RDS uses an expired or unsupported CA certificate

Update RDS instances and clients to use a supported certificate authority.

Description

An expired or unsupported CA for an RDS server certificate can break TLS connections that validate certificates. rds-ca-2019 expired in 2024; use a G1 CA supported by the engine and region. Omitting ca_certificate_identifier alone does not establish that an outdated CA is in use.

Potential impact

Database connections can fail if clients do not trust the new CA or the server certificate has expired.

Remediation

Check the current CA and engine support. Update client trust stores before rotating the CA, test connections with certificate validation enabled, and plan any required restart.

Examples

The examples change the CA setting on an existing instance. rds-ca-2015 is a historical setting; confirm engine and region support for the replacement value too.

Before

yaml
- name: Update the DB instance CA
  amazon.aws.rds_instance:
    db_instance_identifier: ansible-test-aurora-db-instance
    ca_certificate_identifier: rds-ca-2015

After

yaml
- name: Update the DB instance CA
  amazon.aws.rds_instance:
    db_instance_identifier: ansible-test-aurora-db-instance
    ca_certificate_identifier: rds-ca-rsa2048-g1

References