Updated on 2026-10-08 GMT+08:00

Configuring SSL Certificates

Scenarios

RDS for PostgreSQL allows you to reset an instance certificate to a custom certificate and download the certificate to your local PC.

Constraints

  • Resetting the certificate requires corresponding operation permissions. Submit a service ticket.
  • Existing connections must be disconnected and reconnected for the custom certificate to take effect.

Procedure

  1. Log in to the RDS console.
  2. Click in the upper left corner and select a region.
  3. On the Instances page, click the target instance name to go to the Overview page.
  4. Under SSL, click Update.

    Alternatively, choose Connectivity & Security from the navigation pane. In the Connection Information area, click Update next to the SSL field.

  5. In the displayed dialog box, select the target certificate and click OK.

    If no certificate is available, purchase an SSL certificate or a private certificate.

    Figure 1 Resetting a certificate

  6. View the update result on the Overview page.
  1. Log in to the RDS console.
  2. Click in the upper left corner and select a region.
  3. On the Instances page, click the target instance name to go to the Overview page.
  4. Find the SSL field and click Download. In the displayed dialog box, download the Certificate Download package and extract it to obtain the certificate.

    Alternatively, choose Connectivity & Security from the navigation pane. In the Connection Information area, click next to the SSL field to download the Certificate Download package and extract it to obtain the certificate.

    • The root certificate bundle (ca-bundle.pem) contains both the new root certificate (issued after April 2017) and the original root certificate.
    • TLS v1.2 or later is recommended. Versions earlier than TLS v1.2 may pose security risks. You can configure the encryption protocol version by modifying the ssl_min_protocol_version parameter.