Review Alibaba Cloud RDS TLS connection settings

Configure RDS TLS support together with client certificate validation.

Description

Database connections without TLS can transmit credentials and query data in plaintext. Enabling SSL support in RDS and ensuring that every client uses encrypted connections require separate verification.

Potential impact

  • An attacker able to observe the traffic path may obtain data and credentials.
  • Insufficient server certificate validation can allow connections to the wrong server.

Remediation

Set ssl_action = "Open" on supported RDS engines and versions. Configure clients to require TLS and validate the server certificate against the correct CA and hostname. Apply engine-level TLS enforcement where required and verify encryption on actual connections.

Examples

These excerpts compare SSL support for RDS MySQL. Provide a supported version and instance specification, and configure networking and accounts separately.

Before

hcl
resource "alicloud_db_instance" "default" {
  engine              = "MySQL"
  engine_version      = var.mysql_version
  instance_type       = var.db_instance_type
  instance_storage    = var.db_instance_storage
  ssl_action          = "Close"
}

After

hcl
resource "alicloud_db_instance" "default" {
  engine              = "MySQL"
  engine_version      = var.mysql_version
  instance_type       = var.db_instance_type
  instance_storage    = var.db_instance_storage
  ssl_action          = "Open"
}

The after example enables SSL support. Do not assume that every existing connection automatically switches to TLS; verify client and engine connection requirements.

References