I currently have a lambda function which communicates with an aws aurora postgres cluster. Given the nature of the application I need to ensure that the inflight communication is encrypted. We are using IAM database authentication and in the RDS aurora the docs it states:
IAM database authentication provides the following benefits: Network traffic to and from the database is encrypted using Secure Socket Layer (SSL) or Transport Layer Security (TLS)
Though there is little further explanation (that I can find) of how this works in the context of a lambda function i.e. how does the lambda verify that it trusts the issuer, or Certificate Authority, of the SSL certificate it receives. NB I have set the rds.force_ssl to 1 (true) to verify communication is indeed SSL/TLS and the application still functions normally.
The documentation goes onto link to another page Using SSL/TLS to encrypt a connection to a DB cluster where it states:
SSL/TLS connections provide one layer of security by encrypting data that moves between your client and a DB cluster. Using a server certificate provides an extra layer of security by validating that the connection is being made to an Amazon Aurora DB cluster.
What is meant by the server certificate I'm a little unsure about here - i.e. is that what the client uses to verify that it trusts the issuer of the cert it receives during the initial handshake?