Alert Runbooks

RDSCACertificateCloseToExpiration

Runbook: RDSCACertificateCloseToExpiration Alert

Alert Details

Description

Alert is triggered when an RDS instance is detected using a CA certificate which is going to expire in less than 15 days.

Possible Causes

Troubleshooting Steps

1. Identify the instance(s) concerned

2. Renew your certificate for the instances retrieved above by running

aws rds modify-db-instance \ --db-instance-identifier <your_db_instance> \ --ca-certificate-identifier <your_new_certificate>

Tips

We recommend using the rds-ca-rsa2048-g1 certificate authority which: