Configuring SSL Certificates
Scenarios
RDS for PostgreSQL allows you to reset an instance certificate to a custom certificate and download the certificate to your local PC.
Constraints
- Resetting the certificate requires corresponding operation permissions. Submit a service ticket.
- Existing connections must be disconnected and reconnected for the custom certificate to take effect.
Procedure
- Log in to the RDS console.
- Click
in the upper left corner and select a region. - On the Instances page, click the target instance name to go to the Overview page.
- Under SSL, click Update.
Alternatively, choose Connectivity & Security from the navigation pane. In the Connection Information area, click Update next to the SSL field.
- In the displayed dialog box, select the target certificate and click OK.
If no certificate is available, purchase an SSL certificate or a private certificate.
Figure 1 Resetting a certificate
- View the update result on the Overview page.
- Log in to the RDS console.
- Click
in the upper left corner and select a region. - On the Instances page, click the target instance name to go to the Overview page.
- Find the SSL field and click Download. In the displayed dialog box, download the Certificate Download package and extract it to obtain the certificate.
Alternatively, choose Connectivity & Security from the navigation pane. In the Connection Information area, click
next to the SSL field to download the Certificate Download package and extract it to obtain the certificate.
- The root certificate bundle (ca-bundle.pem) contains both the new root certificate (issued after April 2017) and the original root certificate.
- TLS v1.2 or later is recommended. Versions earlier than TLS v1.2 may pose security risks. You can configure the encryption protocol version by modifying the ssl_min_protocol_version parameter.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot