AWS AmazonRDS: Enforced rdsproxyadmin protection in MariaDB 12.3
Summary
Documented engine-level enforcement preventing modification of rdsproxyadmin user.
Security assessment
Hardens security by preventing unauthorized changes to critical proxy management account.
Evidence
Starting in RDS for MariaDB version 12.3, the database engine enforces this protection. Attempts to `CREATE`, `DROP`, `RENAME`, `GRANT`, `REVOKE`, or `SET PASSWORD` for `rdsproxyadmin` return an error.
Diff
diff --git a/AmazonRDS/latest/UserGuide/rds-proxy.md b/AmazonRDS/latest/UserGuide/rds-proxy.md index e21c3ea4c..177b8437b 100644 --- a//AmazonRDS/latest/UserGuide/rds-proxy.md +++ b//AmazonRDS/latest/UserGuide/rds-proxy.md @@ -101,0 +102,2 @@ For more information about global condition context keys, see [AWS global condit +Starting in RDS for MariaDB version 12.3, the database engine enforces this protection. Attempts to `CREATE`, `DROP`, `RENAME`, `GRANT`, `REVOKE`, or `SET PASSWORD` for `rdsproxyadmin` return an error. For details, see [MariaDB security on Amazon RDS](./MariaDB.Concepts.UsersAndPrivileges.html). +