AWS govcloud-us medium security documentation change
Summary
Added region availability section, FIPS-approved cryptographic algorithm requirements, and updated documentation link
Security assessment
Added explicit documentation of FIPS-approved cryptographic algorithms (TLS 1.3/1.2 ciphers and AES-256-GCM) which directly addresses security compliance requirements
Diff
diff --git a/govcloud-us/latest/UserGuide/govcloud-vpnclient.md b/govcloud-us/latest/UserGuide/govcloud-vpnclient.md index c1aee0019..ddd2d5135 100644 --- a//govcloud-us/latest/UserGuide/govcloud-vpnclient.md +++ b//govcloud-us/latest/UserGuide/govcloud-vpnclient.md @@ -7 +7 @@ -How Client VPN differsDocumentationExport-controlled content +Region availabilityHow Client VPN differsDocumentationExport-controlled content @@ -12,0 +13,11 @@ AWS Client VPN is a managed client-based Site-to-Site VPN service that enables y +## Region availability + +This service is available in the following AWS GovCloud (US) Regions: + + * AWS GovCloud (US-West) + + * AWS GovCloud (US-East) + + + + @@ -20,0 +32,8 @@ The following differences apply to Client VPN: + * We suggest you use the client configuration file exported from the {cvpnlong} endpoint without modification. {cvpnlong} endpoints in AWS GovCloud (US) use the following FIPS-approved cryptographic algorithms and clients should not be configured to use other ciphers: + + * TLS 1.3: `TLS_AES_256_GCM_SHA384` and `TLS_AES_128_GCM_SHA256` + + * TLS 1.2: `TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384`, `TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256`, `TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384`, and `TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256` + + * Data channel: `AES-256-GCM` + @@ -26 +45,4 @@ The following differences apply to Client VPN: -[AWS Client VPN documentation](https://docs.aws.amazon.com/vpn). + * [AWS Client VPN documentation](https://docs.aws.amazon.com/vpn) + + + @@ -55 +77 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please -AWS Private Certificate Authority +Amazon Chime SDK