I'm starting to use Amazon Web Service's Relational Database Server product (AWS RDS) and want to confirm I have not made a security blunder.
- Publicly accessible
- Inbound rule on security group added for "PostgreSQL / My IP"
These options enable me to use pgAdmin to connect and populate data. I've tried to determine the auth-method used in AWS RDS Postgres without success.
Am I transmitting my password in clear text when I connect with pgAdmin?
I'm starting to think my fears are warranted. This is what I've learned:
- Directions for Using SSL with PostgreSQL DB Instance suggests it's not the default
- The 'SSL' option in my pgAdmin connection properties has no options (prob'ly because I haven't setup certificates)