hi, i'm using a postgres rds as a backend for pref...
# prefect-cloud
m
hi, i'm using a postgres rds as a backend for prefect cloud. we're getting ready to roll our database ca keys and need to ensure continuity. can i get a confirmation that prefect cloud trusts the aws root certificate identified as "rds-ca-rsa2048-g1"?
Copy code
$ aws rds describe-certificates --certificate-identifier rds-ca-rsa2048-g1
{
    "Certificates": [
        {
            "CertificateIdentifier": "rds-ca-rsa2048-g1",
            "CertificateType": "CA",
            "Thumbprint": "2fa77ef894d983ba9d37ad699c84ab0f657be1c8",
            "ValidFrom": "2021-05-25T22:34:57+00:00",
            "ValidTill": "2061-05-25T23:34:57+00:00",
            "CertificateArn": "arn:aws:rds:us-east-1::cert:rds-ca-rsa2048-g1",
            "CustomerOverride": false
        }
    ],
    "DefaultCertificateForNewLaunches": "rds-ca-rsa2048-g1"
}
Copy code
$ openssl x509 -in cert-78 -noout -fingerprint -sha1
sha1 Fingerprint=2F:A7:7E:F8:94:D9:83:BA:9D:37:AD:69:9C:84:AB:0F:65:7B:E1:C8
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html#UsingWithRDS.SSL.CertificatesAllRegions
this is no longer an issue, please ignore.