Skip to content

aws.rds.describe_certificates

Example SQL Queries

SELECT * FROM
aws.rds.describe_certificates;

Description

Lists the set of certificate authority (CA) certificates provided by Amazon RDS for this Amazon Web Services account.

For more information, see Using SSL/TLS to encrypt a connection to a DB instance in the Amazon RDS User Guide and Using SSL/TLS to encrypt a connection to a DB cluster in the Amazon Aurora User Guide.

Table Definition

Column NameColumn Data Type
certificate_identifier Input Column

The user-supplied certificate identifier. If this parameter is specified, information for only the identified certificate is returned. This parameter isn't case-sensitive.

Constraints:

  • Must match an existing CertificateIdentifier.

VARCHAR
filters Input Column

This parameter isn't currently supported.

STRUCT(
"name" VARCHAR,
"values" VARCHAR[]
)[]
Show child fields
filters[]
Show child fields
filters[].name

The name of the filter. Filter names are case-sensitive.

filters[].values[]
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
certificates

The list of Certificate objects for the Amazon Web Services account.

STRUCT(
"certificate_identifier" VARCHAR,
"certificate_type" VARCHAR,
"thumbprint" VARCHAR,
"valid_from" TIMESTAMP_S,
"valid_till" TIMESTAMP_S,
"certificate_arn" VARCHAR,
"customer_override" BOOLEAN,
"customer_override_valid_till" TIMESTAMP_S
)[]
Show child fields
certificates[]
Show child fields
certificates[].certificate_arn

The Amazon Resource Name (ARN) for the certificate.

certificates[].certificate_identifier

The unique key that identifies a certificate.

certificates[].certificate_type

The type of the certificate.

certificates[].customer_override

Indicates whether there is an override for the default certificate identifier.

certificates[].customer_override_valid_till

If there is an override for the default certificate identifier, when the override expires.

certificates[].thumbprint

The thumbprint of the certificate.

certificates[].valid_from

The starting date from which the certificate is valid.

certificates[].valid_till

The final date that the certificate continues to be valid.

default_certificate_for_new_launches

The default root CA for new databases created by your Amazon Web Services account. This is either the root CA override set on your Amazon Web Services account or the system default CA for the Region if no override exists. To override the default CA, use the ModifyCertificates operation.

VARCHAR