AWS Security ChangesHomeSearch

AWS mgn: Enforced HTTPS default and validation requirements for MGN connector

Service: mgn · 2026-08-31 · Documentation high

File: mgn/latest/ug/connector-register-server-credentials.md · Type: encryption,network

Summary

Updated security configurations including HTTPS as default WinRM protocol, mandatory validation flags, and strict credential formatting requirements.

Security assessment

The changes enforce HTTPS as the default protocol to prevent eavesdropping, require certificate/host key validation to mitigate MITM attacks, and add constraints to prevent insecure HTTP configurations.

Evidence

      * **HTTP protocol constraint:** `WinCaValidation` must be false when `WinConnectionProtocol` is set to HTTP.

Diff

diff --git a/mgn/latest/ug/connector-register-server-credentials.md b/mgn/latest/ug/connector-register-server-credentials.md
index 03b22c955..428033c0e 100644
--- a//mgn/latest/ug/connector-register-server-credentials.md
+++ b//mgn/latest/ug/connector-register-server-credentials.md
@@ -11 +11 @@ NEW - You can now accelerate your migration and modernization with AWS Transform
-After you have the MGN connector set up and ready to use, you can register source servers to the MGN connector. To do so, choose the MGN connector name, then choose **Register servers**. 
+Once you have the MGN connector set up and ready to use, you can register source servers to the MGN connector. To do so click on the MGN connector name, then click "Register servers".
@@ -15 +15 @@ The servers list contains the source servers that were imported via the import f
-Select the source servers you want to register to the MGN connector. Choose the **Register servers with the MGN connector** button.
+Select the source servers you want to register to the MGN connector. Click the "Register servers with the MGN connector" button.
@@ -17 +17 @@ Select the source servers you want to register to the MGN connector. Choose the
-To perform actions on your source server, you must provide source server credentials. Server credentials are stored in AWS Secrets Manager. You can use an existing secret from the AWS Secrets Manager or create a new one. You can create the credentials in the MGN console, by choosing **Register server credentials** from the **Actions** menu.
+To perform actions on your source server, you must provide source server credentials. Server credentials are stored in AWS Secrets Manager. You can use an existing secret from AWS Secrets Manager or create a new one. You can create the credentials in the MGN console by choosing **Register server credentials** from the **Actions** menu.
@@ -21 +21 @@ To perform actions on your source server, you must provide source server credent
-    * Using AWS Secrets Manager MGN can use the stored source server credentials and API keys to connect to the source machine and perform actions on it. You must specify the secret that stores the source server credentials, using an existing secret.
+    * Using AWS Secrets Manager, MGN can use the stored source server credentials to connect to the source machine and perform actions on it. You must specify the secret that stores the source server credentials.
@@ -23 +23 @@ To perform actions on your source server, you must provide source server credent
-    * You may designate the same secret for multiple source servers, if they share the same credentials.
+    * You may designate the same secret for multiple source servers if they share the same credentials.
@@ -35,11 +35 @@ To perform actions on your source server, you must provide source server credent
-      * **Communication protocol** – this is the WinRM connection protocol between the MGN Connector and Source Servers used to install the agents.
-
-###### Note
-
-Though you can use HTTP, we recommend that you use HTTPS to ensure secure and encrypted communication between the MGN connector and the source servers.
-
-Specify either:
-
-        * **HTTP**
-
-        * **HTTPS**
+      * **Communication protocol** – This is the WinRM connection protocol between the MGN Connector and source servers used to install the agents. Specify either HTTP or HTTPS. We recommend HTTPS for secure and encrypted communication. Default is HTTPS.
@@ -51 +41 @@ Specify either:
-      * **CertificateAuthority** (Optional) - Include the source server IPs in the certificate's SAN field to enable communication.
+      * **CertificateAuthority** (Required if WinCaValidation is true) - The CA public certificate in PEM format, base64-encoded. Must be omitted or empty if WinCaValidation is false.
@@ -57 +47 @@ Specify either:
-      * **Provide one of the following:**
+      * **Credentials** \- Provide one of the following:
@@ -59 +49 @@ Specify either:
-        * **Password** – The specific source server's password.
+        * **PrivateKey** – The source server's RSA private key in PEM format, base64-encoded. (The connector uses RSA keys only.)
@@ -61 +51 @@ Specify either:
-        * **PrivateKey** – The source server’s private key.
+        * **Password** – The specific source server's password (alternative to PrivateKey).
@@ -63 +53 @@ Specify either:
-      * **HostKey** (Optional) – include the host key to validate it during SSH connection.
+      * **HostKey** (Required if LinuxHostKeyValidation is true) - The source server's public host key in the format: `algorithm_name base64_public_key` (e.g., `ssh-ed25519 AAAA...`). This is the full base64 public key blob from ssh-keyscan output, not a fingerprint. Must be omitted if LinuxHostKeyValidation is false.
@@ -71,8 +61,9 @@ Specify either:
-            "WinUserName":"_windows_username_ ",
-            "WinPassword":"_windows_password_ ",
-            "WinCertificateAuthority":"",
-            "WinCaValidation":false,
-            "LinuxUserName":"_linux_username_ ",
-            "LinuxPrivateKey":"_linux_private_key_ ",
-            "LinuxHostKey":"_linux_host_key_ ",
-            "LinuxHostKeyValidation":false
+          "WinUserName": "windows_username",
+          "WinPassword": "windows_password",
+          "WinCertificateAuthority": "<base64-encoded CA public certificate (PEM)>",
+          "WinCaValidation": true,
+          "LinuxUserName": "linux_username",
+          "LinuxPrivateKey": "<base64-encoded RSA private key (PEM)>",
+          "LinuxPassword": "<alternative to LinuxPrivateKey>",
+          "LinuxHostKey": "ssh-ed25519 <base64 public host key>",
+          "LinuxHostKeyValidation": true
@@ -82 +73 @@ Specify either:
-  * ###### Note
+    * **Important notes on secret format:**
@@ -84 +75 @@ Specify either:
-The CA/HostKey validation is turned on by default, indicated by the validation flag being set to true. Provide the CA or HostKey in the json for validation. If you don’t provide it, you must explicitly disable validation by setting the validation flag to false. The key algorithm in HostKey, must be provided in the following format:
+      * **Base64 encoding:** `LinuxPrivateKey` and `WinCertificateAuthority` must be base64-encoded PEM values. If you create the secret in the MGN console, encoding is performed automatically. If you create the secret manually in AWS Secrets Manager, you must encode these values yourself. Raw PEM text will cause connection failures.
@@ -86 +77,11 @@ The CA/HostKey validation is turned on by default, indicated by the validation f
-        "HostKey": "algorithm_name thumbprint"
+      * **Private key format:** `LinuxPrivateKey` must be an RSA private key. Other key types are not supported.
+
+      * **Validation flags:** `WinCaValidation` and `LinuxHostKeyValidation` are required fields and must always be present in the secret.
+
+      * **Validation constraints:** `WinCertificateAuthority` is required only when `WinCaValidation` is true. `LinuxHostKey` is required only when `LinuxHostKeyValidation` is true. When their validation flag is false, these fields should be omitted or empty.
+
+      * **HTTP protocol constraint:** `WinCaValidation` must be false when `WinConnectionProtocol` is set to HTTP.
+
+      * **HostKey format:** The `LinuxHostKey` value is the full base64 public key blob from ssh-keyscan output (the second field), in the format `algorithm_name base64_key`. It is NOT a fingerprint or thumbprint.
+
+  * ###### Note
@@ -88 +89 @@ The CA/HostKey validation is turned on by default, indicated by the validation f
-List of supported algorithms: "ssh-ed25519", "ecdsa-sha2-nistp256", "ecdsa-sha2-nistp384", "ecdsa-sha2-nistp521", "rsa-sha2-512", "rsa-sha2-256", "ssh-rsa", "ssh-dss"
+The CA/HostKey validation is controlled by the validation flags (`WinCaValidation` and `LinuxHostKeyValidation`). When a validation flag is set to true, you must provide the corresponding CA or HostKey value. When set to false, the CA or HostKey fields should be omitted or left empty. If you do not provide the required value when validation is enabled, credential validation will fail with a "mandatory field not found" error.