All skills

Provisions, connects, migrates, and operates Amazon RDS for Db2. Applies when provisioning with IBM customer and site IDs (License Manager, BYOL, GovCloud), connecting over TLS, fixing SQL30082N after Secrets Manager rotation, migration from Db2 LUW (Linux, AIX, Windows, AS400) or z/OS mainframe (ADB2GEN, Q Replication), choosing code page/collation (EBCDIC, CCSID), S3 backup/restore, Multi-AZ and cross-region standby replicas, RDSADMIN procedures, customer-managed KMS BYOK, self-managed Active Directory Kerberos, Db2 audit to S3, minimum IAM, or colocation.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/rds-db2

This session only. Nothing lands on disk.

referencesconnectivity-tls.md

≈787 tokens on demand. Your agent reads this file only when SKILL.md points to it.

RDS for Db2 — TLS/SSL Connectivity Reference

Configuring and troubleshooting encrypted (SSL/TLS) connections to RDS for Db2: the <region>-bundle.pem truststore certificate, IBM GSKit, and the RDSAS DSN. The db2client-configure.sh script wires this up automatically; this reference covers the detail and manual recovery. For the base client install, DSN/CLP/Python usage, and the airgap flow, see connectivity.md.

Source blog: https://aws.amazon.com/blogs/database/connect-to-amazon-rds-for-db2-using-aws-cloudshell/

Prerequisites

  • SSL enabled on the parameter group (ssl_svcename set) — SSL listens on port 50443.
  • Security group inbound rule allowing TCP 50443 from the client.
  • Region certificate present at ~/<region>-bundle.pem (downloaded from the RDS truststore).

Automatic SSL setup

db2client-configure.sh handles SSL with no extra flags:

  • Downloads <region>-bundle.pem from the RDS truststore.
  • Reorders the bundle so the RSA2048 certificate is first — required by the Db2 CLP.
  • Registers the RDSAS DSN with SSLServerCertificate and SecurityTransportMode=SSL.

It writes one SSL DSN per database: RDSAS for the RDSADMIN system database and <DB>S for each user database. The certificate lands at ~/<region>-bundle.pem.

Verify the SSL path end to end:

db2_test_connection RDSAS

Connect over SSL

# Helper (preferred — pulls credentials from ~/.db2env / Secrets Manager)
db2_connect RDSAS
# Direct CLP
db2 "connect to RDSAS user admin using '<password>'"

SSL connections use port 50443; plaintext TCP uses 50000. Single quotes around the password protect special characters (!, >, <, $).

Download / re-download the certificate

# Online — from the RDS truststore
curl -sL https://truststore.pki.rds.amazonaws.com/us-east-1/us-east-1-bundle.pem -o ~/us-east-1-bundle.pem
# Airgap — from the staged S3 bucket
aws s3 cp s3://<bucket>/ssl/us-east-1-bundle.pem ~/us-east-1-bundle.pem

After re-downloading, re-run db2client-configure.sh to re-register the SSL DSN against the refreshed (RSA-first) certificate.

Manual SSL catalog (without the helper)

db2cli writecfg add -dsn RDSAS -database RDSADMIN -host <endpoint> -port 50443 \
  -parameter "SSLServerCertificate=~/<region>-bundle.pem;SecurityTransportMode=SSL;TLSVersion=TLSV12"

TLSVersion=TLSV12 enforces TLS 1.2. Point SSLServerCertificate at the reordered region PEM at ~/<region>-bundle.pem.

Troubleshooting (GSKit / SSL)

Problem Fix
GSKit / SSL error on connect Re-download the cert, re-run db2client-configure.sh
db2_test_connection RDSAS reports a certificate problem Cert missing, wrong region, or RSA cert not first — re-download and re-run configure
SSL / TLS handshake failure Confirm ssl_svcename is set on the parameter group and SG inbound 50443 is open
Wrong PEM path SSLServerCertificate must point to ~/<region>-bundle.pem
Plaintext works, SSL fails Use port 50443 (not 50000) and the RDSAS DSN

Full SSL diagnostics: db2_test_connection RDSAS.

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides comprehensive management for Amazon RDS for Db2, authored by AWS. It follows standard administrative patterns for database client setup, connectivity, and migration. The identified patterns are consistent with the skill's operational purpose and include appropriate security measures such as restricted file permissions and support for AWS Secrets Manager.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: MEDIUM · 2 issues

Signed by skilld at cbdc61a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
version
2

README badge

README badge for aws/agent-toolkit-for-aws/rds-db2