All Products
Search
Document Center

Cloud Config:rds-instance-enabled-ssl

Last Updated:Nov 10, 2025

Checks whether SSL encryption is enabled for an ApsaraDB RDS instance.

Scenario

To enhance link security, we recommend that you enable SSL encryption and install SSL certificates that are issued by Certificate Authorities (CAs) on your application services. This ensures the security and integrity of data in transmission.

Risk level

Default risk level: medium.

You can change the risk level as required when you apply this rule.

Compliance evaluation logic

  • If SSL encryption is enabled for the ApsaraDB RDS instance, the configuration is considered compliant.
  • If SSL encryption is not enabled for the ApsaraDB RDS instance, the configuration is considered non-compliant. For more information about how to correct the non-compliant configuration, see Non-compliance remediation.

Rule details

ItemDescription
Rule namerds-instance-enabled-ssl
Rule IDrds-instance-enabled-ssl
TagRDS
Automatic remediationNot supported
Trigger typeConfiguration change
Supported resource typeApsaraDB RDS instance
Input parameterNone

Non-compliance remediation

Configure SSL encryption for the ApsaraDB RDS instance. For more information, see Use a cloud certificate to enable SSL encryption.