Description
RDS clients use CA certificates to verify the database server. rds-ca-2019 expired in August 2024; replace it with a CA supported by the engine, such as rds-ca-rsa2048-g1, rds-ca-rsa4096-g1, or rds-ca-ecc384-g1.
Potential impact
Clients that verify certificates may lose connectivity when an expired CA remains in use.
Remediation
Update client trust stores first, then change ca_cert_identifier to a supported CA. Check whether a restart is required and test connections after rotation.
Examples
The examples replace the CA identifier. Set the engine-version and instance-class variables to a combination supported in the target Region.
Before
hcl
resource "aws_db_instance" "example" {
allocated_storage = 20
storage_type = "gp2"
engine = "mysql"
engine_version = var.mysql_engine_version
instance_class = var.db_instance_class
db_name = "mydb"
username = "foo"
password = "foobarbaz"
iam_database_authentication_enabled = true
storage_encrypted = true
ca_cert_identifier = "rds-ca-2015"
}
After
hcl
resource "aws_db_instance" "example" {
allocated_storage = 20
storage_type = "gp2"
engine = "mysql"
engine_version = var.mysql_engine_version
instance_class = var.db_instance_class
db_name = "mydb"
username = "foo"
password = "foobarbaz"
iam_database_authentication_enabled = true
storage_encrypted = true
ca_cert_identifier = "rds-ca-rsa2048-g1"
}