Amazon Relational Database Service
Command Line Interface Reference (API Version 2014-10-31)


The Amazon RDS Command Line Interface (RDS CLI) has been deprecated. Instead, use the AWS CLI for RDS. To learn how to download and use the AWS CLI, see AWS Command Line Interface User Guide. For RDS commands available in the AWS CLI, see AWS CLI Reference for Amazon RDS.

The AWS CLI does not currently support the DownloadCompleteDBLogFile REST API action. To download an entire log file at once, rather than in parts using the download-db-log-file-portion command, use the last published RDS CLI and the rds-download-db-logfile command.


Returns a set of CA certificates associated with this account. If you pass in a certificate identifier, the command returns information only about that certificate. Otherwise it will return information for all the associated certificates, up to the value of --max-records.


rds-describe-certificates certificate-identifier [General Options]


Name Description Required

--certificate-identifier value

-cert value

User-supplied certificate identifier, the unique key that identifies a certificate. The identifier must be 1 to 63 alphanumeric characters or hyphens, is case-insensitive, and is not case-preserving.



The command returns a table that contains the following information:

  • CertificateIdentifier—User-supplied CA certificate identifier; this is the unique key that identifies a certificate

  • CertificateType—Indicates the type of certificate.

  • Thumbprint—The thumbprint of the certificate.

  • ValidFrom—Specifies the first day the certificate is valid.

  • ValidTill—Specifies the last day the certificate is valid.