sidorares/node-mysql2 · error · TypeError
Unknown SSL profile
Error message
Unknown SSL profile '${name}' What it means
ConnectionConfig.getSSLProfile (lib/connection_config.js:264-273) looks up the provided name in the bundled SSLProfiles map (lib/constants/ssl_profiles.js). If the name is not present it throws TypeError. The map ships only a curated set of well-known CA profiles (e.g. Amazon RDS names); arbitrary strings are rejected.
Solutions
- For custom CAs, pass an ssl object instead of a profile name: ssl: { ca: fs.readFileSync('/path/ca.pem') }.
- Verify the bundled profile names in lib/constants/ssl_profiles.js before using a string.
- For AWS RDS, download the region-specific CA bundle and pass it via the ssl.ca property.
Example fix
// before
createConnection({ ssl: 'my-rds-ca' }); // not a bundled profile
// after
createConnection({ ssl: { ca: fs.readFileSync('rds-ca.pem'), rejectUnauthorized: true } }); Defensive patterns
Strategy: validation
Validate before calling
const fs = require('fs');
function loadSsl(nameOrFile) {
if (typeof nameOrFile !== 'string') return nameOrFile;
// treat only known bundled profile names as strings; otherwise read a CA file
if (/\.pem$/.test(nameOrFile)) return { ca: fs.readFileSync(nameOrFile), rejectUnauthorized: true };
return nameOrFile; // let mysql2 resolve the profile
} Type guard
const isSslProfileName = (v, profiles) => typeof v === 'string' && Object.prototype.hasOwnProperty.call(profiles, v);
Prevention
- Prefer ssl objects with explicit ca/key/cert over profile-name strings.
- Confirm a profile name exists in lib/constants/ssl_profiles.js before use.
When it happens
Trigger: Passing ssl: 'AmazonRDS' when that profile is not bundled or is differently named; passing a filename or alias expecting it to load a CA file; typo in a known profile name.
Common situations: Following an outdated tutorial referencing a profile name that was removed; assuming any string loads a CA bundle file (it does not — use an ssl object with ca: fs.readFileSync(...)).
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
Related errors
- SSL profile must be an object, instead it's a
- "database" connection config property must be a string
- Unknown charset
- "user" connection config property must be a string
- Bind parameters must be array if namedPlaceholders…
AI-assisted analysis of sidorares/node-mysql2@8b1f829d37 (2026-08-11).
Data as JSON: /api/errors/1e9815e0af86db81.
Report an issue: GitHub.
Appendix: source
Thrown at lib/connection_config.js:270
return defaultFlags;
}
static getCharsetNumber(charset) {
const num = Charsets[charset.toUpperCase()];
if (num === undefined) {
throw new TypeError(`Unknown charset '${charset}'`);
}
return num;
}
static getSSLProfile(name) {
if (!SSLProfiles) {
SSLProfiles = require('./constants/ssl_profiles.js');
}
const ssl = SSLProfiles[name];
if (ssl === undefined) {
throw new TypeError(`Unknown SSL profile '${name}'`);
}
return ssl;
}
static parseUrl(url) {
const parsedUrl = new URL(url);
const options = {
host: decodeURIComponent(parsedUrl.hostname),
port: parseInt(parsedUrl.port, 10),
database: decodeURIComponent(parsedUrl.pathname.slice(1)),
user: decodeURIComponent(parsedUrl.username),
password: decodeURIComponent(parsedUrl.password),
};
for (const [key, value] of parsedUrl.searchParams) {
if (key in options) {
continue;
}
try {View on GitHub (pinned to 8b1f829d37)