sidorares/node-mysql2 · error · TypeError

Unknown SSL profile

Error message

Unknown SSL profile '${name}'

What it means

ConnectionConfig.getSSLProfile (lib/connection_config.js:264-273) looks up the provided name in the bundled SSLProfiles map (lib/constants/ssl_profiles.js). If the name is not present it throws TypeError. The map ships only a curated set of well-known CA profiles (e.g. Amazon RDS names); arbitrary strings are rejected.

Solutions

  1. For custom CAs, pass an ssl object instead of a profile name: ssl: { ca: fs.readFileSync('/path/ca.pem') }.
  2. Verify the bundled profile names in lib/constants/ssl_profiles.js before using a string.
  3. For AWS RDS, download the region-specific CA bundle and pass it via the ssl.ca property.

Example fix

// before
createConnection({ ssl: 'my-rds-ca' }); // not a bundled profile

// after
createConnection({ ssl: { ca: fs.readFileSync('rds-ca.pem'), rejectUnauthorized: true } });
Defensive patterns

Strategy: validation

Validate before calling

const fs = require('fs');
function loadSsl(nameOrFile) {
  if (typeof nameOrFile !== 'string') return nameOrFile;
  // treat only known bundled profile names as strings; otherwise read a CA file
  if (/\.pem$/.test(nameOrFile)) return { ca: fs.readFileSync(nameOrFile), rejectUnauthorized: true };
  return nameOrFile; // let mysql2 resolve the profile
}

Type guard

const isSslProfileName = (v, profiles) => typeof v === 'string' && Object.prototype.hasOwnProperty.call(profiles, v);

Prevention

When it happens

Trigger: Passing ssl: 'AmazonRDS' when that profile is not bundled or is differently named; passing a filename or alias expecting it to load a CA file; typo in a known profile name.

Common situations: Following an outdated tutorial referencing a profile name that was removed; assuming any string loads a CA bundle file (it does not — use an ssl object with ca: fs.readFileSync(...)).

Understand the failure class

Related errors


AI-assisted analysis of sidorares/node-mysql2@8b1f829d37 (2026-08-11). Data as JSON: /api/errors/1e9815e0af86db81. Report an issue: GitHub.

Appendix: source

Thrown at lib/connection_config.js:270

    return defaultFlags;
  }

  static getCharsetNumber(charset) {
    const num = Charsets[charset.toUpperCase()];
    if (num === undefined) {
      throw new TypeError(`Unknown charset '${charset}'`);
    }
    return num;
  }

  static getSSLProfile(name) {
    if (!SSLProfiles) {
      SSLProfiles = require('./constants/ssl_profiles.js');
    }
    const ssl = SSLProfiles[name];
    if (ssl === undefined) {
      throw new TypeError(`Unknown SSL profile '${name}'`);
    }
    return ssl;
  }

  static parseUrl(url) {
    const parsedUrl = new URL(url);
    const options = {
      host: decodeURIComponent(parsedUrl.hostname),
      port: parseInt(parsedUrl.port, 10),
      database: decodeURIComponent(parsedUrl.pathname.slice(1)),
      user: decodeURIComponent(parsedUrl.username),
      password: decodeURIComponent(parsedUrl.password),
    };
    for (const [key, value] of parsedUrl.searchParams) {
      if (key in options) {
        continue;
      }
      try {

View on GitHub (pinned to 8b1f829d37)