# SSL encryption

Memgraph uses SSL (Secure Sockets Layer) protocol for establishing an
authenticated and encrypted connection to a database instance.

Achieving a secure connection is a three-step process that requires

1. Owning a SSL certificate
2. Configuring the server
3. Enabling SSL connection

For any errors that might come up, check out [the Help center page on
errors](https://memgraph.com/docs/help-center/errors/ssl).

## SSL certificate

SSL certificate is a pair of `.pem` documents issued by self-signing, or by a
Certification Authority. Memgraph contains a self-signed testing certificate
(`cert.pem` and `key.pem`) located at `/etc/memgraph/ssl/`.

If you are using Docker and want to use your own certificates, you need to [copy
them into a Docker
container](https://memgraph.com/docs/getting-started/first-steps-with-docker#copy-files-to-a-docker-container)
in order to utilize them.

## Configure the server

To use a certain SSL certificate, change the configuration file to include the
`--bolt-cert-file` and `--bolt-key-file` flags and set them to the location of
the certification files.

If you are using the Memgraph self-signed certificate, set the configuration
flags to:

```
--bolt-cert-file=/etc/memgraph/ssl/cert.pem
--bolt-key-file=/etc/memgraph/ssl/key.pem
```

When using Linux, be sure that the user `memgraph` has permissions (400) to
access the files.

Once the flags are included in the configuration, you cannot establish an
insecure connection.

## Enable SSL connection

**Memgraph Lab**

To enable SSL connection in Memgraph Lab, switch to **Connect Manually** view
and turn the SSL on.

![](https://memgraph.com/docs/pages/database-management/ssl-encryption/memgraph_lab_ssl.png)

When Memgraph Lab is connected to Memgraph database using SSL encryption, logs cannot
be viewed inside the Lab.

**mgconsole**

When starting mgconsol include the `--use-ssl=true` flag. Flag can also be
explicitly set to `false` if needed.

For example, if you are starting mgconsole on Linux:

```
mgconsole --host 127.0.0.1 --port 7687 --use-ssl=true
```

or if you are using `memgraph` or `memgraph-mage` Docker images:

```
docker run -p 7687:7687 -p 7444:7444 -v mg_lib:/var/lib/memgraph -v mg_etc:/etc/memgraph memgraph/memgraph-mage --use-ssl=true
```

**Drivers**

**Javascript**

Use [Neo4j driver for JavaScript](https://neo4j.com/developer/javascript/), and
add `+ssc` to the UNI when defining a `MEMGRAPH_URI` constant: 


<code>MEMGRAPH_URI = 'bolt+ssc://18.196.53.118:7687'</code>.<p></p>

**Python**

Use [pymgclient](https://github.com/memgraph/pymgclient), and add
`sslmode=mgclient.MG_SSLMODE_REQUIRE` to the `mgclient.connect`.

**C/C++**

Use [mgclient](https://github.com/memgraph/mgclient), and add set the
`params.use_ssl` to `true` or `false`.

**Go**

Use the [Neo4j driver for Go](https://neo4j.com/developer/go/), and add `+ssc`
to the UNI: `"bolt+ssc://18.196.53.118:7687"`.

**PHP**

Use the [Bolt protocol library by
stefanak-michal](https://github.com/neo4j-php/Bolt) and add the following code

```python
$conn->setSslContextOptions([
 'passphrase' => 'bolt',
 'allow_self_signed' => true,
 'verify_peer' => false,
 'verify_peer_name' => false
]);
```

**C#**

Use the [Neo4j.Driver.Simple](https://neo4j.com/developer/dotnet/), and add
`+ssc` to the UNI: `"bolt+ssc://18.196.53.118:7687"`.

**Java**

Use the [Neo4j driver for Java](https://neo4j.com/developer/java/) and add
`+ssc` to the UNI: `"bolt+ssc://18.196.53.118:7687"`.

**Rust**

Use [mgclient](https://github.com/memgraph/mgclient), and add `sslmode:
SSLMode::Require` to the `ConnectParams`.

**WebSocket**

WebSocket over SSL is currently not supported in Memgraph.

## Reload SSL certificates at runtime

You can rotate SSL certificates without restarting Memgraph by using the
`RELOAD BOLT_SERVER TLS` Cypher command. This is useful in production
environments where certificate rotation is required (e.g., Let's Encrypt
renewals or compliance requirements) and downtime is not acceptable.

To reload SSL certificates:

1. Replace the certificate and key files on disk (at the paths originally
   configured with `--bolt-cert-file` and `--bolt-key-file`).
2. Run the following command from any connected client:

```cypher
RELOAD BOLT_SERVER TLS;
```

After a successful reload:
- **New connections** will use the updated certificate.
- **Existing connections** continue using the previous certificate until they
  disconnect.

If the reload fails (e.g., due to an invalid certificate or missing file), the
existing SSL configuration remains active and an error is returned. The server
continues to operate normally.


> **Info**
>
> The `RELOAD BOLT_SERVER TLS` command cannot be executed inside an explicit
> (multi-command) transaction.



> **Warning**
>
> Running `RELOAD BOLT_SERVER TLS` on a Memgraph instance that was started
> without SSL enabled will return an error.



> **Warning**
>
> **Breaking change in Memgraph 3.11:** `RELOAD BOLT_SERVER TLS` now requires the
> `RELOAD_TLS`
> [privilege](https://memgraph.com/docs/database-management/authentication-and-authorization/role-based-access-control).
> Previously no privilege was needed. If you use authorization, grant `RELOAD_TLS`
> to the users or roles that perform certificate rotation:
> `GRANT RELOAD_TLS TO user;`.


### Reload intra-cluster TLS certificates

In a [high-availability](https://memgraph.com/docs/clustering/high-availability) cluster, the internal
communication between instances can be secured with
[intra-cluster TLS](https://memgraph.com/docs/clustering/high-availability/how-high-availability-works#intra-cluster-tls).
To rotate those certificates at runtime, replace the certificate and key files
on disk (at the paths configured with `--cluster-cert-file`,
`--cluster-key-file`, and `--cluster-ca-file`) and run:

```cypher
RELOAD INTRA_CLUSTER TLS;
```

`RELOAD INTRA_CLUSTER TLS` reloads both the client and server connections, so
new connections will start using the new certificates.

Like `RELOAD BOLT_SERVER TLS`, this command requires the `RELOAD_TLS` privilege
and cannot be executed inside an explicit (multi-command) transaction.

## How to set up SSL encryption

Memgraph uses SSL (Secure Sockets Layer) protocol for establishing an
authenticated and encrypted connection to a database instance.

## Docker


    
### Create a container

    Create a Docker container with the `--bolt-cert-file` and `--bolt-key-file` arguments pointing to `/etc/memgraph/ssl/cert.pem` and `/etc/memgraph/ssl/key.pem` respectively.
    ```
    docker create --name memgraph_container -p 7687:7687 -p 7444:7444 memgraph/memgraph-mage --bolt-cert-file=/etc/memgraph/ssl/cert.pem --bolt-key-file=/etc/memgraph/ssl/key.pem 
    ```

    
### Copy the SSL certificate files

    ```
    docker cp cert.pem memgraph_container:/etc/memgraph/ssl/cert.pem
    docker cp key.pem memgraph_container:/etc/memgraph/ssl/key.pem
    ```

    
### Start the container


    ```
    docker start memgraph_container
    ```


### Enable SSL connection

Choose the preferred way to connect to Memgraph and first [enable SSL connection](https://memgraph.com/docs/database-management/ssl-encryption#enable-ssl-connection).



## Linux

1. Run Memgraph.

2. Open the configuration file available at `/etc/memgraph/memgraph.conf`.

3. Change the configuration file to include the following configuration flags:

   ```
   --bolt-cert-file=<path>
   --bolt-key-file=<path>
   ```

4. Set the flags to the paths of your SSL certificate, or use Memgraph
   self-signed certificates (`cert.pem` and `key.pem`) located at
   `/etc/memgraph/ssl/`:

   ```
   --bolt-cert-file=/etc/memgraph/ssl/cert.pem
   --bolt-key-file=/etc/memgraph/ssl/key.pem
   ```

5. Restart Memgraph.

6. Open Memgraph Lab and switch to **Connect Manually** view, turn the **SSL
   On** and connect.

7. If you are using [pymgclient](https://github.com/memgraph/pymgclient) to
   query the database with Python, add `sslmode=mgclient.MG_SSLMODE_REQUIRE` to
   the `mgclient.connect`
