AWS Security ChangesHomeSearch

AWS AmazonRDS: Added MySQL 8.4.11 with post-quantum TLS support

Service: AmazonRDS · 2026-08-23 · Documentation high

File: AmazonRDS/latest/UserGuide/MySQL.Concepts.VersionMgmt.md · Type: encryption

Summary

Documentation update for MySQL 8.4.11 release including post-quantum hybrid key exchange for TLS 1.3 connections.

Security assessment

The evidence line explicitly documents new quantum-resistant encryption for TLS 1.3, enhancing protection against future cryptographic attacks.

Evidence

  * Added support for post-quantum hybrid key exchange (`X25519MLKEM768` and `SecP256r1MLKEM768`) for TLS 1.3 connections. Clients that support post-quantum key exchange negotiate a quantum-resistant shared secret automatically. To confirm which group the current session negotiated, query the `Ssl_named_group` status variable. For example: `SHOW STATUS LIKE 'Ssl_named_group';`.

Diff

diff --git a/AmazonRDS/latest/UserGuide/MySQL.Concepts.VersionMgmt.md b/AmazonRDS/latest/UserGuide/MySQL.Concepts.VersionMgmt.md
index 0d531a342..a0f2ad1c1 100644
--- a//AmazonRDS/latest/UserGuide/MySQL.Concepts.VersionMgmt.md
+++ b//AmazonRDS/latest/UserGuide/MySQL.Concepts.VersionMgmt.md
@@ -65,0 +66 @@ MySQL engine version | Community release date | RDS release date | RDS end of st
+8.4.11 |  28 July 2026 |  21 August 2026 | 21 August 2027  
@@ -156,0 +158,2 @@ For the changes that the MySQL community made to the minor versions, see [Critic
+  * MySQL version 8.4.11
+
@@ -191,0 +195,13 @@ For the changes that the MySQL community made to the minor versions, see [Critic
+#### MySQL version 8.4.11
+
+MySQL version 8.4.11 is now available on Amazon RDS. This release contains fixes and improvements added by the MySQL community and Amazon RDS.
+
+**New features and enhancements**
+
+  * Updated the time zone information to base it on `tzdata2026c`.
+
+  * Added support for post-quantum hybrid key exchange (`X25519MLKEM768` and `SecP256r1MLKEM768`) for TLS 1.3 connections. Clients that support post-quantum key exchange negotiate a quantum-resistant shared secret automatically. To confirm which group the current session negotiated, query the `Ssl_named_group` status variable. For example: `SHOW STATUS LIKE 'Ssl_named_group';`.
+
+
+
+