Description
An expired or unsupported CA for an RDS server certificate can break TLS connections that validate certificates. rds-ca-2019 expired in 2024; use a G1 CA supported by the engine and region. Omitting ca_certificate_identifier alone does not establish that an outdated CA is in use.
Potential impact
Database connections can fail if clients do not trust the new CA or the server certificate has expired.
Remediation
Check the current CA and engine support. Update client trust stores before rotating the CA, test connections with certificate validation enabled, and plan any required restart.
Examples
The examples change the CA setting on an existing instance. rds-ca-2015 is a historical setting; confirm engine and region support for the replacement value too.
Before
- name: Update the DB instance CA
amazon.aws.rds_instance:
db_instance_identifier: ansible-test-aurora-db-instance
ca_certificate_identifier: rds-ca-2015
After
- name: Update the DB instance CA
amazon.aws.rds_instance:
db_instance_identifier: ansible-test-aurora-db-instance
ca_certificate_identifier: rds-ca-rsa2048-g1