AWS AmazonRDS: Update insecure cipher documentation link
Summary
Fixed a URL in the release notes discussing the removal of the DES-CBC3-SHA cipher from SSL configurations.
Security assessment
The change only corrects a URL; the security context (cipher removal) is pre-existing and not altered by this diff.
Evidence
+ * Default SSL ciphers used by Aurora MySQL have been updated to exclude the less secure DES-CBC3-SHA values from the [SSL_CIPHER](https://dev.mysql.com/doc/refman/5.7/en/server-system-variables.html#sysvar_ssl_cipher) database parameter. If you encounter SSL connection issues due to the removal of the DES-CBC3-SHA cipher, please use an applicable secure cipher from the following list, [Configuring cipher suites for connections to Aurora MySQL DB clusters](https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/AuroraMySQL.Security.html#AuroraMySQL.Security.SSL.ConfiguringCipherSuites). More information on MySQL client [Connection Cipher Configuration](https://dev.mysql.com/doc/refman/5.7/en/encrypted-connection-protocols-ciphers.html#encrypted-connection-cipher-configuration) can be found in the MySQL documentation.
Diff
diff --git a/AmazonRDS/latest/AuroraMySQLReleaseNotes/AuroraMySQL.Updates.2120.md b/AmazonRDS/latest/AuroraMySQLReleaseNotes/AuroraMySQL.Updates.2120.md index b0291a3fb..b2efce3d8 100644 --- a//AmazonRDS/latest/AuroraMySQLReleaseNotes/AuroraMySQL.Updates.2120.md +++ b//AmazonRDS/latest/AuroraMySQLReleaseNotes/AuroraMySQL.Updates.2120.md @@ -31 +31 @@ This release includes all community CVEs fixes up to and including MySQL 5.7.40. - * Default SSL ciphers used by Aurora MySQL have been updated to exclude the less secure DES-CBC3-SHA values from the [SSL_CIPHER](https://dev.mysql.com/doc/refman/5.7/en/server-system-variables.html#sysvar_ssl_cipher) database parameter. If you encounter SSL connection issues due to the removal of the DES-CBC3-SHA cipher, please use an applicable secure cipher from the following list, [Configuring cipher suites for connections to Aurora MySQL DB clusters](https://docs.aws.amazon.com//AmazonRDS/latest/AuroraUserGuide/AuroraMySQL.Security.html#AuroraMySQL.Security.SSL.ConfiguringCipherSuites). More information on MySQL client [Connection Cipher Configuration](https://dev.mysql.com/doc/refman/5.7/en/encrypted-connection-protocols-ciphers.html#encrypted-connection-cipher-configuration) can be found in the MySQL documentation. + * Default SSL ciphers used by Aurora MySQL have been updated to exclude the less secure DES-CBC3-SHA values from the [SSL_CIPHER](https://dev.mysql.com/doc/refman/5.7/en/server-system-variables.html#sysvar_ssl_cipher) database parameter. If you encounter SSL connection issues due to the removal of the DES-CBC3-SHA cipher, please use an applicable secure cipher from the following list, [Configuring cipher suites for connections to Aurora MySQL DB clusters](https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/AuroraMySQL.Security.html#AuroraMySQL.Security.SSL.ConfiguringCipherSuites). More information on MySQL client [Connection Cipher Configuration](https://dev.mysql.com/doc/refman/5.7/en/encrypted-connection-protocols-ciphers.html#encrypted-connection-cipher-configuration) can be found in the MySQL documentation.