PostgreSQL has native support for using SSL connections to encrypt client/server communications for increased security. See Section 16.7, “Secure TCP/IP Connections with SSL” for details about the server-side SSL functionality.
If the server demands a client certificate, libpq will send the certificate stored in file .postgresql/postgresql.crt within the user's home directory. A matching private key file .postgresql/postgresql.key must also be present, and must not be world-readable.
If the file .postgresql/root.crt is present in the user's home directory, libpq will use the certificate list stored therein to verify the server's certificate. The SSL connection will fail if the server does not present a certificate; therefore, to use this feature the server must also have a root.crt file.