Enable SSL Encryption

<p>This article describes how to enable SSL encryption.</p> <p><span style="font-size:18px"><strong>Overview</strong></span></p> <p>SSL (Secure Sockets Layer) encryption can encrypt the network connection in the transmission layer. In order to enhance security of data transmission link, you can enable SSL encryption to improve the security and integrity of communication data. But the response time of network connection will increase after SSL encryption is enabled.</p> <p>A general instance and read-only instance support enabling SSL encryption.</p> <p><span style="font-size:18px"><strong>Prerequisites</strong></span></p> <p>You have successfully created an instance. For more information, see <a href="http://pinganyun.com/ssr/help/database/RDS/User_Guide_RDS_MySQL.Instance_Management.Create_Instance.Create_Common_Instance" target="_blank">Create a General Instance</a>, <a href="http://pinganyun.com/ssr/help/database/RDS/User_Guide_RDS_MySQL.Instance_Management.Create_Instance.Create_Slave_Instance" target="_blank">Create a Remote Disaster Recovery Instance</a> or <a href="http://pinganyun.com/ssr/help/database/RDS/User_Guide_RDS_MySQL.Instance_Management.Create_Instance.Create_Read_Only_Instance" target="_blank">Create a Read-only Instance</a>.</p> <p><span style="font-size:18px"><strong>Usage Guidelines</strong></span></p> <ul> <li>Enabling SSL encryption of general instances will lead to restarting the general instances created by your account. The instances will be restarted at the same time as you create a disaster recovery instance.</li> <li>SSL Encryption of read-only instances can be enabled independently from that of the general instances.</li> <li>SSL Encryption of citywide read-only instances and remote read-only instances can be enabled separately.</li> <li>Enabling SSL Encryption of citywide read-only instances only leads to restarting citywide read-only instances; enabling SSL encryption of remote read-only instances only leads to restarting remote read-only instances.</li> <li>You enable SSL Encryption in the console. It only means that Ping An Cloud provides SSL encryption. When connecting to RDS MySQL instances, you can select whether to enable SSL encryption. If you want to enable it, you need to download a certificate in the console. If not, you do not need to download a certificate and just connect to the instances as normal.</li> <li>Due to inherent defect of SSL encryption, enabling SSL encryption may significantly increase the CPU usage. We recommend that you perform the task with caution.</li> </ul> <p><span style="font-size:18px"><strong>Procedures</strong></span></p> <p>1.&nbsp; Log in to the <a href="http://pinganyun.com/console/rds/overview" target="_blank">RDS Console</a>.</p> <p>2.&nbsp; In the left navigation pane, click <strong>RDS-MySQL</strong> to enter the <strong>DBPaaS for RDS-MySQL</strong> page.</p> <p>3.&nbsp; Select the target region.</p> <p>4.&nbsp; In the <strong>Operations </strong>column of the target instance, click <strong>Manage</strong>. Select <strong>White List</strong> tab.</p> <p>5.&nbsp; In the <strong>SSL Setting </strong>area, switch on <strong>Enable SSL Encryption</strong> to enter <strong>Enable SSL Encryption</strong> page.</p> <p><img src="https://obs-cn-shanghai.yun.pingan.com/pcp-portal/20200307170823-13d70edd9d1c.png" style="height:213px; width:830px" /></p> <p>6.&nbsp; Select an effective time. Currently it supports one month, six months, one year, three years, and ten years. One year is the default value.</p> <p><img src="https://obs-cn-shanghai.yun.pingan.com/pcp-portal/20200307170852-11cf6880919f.png" style="height:278px; width:758px" /></p> <p>7.&nbsp; Click <strong>Save</strong> to enter the <strong>Verification Code</strong> page.</p> <p>8.&nbsp; The system will send a verification code to the mobile phone that is bound to the account. Fill in the verification code and click <strong>Confirm</strong>.</p> <p>9.&nbsp; The <strong>Status</strong> of the target instance is <strong>Restarting</strong>.</p> <p><span style="font-size:18px"><strong>Result</strong></span></p> <ul> <li>The <strong>Status</strong> of the target instance is<strong> Running</strong>.</li> <li>In the <strong>Operations </strong>column of the target instance, click <strong>Manage</strong>. Select <strong>White List</strong> tab. In the <strong>SSL Setting</strong> area, you can view SSL Encryption is enabled and <strong>Status</strong> is <strong>Encrypted</strong> and also view the <strong>effective time</strong> of SSL encryption.</li> </ul> <p><img src="https://obs-cn-shanghai.yun.pingan.com/pcp-portal/20200307170915-11d419b49bf9.png" style="height:230px; width:830px" /></p>
Did the above content solve your problem? Yes No
Please complete information!

Call us

400-151-8800

Email us

cloud@pingan.com

Online customer service

Instant reply

Technical Support

cloud products