Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use the recommended CA if none are specified #3

Merged
merged 1 commit into from
Nov 16, 2023

Conversation

avnes
Copy link
Contributor

@avnes avnes commented Nov 16, 2023

If var.ca_cert_identifier is not specified, the RDS creation will default to using the CA with id rds-ca-2019
That CA reaches end of life in some months, and AWS has already starting sending emails to database owners that have yet not upgraded.

The new suggested ID is rds-ca-ecc384-g1, and it can be calculated using the data source used in a PR.

PLEASE NOTE: If you already created the database, the certifification change will take place IN THE NEXT MAINTENANCE WINDOW unless you also use var. apply_immediately = true

@avnes avnes merged commit 3b6d689 into main Nov 16, 2023
3 checks passed
@avnes avnes deleted the feat/default-to-recommended-ca branch November 16, 2023 15:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants