SSL / TLS

Configure SSL modes for MySQL, MariaDB, and PostgreSQL connections.

Last updated

Cocobox supports SSL/TLS for all three database dialects. The mode you pick controls how strictly the server’s certificate is validated.

Modes

ModeWhat it does
disableNo TLS. Allowed only for local-network connections (e.g. through SSH). Strongly discouraged on the public internet.
requireTLS required, but the server certificate is not validated. Protects against passive sniffing only.
verify-caValidate that the server certificate is signed by a CA you trust. Doesn’t check the hostname.
verify-fullFull validation: CA chain + hostname + expiry. Recommended.

CA bundles

For verify-ca and verify-full, paste your CA certificate (PEM) into the Server CA field. Cocobox stores it encrypted alongside the connection credentials.

For managed databases, the CA is usually published by your provider:

  • AWS RDS / Aurora — download the global bundle.
  • Google Cloud SQL — Settings → Connections → SSL/TLS → server CA certificate.
  • Azure Database for MySQL/PostgreSQL — DigiCert Global Root CA.
  • Supabase / Neon / PlanetScale — listed in their connection-string docs.

Client certificates (mTLS)

If your database requires the client to present its own certificate:

  1. Toggle Client certificate.
  2. Paste the client cert (PEM) and the corresponding private key.
  3. (Optional) Provide a passphrase.

mTLS is supported for both MySQL/MariaDB and PostgreSQL.

Common errors

  • unable to verify the first certificate — CA bundle is missing or wrong. Use the bundle from your provider.
  • Hostname/IP does not match certificate's altnames — the hostname in the connection doesn’t match the cert. Either fix the host (often the case with IP-based connections) or downgrade to verify-ca if you accept the trade-off.
  • SSL connection error: protocol version mismatch — your DB server enforces TLS 1.2 or 1.3 minimum. Cocobox negotiates 1.2+ by default; if your server is older, upgrade.