Configure SSL encryption
Updated at:
Copy as MD
To enhance the security of data in transit, you can enable Secure Sockets Layer (SSL) encryption and install an SSL CA certificate on your applications. SSL encrypts network connections at the transport layer, which improves data security and integrity but also increases connection response time.
Usage notes
- An SSL certificate is valid for one year. You must update the certificate before it expires to prevent connection failures.
- Due to the inherent overhead of SSL encryption, enabling it can significantly increase CPU utilization. We recommend enabling SSL encryption only for instances accessed over the internet, as internal network connections are generally secure and do not require it.
Enable SSL encryption
Warning This operation restarts the instance. To avoid service interruptions, perform this operation during off-peak hours.
- Log on to the AnalyticDB for PostgreSQL console.
- In the upper-left corner of the console, select a region.
- Find the instance that you want to manage and click the instance ID.
- In the left-side navigation pane, click Security Controls.
- Click the SSL Encryption tab.
- Turn on the SSL Encryption switch.
- In the Enable SSL Encryption dialog box, click OK.
- When the SSL Encryption status changes to Enabled, click Download Certificate.
The downloaded compressed archive contains the following files:
- .p7b file: Use this file to import the CA certificate into Windows systems.
- .pem file: Use this file to import the CA certificate into other operating systems or applications.
- .jks file: A Java KeyStore (JKS) file used to import the CA certificate chain into Java applications. The keystore password is
apsaradb.When you use the JKS file with JDK 7 or JDK 8, you must modify the following settings in the
jre/lib/security/java.securityfile on your application's host:jdk.tls.disabledAlgorithms=SSLv3, RC4, DH keySize < 224 jdk.certpath.disabledAlgorithms=MD2, RSA keySize < 1024If you do not modify these settings, an error similar to the following may occur. Such errors are typically caused by Java security configurations.
javax.net.ssl.SSLHandshakeException: DHPublicKey does not comply to algorithm constraints
Update the validity period
Warning This operation restarts the instance. To avoid service interruptions, perform this operation during off-peak hours.
- Log on to the AnalyticDB for PostgreSQL console.
- In the upper-left corner of the console, select a region.
- Find the instance that you want to manage and click the instance ID.
- In the left-side navigation pane, click Security Controls.
- Click the SSL Encryption tab.
- Click Update Validity next to SSL Encryption.
- In the Update SSL Certificate Validity dialog box, click OK.
Disable SSL encryption
Warning This operation restarts the instance. To avoid service interruptions, perform this operation during off-peak hours.
- Log on to the AnalyticDB for PostgreSQL console.
- In the upper-left corner of the console, select a region.
- Find the instance that you want to manage and click the instance ID.
- In the left-side navigation pane, click Security Controls.
- Click the SSL Encryption tab.
- Turn off the SSL Encryption switch.
- In the Disable SSL Encryption dialog box, click OK.
API reference
| API | Description |
| DescribeDBInstanceSSL | Queries information about SSL encryption for an instance. |
| ModifyDBInstanceSSL | Enables or disables SSL encryption, or updates the validity period of an SSL certificate. |
Is this page helpful?