This repository was archived by the owner on Jan 28, 2026. It is now read-only.
Improve sslrootcert defaults/documentation#46
Merged
Conversation
vic-tsang
approved these changes
Jan 21, 2026
danielfrankcom
added a commit
that referenced
this pull request
Jan 26, 2026
This PR fixes a build error which was introduced by the combination of #45 and #46. The pre-commit checks were not run against #46 due to the merge order. Now that the quotes are added, the build will not fail like [here](https://github.com/awslabs/aurora-dsql-sqlalchemy/actions/runs/21368988492/job/61508301097). By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
As discussed in #41, our current documentation around SSL/TLS configuration is lacking. This PR adds better documentation for how to correctly configure certificate trust, and also updates the default configuration to use the
systemtrust store, rather than requiring a specific cert file path.The default change is primarily motivated by the fact that on some systems, the Amazon root cert will already be trusted by the
systemtrust store. This is platform-specific and won't always be the case, but in those cases customers won't need to make any changes to use the driver. For other cases, the cert will need to be downloaded and configured as trusted, but we were requiring that anyway with our previous default.By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.