How to get hold of Amazon MySQL RDS certificates

Amazon RDS documentation ( specifies that "Amazon RDS generates an SSL certificate for each [MySQL] DB Instance". I haven't been able to find any documentation on how to find the certificates and the certificates are nowhere to be found in the management console.

Where are the certificates?

As of September 19, 2019, Amazon RDS has published new Certificate Authority (CA) certificates for connecting to your RDS DB instances using Secure Socket

You can get the AWS RDS certificate file information from the AWS Documentation guide itself

Download the certificate from here

Update - Amazon updated the SSL certificate, you can download the it from here :

Use the following command to login into mysql

root@sathish:/usr/src# mysql -h -u awssathish -p --ssl-ca=mysql-ssl-ca-cert.pem
Enter password: 
Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 22
Server version: 5.6.13-log MySQL Community Server (GPL)

Copyright (c) 2000, 2013, Oracle and/or its affiliates. All rights reserved.

Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

mysql> GRANT USAGE ON *.* TO ‘awssathish’@’%’ REQUIRE SSL
Query OK, 0 rows affected (0.02 sec)
mysql> show variables like "%ssl";
| Variable_name | Value |
| have_openssl  | YES   |
| have_ssl      | YES   |
2 rows in set (0.00 sec)
mysql> SHOW STATUS LIKE 'Ssl_cipher';
| Variable_name | Value      |
| Ssl_cipher    | AES256-SHA |
1 row in set (0.01 sec)

mysql> exit


is Endpoint of RDS,


is the username of the rds server

To get a certificate bundle that contains both the intermediate and root certificates, download from If your application is on Microsoft Windows and requires a PKCS7 file, you can download the PKCS7 certificate bundle.

I used You have to get root pem and pem for the region and concatenate 2 files in one.

And merge files to have single rds-ca-2015-us-west-2-bundle.pem file. With --ssl-ca provide full path to you pem file.

When you update the trust store, you can retain older certificates in addition to adding the new certificates. Amazon's documentation recommends to use both the intermediate and root certificates rds-combined-ca-bundle.pem with MySQL but only root certificate rds-ca-2019-root.pem with PostgreSQL.

To get a certificate bundle that contains both the intermediate and root certificates for the AWS Amazon RDS provides new CA certificates as an AWS security best practice.

Connecting to Amazon RDS MySQL Database Amazon RDS is a secure and reliable web-based service, which greatly simplifies the process of deploying, managing, and scaling relational databases in the cloud, thus, allowing you to connect at any time and from any place where the Internet access is available.

To enable an SSL connection to RDS for MySQL the first step is to download the certificate authority (CA) file from Amazon. To make sure your MySQL connection is done over SSL you need to supply the CA file when connecting.

