diff --git a/docs/pages/database-access/getting-started.mdx b/docs/pages/database-access/getting-started.mdx index 7cb9de84709..230cfaa368d 100644 --- a/docs/pages/database-access/getting-started.mdx +++ b/docs/pages/database-access/getting-started.mdx @@ -217,6 +217,10 @@ Finally, connect to the database: $ tsh db connect --db-user=alice --db-name postgres aurora ``` +## Troubleshooting + +(!docs/pages/includes/database-access/aws-troubleshooting.mdx!) + ## Next Steps For the next steps, dive deeper into the topics relevant to your Database diff --git a/docs/pages/database-access/guides/postgres-redshift.mdx b/docs/pages/database-access/guides/postgres-redshift.mdx index 3e45b0d17f6..0230d771175 100644 --- a/docs/pages/database-access/guides/postgres-redshift.mdx +++ b/docs/pages/database-access/guides/postgres-redshift.mdx @@ -162,6 +162,10 @@ To log out of the database and remove credentials: $ tsh db logout my-redshift ``` +## Troubleshooting + +(!docs/pages/includes/database-access/aws-troubleshooting.mdx!) + ## Next steps - Learn more about [using IAM authentication to generate database user diff --git a/docs/pages/database-access/guides/rds.mdx b/docs/pages/database-access/guides/rds.mdx index e9a7d603d8e..b67bdbb4b0d 100644 --- a/docs/pages/database-access/guides/rds.mdx +++ b/docs/pages/database-access/guides/rds.mdx @@ -211,6 +211,10 @@ To log out of the database and remove credentials: $ tsh db logout postgres-rds ``` +## Troubleshooting + +(!docs/pages/includes/database-access/aws-troubleshooting.mdx!) + ## Next steps (!docs/pages/includes/database-access/guides-next-steps.mdx!) diff --git a/docs/pages/database-access/guides/redis-aws.mdx b/docs/pages/database-access/guides/redis-aws.mdx index 30f0c315073..9128810cfeb 100644 --- a/docs/pages/database-access/guides/redis-aws.mdx +++ b/docs/pages/database-access/guides/redis-aws.mdx @@ -225,6 +225,10 @@ $ tsh db logout my-elasticache $ tsh db logout ``` +## Troubleshooting + +(!docs/pages/includes/database-access/aws-troubleshooting.mdx!) + ## Next steps (!docs/pages/includes/database-access/guides-next-steps.mdx!) diff --git a/docs/pages/includes/database-access/aws-troubleshooting.mdx b/docs/pages/includes/database-access/aws-troubleshooting.mdx new file mode 100644 index 00000000000..51ae52ff59d --- /dev/null +++ b/docs/pages/includes/database-access/aws-troubleshooting.mdx @@ -0,0 +1,26 @@ +### Certificate error + +If your `tsh db connect` error includes the following text, you likely have an RDS database created before July 28, 2020, which presents an X.509 certificate that is incompatible with Teleport: + +```code +x509: certificate relies on legacy Common Name field, use SANs instead +``` + +AWS provides instructions to rotate your [SSL/TLS certificate](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL-certificate-rotation.html). + +### No credential providers error + +If you see the error ` NoCredentialProviders: no valid providers in chain` in Database Service logs then Teleport +is not detecting the required credentials to connect via AWS IAM permissions. Check whether +the credentials or security role has been applied in the machine running the Teleport Database Service. + +### Timeout errors + +The Teleport Database Service needs connectivity to your database endpoints. That may require +enabling inbound traffic on the database from the Database Service on the same VPC or routing rules from another VPC. Using the `nc` +program you can verify connections to databases: + +```code +nc -zv postgres-instance-1.sadas.us-east-1.rds.amazonaws.com 5432 +# Connection to postgres-instance-1.sadas.us-east-1.rds.amazonaws.com (172.31.24.172) 5432 port [tcp/postgresql] succeeded! +```