AWS Security ChangesHomeSearch

AWS datasync: Clarified TDE encryption support limitations

Service: datasync · 2026-07-29 · Documentation medium

File: datasync/latest/userguide/encryption-in-transit.md · Type: encryption

Summary

Specified that TDE encryption with HDFS is unsupported only in Basic mode tasks.

Security assessment

Clarifies encryption support limitations, helping users avoid insecure configurations in Basic mode.

Evidence

For example, DataSync currently doesn't support Kerberos authentication with NFS file servers, or when using TDE encryption with HDFS on Basic mode tasks.

Diff

diff --git a/datasync/latest/userguide/encryption-in-transit.md b/datasync/latest/userguide/encryption-in-transit.md
index 1009bef99..079ad6a81 100644
--- a//datasync/latest/userguide/encryption-in-transit.md
+++ b//datasync/latest/userguide/encryption-in-transit.md
@@ -25 +25 @@ Reference | Network connection | Description
-1 | Reading data from the source location | DataSync connects by using the storage system's protocol for accessing data (for example, SMB or the Amazon S3 API). For this connection, data is protected by using the security features of the storage system unless DataSync doesn't support those features. For example, DataSync currently doesn't support Kerberos authentication with NFS file servers or when using TDE encryption with HDFS.  
+1 | Reading data from the source location | DataSync connects by using the storage system's protocol for accessing data (for example, SMB or the Amazon S3 API). For this connection, data is protected by using the security features of the storage system unless DataSync doesn't support those features. For example, DataSync currently doesn't support Kerberos authentication with NFS file servers, or when using TDE encryption with HDFS on Basic mode tasks.