RDS instance uses an outdated CA certificate

Replace the CA certificate with a valid one supported by RDS.

Description

RDS clients use CA certificates to verify the database server. rds-ca-2019 expired in August 2024; replace it with a CA supported by the engine, such as rds-ca-rsa2048-g1, rds-ca-rsa4096-g1, or rds-ca-ecc384-g1.

Potential impact

Clients that verify certificates may lose connectivity when an expired CA remains in use.

Remediation

Update client trust stores first, then change ca_cert_identifier to a supported CA. Check whether a restart is required and test connections after rotation.

Examples

The examples replace the CA identifier. Set the engine-version and instance-class variables to a combination supported in the target Region.

Before

hcl
resource "aws_db_instance" "example" {
  allocated_storage                   = 20
  storage_type                        = "gp2"
  engine                              = "mysql"
  engine_version                      = var.mysql_engine_version
  instance_class                      = var.db_instance_class
  db_name                             = "mydb"
  username                            = "foo"
  password                            = "foobarbaz"
  iam_database_authentication_enabled = true
  storage_encrypted                   = true
  ca_cert_identifier                  = "rds-ca-2015"
}

After

hcl
resource "aws_db_instance" "example" {
  allocated_storage                   = 20
  storage_type                        = "gp2"
  engine                              = "mysql"
  engine_version                      = var.mysql_engine_version
  instance_class                      = var.db_instance_class
  db_name                             = "mydb"
  username                            = "foo"
  password                            = "foobarbaz"
  iam_database_authentication_enabled = true
  storage_encrypted                   = true
  ca_cert_identifier                  = "rds-ca-rsa2048-g1"
}

References