
Cocobox supports SSL/TLS for all three database dialects. The mode you pick controls how strictly the server’s certificate is validated.
Modes
| Mode | What it does |
|---|---|
disable | No TLS. Allowed only for local-network connections (e.g. through SSH). Strongly discouraged on the public internet. |
require | TLS required, but the server certificate is not validated. Protects against passive sniffing only. |
verify-ca | Validate that the server certificate is signed by a CA you trust. Doesn’t check the hostname. |
verify-full | Full validation: CA chain + hostname + expiry. Recommended. |
CA bundles
For verify-ca and verify-full, paste your CA certificate (PEM) into the Server CA field. Cocobox stores it encrypted alongside the connection credentials.
For managed databases, the CA is usually published by your provider:
- AWS RDS / Aurora — download the global bundle.
- Google Cloud SQL — Settings → Connections → SSL/TLS → server CA certificate.
- Azure Database for MySQL/PostgreSQL — DigiCert Global Root CA.
- Supabase / Neon / PlanetScale — listed in their connection-string docs.
Client certificates (mTLS)
If your database requires the client to present its own certificate:
- Toggle Client certificate.
- Paste the client cert (PEM) and the corresponding private key.
- (Optional) Provide a passphrase.
mTLS is supported for both MySQL/MariaDB and PostgreSQL.
Common errors
unable to verify the first certificate— CA bundle is missing or wrong. Use the bundle from your provider.Hostname/IP does not match certificate's altnames— the hostname in the connection doesn’t match the cert. Either fix the host (often the case with IP-based connections) or downgrade toverify-caif you accept the trade-off.SSL connection error: protocol version mismatch— your DB server enforces TLS 1.2 or 1.3 minimum. Cocobox negotiates 1.2+ by default; if your server is older, upgrade.