Configure SSL encryption

Updated at:
Copy as MD

To enhance the security of data in transit, you can enable Secure Sockets Layer (SSL) encryption and install an SSL CA certificate on your applications. SSL encrypts network connections at the transport layer, which improves data security and integrity but also increases connection response time.

Usage notes

  • An SSL certificate is valid for one year. You must update the certificate before it expires to prevent connection failures.
  • Due to the inherent overhead of SSL encryption, enabling it can significantly increase CPU utilization. We recommend enabling SSL encryption only for instances accessed over the internet, as internal network connections are generally secure and do not require it.

Enable SSL encryption

Warning This operation restarts the instance. To avoid service interruptions, perform this operation during off-peak hours.
  1. Log on to the AnalyticDB for PostgreSQL console.
  2. In the upper-left corner of the console, select a region.
  3. Find the instance that you want to manage and click the instance ID.
  4. In the left-side navigation pane, click Security Controls.
  5. Click the SSL Encryption tab.
  6. Turn on the SSL Encryption switch.
  7. In the Enable SSL Encryption dialog box, click OK.
  8. When the SSL Encryption status changes to Enabled, click Download Certificate.
    The downloaded compressed archive contains the following files:
    • .p7b file: Use this file to import the CA certificate into Windows systems.
    • .pem file: Use this file to import the CA certificate into other operating systems or applications.
    • .jks file: A Java KeyStore (JKS) file used to import the CA certificate chain into Java applications. The keystore password is apsaradb.

      When you use the JKS file with JDK 7 or JDK 8, you must modify the following settings in the jre/lib/security/java.security file on your application's host:

      jdk.tls.disabledAlgorithms=SSLv3, RC4, DH keySize < 224
      jdk.certpath.disabledAlgorithms=MD2, RSA keySize < 1024

      If you do not modify these settings, an error similar to the following may occur. Such errors are typically caused by Java security configurations.

      javax.net.ssl.SSLHandshakeException: DHPublicKey does not comply to algorithm constraints

Update the validity period

Warning This operation restarts the instance. To avoid service interruptions, perform this operation during off-peak hours.
  1. Log on to the AnalyticDB for PostgreSQL console.
  2. In the upper-left corner of the console, select a region.
  3. Find the instance that you want to manage and click the instance ID.
  4. In the left-side navigation pane, click Security Controls.
  5. Click the SSL Encryption tab.
  6. Click Update Validity next to SSL Encryption.
  7. In the Update SSL Certificate Validity dialog box, click OK.

Disable SSL encryption

Warning This operation restarts the instance. To avoid service interruptions, perform this operation during off-peak hours.
  1. Log on to the AnalyticDB for PostgreSQL console.
  2. In the upper-left corner of the console, select a region.
  3. Find the instance that you want to manage and click the instance ID.
  4. In the left-side navigation pane, click Security Controls.
  5. Click the SSL Encryption tab.
  6. Turn off the SSL Encryption switch.
  7. In the Disable SSL Encryption dialog box, click OK.

API reference

API Description
DescribeDBInstanceSSL Queries information about SSL encryption for an instance.
ModifyDBInstanceSSL Enables or disables SSL encryption, or updates the validity period of an SSL certificate.