Global Search
  • Software
    • Overview
    • OpenStack Components
    • SDKs
    • Deployment Tools
    • OpenStack Map
    • Sample Configs
  • Use Cases
    • Users in Production

    • Ironic Bare Metal
    • Edge Computing
    • Telecom & NFV
    • Science and HPC
    • Containers
    • Enterprise
    • User Survey
  • Events
    • OpenInfra Summit
    • Project Teams Gathering
    • OpenDev
    • Community Events
    • OpenStack & OpenInfra Days
    • Summit Videos
  • Community
    • Welcome! Start Here
    • OpenStack Technical Committee
    • Speakers Bureau
    • OpenStack Wiki
    • Get Certified (COA)
    • Jobs
    • Marketing Resources
    • Community News
    • Superuser Magazine

    • OpenInfra Foundation Supporting Organizations
    • OpenInfra Foundation
  • Marketplace
    • Training
    • Distros & Appliances
    • Public Clouds
    • Hosted Private Clouds
    • Remotely Managed Private Clouds
    • Consulting & Integrators
    • Drivers
  • Blog
  • Docs
  • Join
    • Sign up for Foundation Membership
    • Sponsor the Foundation
    • More about the Foundation
  • Log In

SSL/TLS Support in Trove

SSL/TLS Support in Trove¶

Trove provides support for enabling SSL/TLS encryption for database instances, including optional mutual TLS (mTLS) authentication.

This section describes the concepts, configuration, and usage of SSL/TLS in Trove.

  • Overview
    • SSL operating modes
    • Limitations
  • Usage
    • SSL management actions
    • Certificate requirements
    • End-user recommendations
  • Preparing Certificates
    • Generate CA private key
    • Create self-signed CA certificate
    • Generate server private key
    • Generate server CSR
    • Sign server certificate with CA
    • Create PKCS#12 container
    • Store PKCS#12 password in Barbican
    • Upload PKCS#12 to Barbican
    • Generate client private key
    • Generate client CSR
    • Sign client certificate
    • PostgreSQL connection using client certificate
  • SSL/TLS for replication
    • General behavior
    • Prerequisites
    • Enable SSL in replication
    • Restart behavior
    • Replica provisioning
    • Certificate rotation
this page last updated: 2026-05-11 13:55:54
Creative Commons Attribution 3.0 License

Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.

found an error? report a bug
  • Guides
  • Install Guides
  • User Guides
  • Configuration Guides
  • Operations and Administration Guides
  • API Guides
  • Contributor Guides
  • Languages
  • Deutsch (German)
  • Français (French)
  • Bahasa Indonesia (Indonesian)
  • Italiano (Italian)
  • 日本語 (Japanese)
  • 한국어 (Korean)
  • Português (Portuguese)
  • Türkçe (Türkiye)
  • 简体中文 (Simplified Chinese)

trove 25.1.0.dev74

  • Database service
  • Database Service User Guide
    • Database instance status
    • Create and access a database instance
    • Manage databases and users on Trove instances
    • Backup and restore a database
    • Manage database configuration
    • Set up database replication
    • Upgrade datastore
    • Set up database clustering
    • Upgrade cluster datastore
    • SSL/TLS Support in Trove
  • Administrator’s Guide
  • Trove Command Line Tools
  • Contributor Resources
  • Reference Guides

OpenStack

  • Projects
  • OpenStack Security
  • Blog
  • News

Community

  • User Groups
  • Events
  • Jobs
  • Companies
  • Contribute

Documentation

  • OpenStack Manuals
  • Getting Started
  • API Documentation
  • Wiki

Branding & Legal

  • Legal Docs
  • Logos & Guidelines
  • Trademark Policy
  • Privacy Policy
  • OpenInfra CLA

Stay In Touch

The OpenStack project is provided under the Apache 2.0 license. Docs.openstack.org is powered by Rackspace Cloud Computing.