AWS Security ChangesHomeSearch

AWS AmazonRDS: Aurora MySQL: rename TLS key-exchange status variable to Aurora_ssl_named_group

Service: AmazonRDS · 2026-09-27 · Documentation medium

File: AmazonRDS/latest/AuroraMySQLReleaseNotes/AuroraMySQL.Updates.848.md · Type: encryption

Summary

In the Aurora MySQL 8.4.8 release notes, the documented status variable used to inspect the negotiated TLS 1.3 post-quantum hybrid key exchange group was corrected from `Ssl_named_group` to `Aurora_ssl_named_group`, including the accompanying `SHOW STATUS LIKE` example.

Security assessment

The edited line documents Aurora MySQL support for post-quantum hybrid key exchange (X25519MLKEM768, SecP256r1MLKEM768) for TLS 1.3 and fixes the status variable name used to verify the negotiated group (`Aurora_ssl_named_group`). It is security documentation for transport encryption/quantum resistance, but the change itself is only a documentation correction of a status variable name, with no evidence of a fixed vulnerability or CVE.

Evidence

  * Added support for post-quantum hybrid key exchange (X25519MLKEM768 and SecP256r1MLKEM768) for TLS 1.3 connections. Clients that support post-quantum key exchange negotiate a quantum-resistant shared secret automatically. To confirm which group the current session negotiated, query the `Aurora_ssl_named_group` status variable. For example: `SHOW STATUS LIKE 'Aurora_ssl_named_group';`.

Diff

diff --git a/AmazonRDS/latest/AuroraMySQLReleaseNotes/AuroraMySQL.Updates.848.md b/AmazonRDS/latest/AuroraMySQLReleaseNotes/AuroraMySQL.Updates.848.md
index 8ee53c039..3d32e614e 100644
--- a//AmazonRDS/latest/AuroraMySQLReleaseNotes/AuroraMySQL.Updates.848.md
+++ b//AmazonRDS/latest/AuroraMySQLReleaseNotes/AuroraMySQL.Updates.848.md
@@ -33 +33 @@ If you have any questions or concerns, AWS Support is available on the community
-  * Added support for post-quantum hybrid key exchange (X25519MLKEM768 and SecP256r1MLKEM768) for TLS 1.3 connections. Clients that support post-quantum key exchange negotiate a quantum-resistant shared secret automatically. To confirm which group the current session negotiated, query the `Ssl_named_group` status variable. For example: `SHOW STATUS LIKE 'Ssl_named_group';`.
+  * Added support for post-quantum hybrid key exchange (X25519MLKEM768 and SecP256r1MLKEM768) for TLS 1.3 connections. Clients that support post-quantum key exchange negotiate a quantum-resistant shared secret automatically. To confirm which group the current session negotiated, query the `Aurora_ssl_named_group` status variable. For example: `SHOW STATUS LIKE 'Aurora_ssl_named_group';`.