# Configure SSH and SSL

To make a connection to a database more secure, some services require SSH or SSL usage.

## SSL

The following procedure describes the SSL configuration that suits most databases. For some databases, you need to use another approach for a successful connection.  You can see configuration examples for [Cassandra](https://www.jetbrains.com.cn/en-us/help/datagrip/how-to-connect-to-cassandra-with-ssl.html) and [Heroku Postgres](https://www.jetbrains.com.cn/en-us/help/datagrip/how-to-connect-to-heroku-postgres.html) in the DataGrip documentation.

Procedure: Connect to a database with SSL

1. Open data source properties by doing one of the following:

* On the Database tool window toolbar, click ![The Data Sources icon](https://resources.jetbrains.com.cn/help/img/idea/2026.2/database-plugin.icons.expui.manageDataSources.svg) Data Sources.

* Press `Shift+Enter` (Windows), `⌘ I` (macOS), `⇧ ⏎` (IntelliJ IDEA Classic (macOS)), `⌘ I` (macOS System Shortcuts), `Shift+Enter` (XWin), `Shift+Enter` (GNOME), `Shift+Enter` (KDE), `Shift+Enter` (Emacs), `Shift+Enter` (Sublime Text), `⌘ I` (Sublime Text (macOS)), `Shift+Enter` (NetBeans), `Shift+Enter` (Visual Studio), `⌘ I` (Visual Studio (macOS)), `Shift+Enter` (Eclipse), `⌘ I` (Eclipse (macOS)) .

![Open the Data Source and Drivers dialog](https://resources.jetbrains.com.cn/help/img/idea/2026.2/open_data_sources_and_drivers_dialog.png)

2. On the  Data Sources  tab, select a data source that you want to modify.

3. Click the SSH/SSL tab and select the Use SSL checkbox.

4. In the CA file field, navigate to the CA certificate file (for example, `mssql.pem`).

5. You can leave the certificate file fields empty and use a truststore to obtain a required certificate from the certificates that it contains. To do that, tick the Use truststore checkbox and select the truststore that you want to use.

* IDE: Use the certificates that are accepted by the IDE. You can add new accepted certificates in `Settings | Appearance & Behavior | System Settings | Server Certificates`.

* JAVA: Use JAVA truststore certificates.

* System: Use System truststore certificates.

6. In the Client certificate file field, navigate to the client certificate file (for example, `client-cert.pem`).

7. In the Client key file field, navigate to the client key file (for example, `client-key.pem`).

8. From the Mode list, select the verification mode:

|  |  |
| --- | --- |
|  Require  | Verifies that the server recognizes the client certificate, if the certificate is provided. |
| Verify CA |      * Verifies that the server recognizes the client certificate, if the certificate is provided.    * Verifies the server by checking the certificate chain up to the root certificate that is stored on the client.    |
| Full Verification |      * Verifies that the server recognizes the client certificate, if the certificate is provided.    * Verifies the server by checking the certificate chain up to the root certificate that is stored on the client.    * Verifies the server host to ensure that it matches the name stored in the server certificate.    |

The SSL connection fails if either one of the certificates cannot be verified.

9. To ensure that the connection to the data source is successful, click Test Connection.

![Connect to a database with SSL](https://resources.jetbrains.com.cn/help/img/idea/2026.2/db_connect_with_ssl.png)

> **Note:**
> It is recommended to use PEM certificates.

> **Note:**
> With self-signed certificates and in some cases with certificates issued by the trusted root entity, you might experience errors when you use the latest JDBC driver version. The SSL connection might fail if your Java keystore does not accept the certificate chains. As a temporary solution, try to downgrade the JDBC driver (for example, for the MySQL connector, you need to switch to the 5.1.40 version.)

Procedure: Disable SSL connection to a database

1. Open data source properties by doing one of the following:

* On the Database tool window toolbar, click ![The Data Sources icon](https://resources.jetbrains.com.cn/help/img/idea/2026.2/database-plugin.icons.expui.manageDataSources.svg) Data Sources.

* Press `Shift+Enter` (Windows), `⌘ I` (macOS), `⇧ ⏎` (IntelliJ IDEA Classic (macOS)), `⌘ I` (macOS System Shortcuts), `Shift+Enter` (XWin), `Shift+Enter` (GNOME), `Shift+Enter` (KDE), `Shift+Enter` (Emacs), `Shift+Enter` (Sublime Text), `⌘ I` (Sublime Text (macOS)), `Shift+Enter` (NetBeans), `Shift+Enter` (Visual Studio), `⌘ I` (Visual Studio (macOS)), `Shift+Enter` (Eclipse), `⌘ I` (Eclipse (macOS)) .

![Open the Data Source and Drivers dialog](https://resources.jetbrains.com.cn/help/img/idea/2026.2/open_data_sources_and_drivers_dialog.png)

2. On the  Data Sources  tab, select a data source that you want to modify.

3. Click the SSH/SSL tab and clear the Use SSL checkbox.

4. Click Apply.

Procedure: Copy SSL settings from other data sources

If you configured SSL settings for one data source, you can copy them for another data source.

1. Open data source properties by doing one of the following:

* On the Database tool window toolbar, click ![The Data Sources icon](https://resources.jetbrains.com.cn/help/img/idea/2026.2/database-plugin.icons.expui.manageDataSources.svg) Data Sources.

* Press `Shift+Enter` (Windows), `⌘ I` (macOS), `⇧ ⏎` (IntelliJ IDEA Classic (macOS)), `⌘ I` (macOS System Shortcuts), `Shift+Enter` (XWin), `Shift+Enter` (GNOME), `Shift+Enter` (KDE), `Shift+Enter` (Emacs), `Shift+Enter` (Sublime Text), `⌘ I` (Sublime Text (macOS)), `Shift+Enter` (NetBeans), `Shift+Enter` (Visual Studio), `⌘ I` (Visual Studio (macOS)), `Shift+Enter` (Eclipse), `⌘ I` (Eclipse (macOS)) .

![Open the Data Source and Drivers dialog](https://resources.jetbrains.com.cn/help/img/idea/2026.2/open_data_sources_and_drivers_dialog.png)

2. On the  Data Sources  tab, select a data source that you want to modify.

3. Click the SSH/SSL tab and select the Use SSL checkbox.

4. Click the Copy from… link and select the configuration that you want to copy.

## SSH

Secure Shell or SSH is a network protocol that is used to encrypt a connection between a client and a server.

In IntelliJ IDEA, you can create an SSH connection one of the following ways:

* [Using the IntelliJ IDEA SSH tunnel.](#ssh_tunnel) The IDE will create an SSH tunnel using the SSH configuration that you set.

* [Creating an SSH tunnel manually using PuTTy, Pageant, or ssh-client.](#ssh_tunnel_manually)

### IntelliJ IDEA SSH tunnel

IntelliJ IDEA can create an SSH tunnel based on the SSH configuration that you set. To access the SSH configuration settings,  press `Ctrl+Alt+S` (Windows), `⌘ Comma` (macOS), `⌘ Comma` (IntelliJ IDEA Classic (macOS)), `⌘ Comma` (macOS System Shortcuts), `Ctrl+Alt+S` (XWin), `Ctrl+Alt+S` (GNOME), `Ctrl+Alt+S` (KDE), `Ctrl+Alt+S` (Emacs), `Ctrl+Alt+S` (Sublime Text), `⌘ Comma` (Sublime Text (macOS)), `Ctrl+Alt+S` (NetBeans), `Ctrl+Alt+S` (Visual Studio), `⌘ Comma` (Visual Studio (macOS)), `Ctrl+Alt+S` (Eclipse), `⌘ Comma` (Eclipse (macOS)) to open settings and select Tools | SSH Configuration .

To use an SSH tunnel for the data source, select the Use SSH tunnel checkbox in the SSH/SSL tab of   Data Sources and Drivers  dialog (  `Shift+Enter` (Windows), `⌘ I` (macOS), `⇧ ⏎` (IntelliJ IDEA Classic (macOS)), `⌘ I` (macOS System Shortcuts), `Shift+Enter` (XWin), `Shift+Enter` (GNOME), `Shift+Enter` (KDE), `Shift+Enter` (Emacs), `Shift+Enter` (Sublime Text), `⌘ I` (Sublime Text (macOS)), `Shift+Enter` (NetBeans), `Shift+Enter` (Visual Studio), `⌘ I` (Visual Studio (macOS)), `Shift+Enter` (Eclipse), `⌘ I` (Eclipse (macOS)) ) .

> **Note:**
> In most cases, you do not need to modify the General tab settings after setting the SSH configuration in SSH/SSL tab, as IntelliJ IDEA will connect to the local end of the SSH tunnel. The exception is when you create an SSH tunnel manually. In this case, as Host on the General tab, you need to set the IP address of your server in an isolated network.
>
>
>
> Upon the connection, the SSH tunnel hostname is resolved on the machine with SSH server, as the server establishes connection to a database.

All created SSH connections are shared between all the data sources that you have in a project. If you do not want to share a connection between projects, select the Visible only for this project checkbox in the SSH connection settings.

Procedure: Connect to a database with SSH

1. Open data source properties by doing one of the following:

* On the Database tool window toolbar, click ![The Data Sources icon](https://resources.jetbrains.com.cn/help/img/idea/2026.2/database-plugin.icons.expui.manageDataSources.svg) Data Sources.

* Press `Shift+Enter` (Windows), `⌘ I` (macOS), `⇧ ⏎` (IntelliJ IDEA Classic (macOS)), `⌘ I` (macOS System Shortcuts), `Shift+Enter` (XWin), `Shift+Enter` (GNOME), `Shift+Enter` (KDE), `Shift+Enter` (Emacs), `Shift+Enter` (Sublime Text), `⌘ I` (Sublime Text (macOS)), `Shift+Enter` (NetBeans), `Shift+Enter` (Visual Studio), `⌘ I` (Visual Studio (macOS)), `Shift+Enter` (Eclipse), `⌘ I` (Eclipse (macOS)) .

![Open the Data Source and Drivers dialog](https://resources.jetbrains.com.cn/help/img/idea/2026.2/open_data_sources_and_drivers_dialog.png)

2. Select a data source for which you want to set up an SSH connection.

3. Click the SSH/SSL tab and select the Use SSH tunnel checkbox.

4. Click ![the Add SSH configuration](https://resources.jetbrains.com.cn/help/img/idea/2026.2/app.general.ellipsis.svg) Add SSH configuration.

5. In the SSH Configurations dialog, click the Add button.

6. If you do not want to share the configuration between projects, select the Visible only for this project checkbox.

7. In the Host and Port fields, specify your connection details.

8. Enter your username in the Username field.

9. In this tutorial, we use encrypted private key file and public key file to authenticate. From the Authentication type list, you can select an authentication method:

* Password: Access the host with a password. To save the password in IntelliJ IDEA, select the Save password checkbox.

* Key pair (OpenSSH or PuTTY): Use [SSH authentication](https://www.ssh.com/) with a key pair. To apply this authentication method, you must have a private key on the client machine and a public key on the remote server. IntelliJ IDEA supports private keys that are generated with the [OpenSSH](https://www.openssh.com/) utility. Specify the path to the file where your private key is stored and type the passphrase (if any) in the corresponding fields. To have IntelliJ IDEA remember the passphrase, select the Save passphrase checkbox.

* OpenSSH config and authentication agent: Use a credentials helper application that manages your SSH keys, such as [ssh-agent](https://en.wikipedia.org/wiki/Ssh-agent) or [Pageant (Windows only)](https://the.earth.li/~sgtatham/putty/0.70/htmldoc/Chapter9.html#pageant). > **Tip:** > If you have both OpenSSH ssh-agent and Pageant running, only ssh-agent will be used, even if it does not contain any keys.

10. Click Test Connection to run a test connection.

11. In the SSH Configurations dialog, click OK to confirm the new SSH configuration settings.

12. In the Local port field of Data Sources and Drivers dialog, specify the local port number from which you want to forward the connection. Otherwise, IntelliJ IDEA selects the port dynamically.

13. Click the Test Connection link at the bottom of the connection details area to initiate a test connection to your database.

![Test Connection link](https://resources.jetbrains.com.cn/help/img/idea/2026.2/db_test_connection_link.png)

14. Click OK to create the data source.

![SSH settings of a data source](https://resources.jetbrains.com.cn/help/img/idea/2026.2/db_ssh_configurations.png)

> **Tip:**
> For more information about working with SSH keys, refer to the [Generating a new SSH key and adding it to the ssh-agent](https://help.github.com/articles/generating-a-new-ssh-key-and-adding-it-to-the-ssh-agent/) tutorial.

#### Examples

For examples of connecting to databases with SSH, refer to the [Connect to a database with SSH](connect-to-a-database-with-ssh.html) topic.

Procedure: Disable SSH connection to a database

1. Open data source properties by doing one of the following:

* On the Database tool window toolbar, click ![The Data Sources icon](https://resources.jetbrains.com.cn/help/img/idea/2026.2/database-plugin.icons.expui.manageDataSources.svg) Data Sources.

* Press `Shift+Enter` (Windows), `⌘ I` (macOS), `⇧ ⏎` (IntelliJ IDEA Classic (macOS)), `⌘ I` (macOS System Shortcuts), `Shift+Enter` (XWin), `Shift+Enter` (GNOME), `Shift+Enter` (KDE), `Shift+Enter` (Emacs), `Shift+Enter` (Sublime Text), `⌘ I` (Sublime Text (macOS)), `Shift+Enter` (NetBeans), `Shift+Enter` (Visual Studio), `⌘ I` (Visual Studio (macOS)), `Shift+Enter` (Eclipse), `⌘ I` (Eclipse (macOS)) .

![Open the Data Source and Drivers dialog](https://resources.jetbrains.com.cn/help/img/idea/2026.2/open_data_sources_and_drivers_dialog.png)

2. Select a data source profile where you want to change connection settings.

3. Click the SSH/SSL tab and clear the Use SSH tunnel checkbox.

4. Click Apply.

### Create SSH tunnel manually

Procedure: Create the SSH tunnel with PuTTY (Windows)

1. Download and run the latest version of the PuTTY SSH and Telnet client (download the client from [https://www.putty.org/](https://www.putty.org/)).

2. In the PuTTY Configuration dialog, navigate to `Connection | SSH | Auth`.

3. In the Private key file for authentication field, specify the path to your private key file and click Open.

4. In the command line window, specify the username that you use for the SSH tunnel and press `Enter` (Windows), `⏎` (macOS), `⏎` (IntelliJ IDEA Classic (macOS)), `⏎` (macOS System Shortcuts), `Enter` (XWin), `Enter` (GNOME), `Enter` (KDE), `Enter` (Emacs), `Enter` (Sublime Text), `⏎` (Sublime Text (macOS)), `Enter` (NetBeans), `Enter` (Visual Studio), `⏎` (Visual Studio (macOS)), `Enter` (Eclipse), `⏎` (Eclipse (macOS)). Do not close the command line window.

5. In the   Database   tool window ,  click the Data Source Properties icon ![the Data Source Properties icon](https://resources.jetbrains.com.cn/help/img/idea/2026.2/database-plugin.icons.expui.manageDataSources.svg) on the toolbar.

6. Select a data source profile where you want to change connection settings.

7. Click the SSH/SSL tab and select the Use SSH tunnel checkbox.

8. From the Auth type list, select OpenSSH config and authentication agent.

9. In Proxy host, Proxy user, and Port fields, specify connection details.

10. To ensure that the connection to the data source is successful, click Test Connection.

![Create the SSH tunnel with PuTTY (Windows)](https://resources.jetbrains.com.cn/help/img/idea/2026.2/db_putty_key_config.png)

Procedure: Create the SSH tunnel with Pageant (Windows)

Pageant is an SSH authentication agent for PuTTY, PSCP, PSFTP, and Plink. Pageant stores your private key, and as long as it is running, it provides the unlocked private key to PuTTY or other tools like IntelliJ IDEA. You can find the Pageant icon in the Windows taskbar.

1. Download the latest version of Pageant (download the client from [https://www.putty.org/](https://www.putty.org/)).

2. In the Windows taskbar, right-click the Pageant icon and select Add Key.

3. In the Select Private Key File dialog, navigate to the private key file (the PPK file) and click Open.

4. (Optional) Enter the private key passphrase and press `Enter` (Windows), `⏎` (macOS), `⏎` (IntelliJ IDEA Classic (macOS)), `⏎` (macOS System Shortcuts), `Enter` (XWin), `Enter` (GNOME), `Enter` (KDE), `Enter` (Emacs), `Enter` (Sublime Text), `⏎` (Sublime Text (macOS)), `Enter` (NetBeans), `Enter` (Visual Studio), `⏎` (Visual Studio (macOS)), `Enter` (Eclipse), `⏎` (Eclipse (macOS)).

5. In the   Database   tool window ,  click the Data Source Properties icon ![the Data Source Properties icon](https://resources.jetbrains.com.cn/help/img/idea/2026.2/database-plugin.icons.expui.manageDataSources.svg) on the toolbar.

6. Select a data source profile where you want to change connection settings.

7. Click the SSH/SSL tab and select the Use SSH tunnel checkbox.

8. From the Auth type list, select OpenSSH config and authentication agent.

9. In Proxy host, Proxy user, and Port fields, specify connection details.

10. To ensure that the connection to the data source is successful, click Test Connection.

![Create the SSH tunnel with Pageant (Windows)](https://resources.jetbrains.com.cn/help/img/idea/2026.2/db_task_area_pageant.png)

Procedure: Create the SSH tunnel with the ssh-agent (macOS and Linux)

Run all commands for ssh-agent in the command line.

1. Ensure that ssh-agent is running.

```
ssh-agent
```

2. Add your key to the agent (in the following example, the key path is `~/.ssh/id_rsa`).

```
ssh-add ~/.ssh/id_rsa
```

3. (Optional) On macOS, you can add `-K` option to the `ssh-add` command to store passphrases in your keychain. On macOS Sierra and later, you need to create the `config` file in `~/.ssh/` with the following text:

```
Host *
UseKeychain yes
AddKeysToAgent yes
IdentityFile ~/.ssh/id_rsa
```

If you have other private keys in the `.ssh` directory, add an `IdentityFile` line for each key. For example, if the second key has the `id_ed25519` name, add `IdentityFile ~/.ssh/id_ed25519` as an additional line for the second private key.

4. List all added keys.

```
ssh-add -L
```

5. In the   Database   tool window ,  click the Data Source Properties icon ![the Data Source Properties icon](https://resources.jetbrains.com.cn/help/img/idea/2026.2/database-plugin.icons.expui.manageDataSources.svg) on the toolbar.

6. Select a data source profile where you want to change connection settings.

7. Click the SSH/SSL tab and select the Use SSH tunnel checkbox.

8. From the Auth type list, select OpenSSH config and authentication agent.

9. In Proxy host, Proxy user, and Port fields, specify connection details.

10. To ensure that the connection to the data source is successful, click Test Connection.

![Create the SSH tunnel with the ssh-agent (macOS and Linux)](https://resources.jetbrains.com.cn/help/img/idea/2026.2/db_ssh_agent_linux_macos.png)

## See also

