Credential storage

The OS credential store, launch profiles, and TLS trust per database engine.

Secrets follow one rule: they live in the operating system’s credential store, or they live in memory for the session. They do not live in JSON, command arguments, environment variables, or logs.

Connection passwords

Saving a connection profile writes the password to the platform store: Keychain on macOS, Credential Manager on Windows. The profile itself records everything except the secret. Test Connection does not write the keyring.

If the OS store is missing, connection passwords fall back to an in-memory store for the session, with a line in the startup log rather than a dialog. Trust-store passwords never take that fallback. Lock credentials in the command palette (Ctrl/Cmd+K) clears the unlocked session cache; it does not delete the OS secret.

SAFEDB_KEYCHAIN_BACKEND=disabled is a development switch that forces the in-memory store for connection passwords. It is not a place to put a password, and trust-store lookup still uses the platform backend.

TLS trust, per engine

  • PostgreSQL: verified TLS keeps pgjdbc’s normal trust and client-certificate behavior.
  • MySQL and SQL Server: normal JVM trust by default.
  • Oracle: verified TCPS uses an Oracle wallet. A generic PKCS12 file is not a substitute for a wallet.

Managed trust stores

Managed installations can load a PKCS12 trust store at startup with a launch profile, without putting its path or password in a saved connection:

safe-db --launch-profile /absolute/path/to/production.json

The profile is read before JDBC, the credential session, or the data directory initializes; an invalid profile fails startup rather than weakening trust. The profile records only a password source (a platform credential reference or a protected password file), never the password itself. For verified PostgreSQL, MySQL, and SQL Server connections, launch profiles are the only custom trust-store path. The product repository covers the PKCS12 templates and helper scripts.

Import only independently verified CA certificates, never private keys, and restart after changing the profile, store, or password.

safe-db is proudly opensource. Apache License 2.0.

GitHub