Description
Database connections without TLS can transmit credentials and query data in plaintext. Enabling SSL support in RDS and ensuring that every client uses encrypted connections require separate verification.
Potential impact
- An attacker able to observe the traffic path may obtain data and credentials.
- Insufficient server certificate validation can allow connections to the wrong server.
Remediation
Set ssl_action = "Open" on supported RDS engines and versions. Configure clients to require TLS and validate the server certificate against the correct CA and hostname. Apply engine-level TLS enforcement where required and verify encryption on actual connections.
Examples
These excerpts compare SSL support for RDS MySQL. Provide a supported version and instance specification, and configure networking and accounts separately.
Before
resource "alicloud_db_instance" "default" {
engine = "MySQL"
engine_version = var.mysql_version
instance_type = var.db_instance_type
instance_storage = var.db_instance_storage
ssl_action = "Close"
}
After
resource "alicloud_db_instance" "default" {
engine = "MySQL"
engine_version = var.mysql_version
instance_type = var.db_instance_type
instance_storage = var.db_instance_storage
ssl_action = "Open"
}
The after example enables SSL support. Do not assume that every existing connection automatically switches to TLS; verify client and engine connection requirements.