AWS Security ChangesHomeSearch

AWS AmazonRDS: Clarify RDS Proxy lacks hybrid post-quantum key exchange

Service: AmazonRDS · 2026-09-27 · Documentation medium

File: AmazonRDS/latest/AuroraUserGuide/rds-proxy.howitworks.md · Type: encryption

Summary

Rewords the statement so it says RDS Proxy currently does not support hybrid post-quantum named groups and that post-quantum key-exchange negotiation applies only to direct database connections, not through RDS Proxy.

Security assessment

Documents a TLS/cryptography limitation (no hybrid post-quantum key exchange via RDS Proxy) with clearer phrasing; it is a capability clarification rather than a fix for a specific vulnerability, though it is relevant to encryption posture for proxied connections.

Evidence

+RDS Proxy currently does not support hybrid post-quantum named groups. As a result, post-quantum key-exchange negotiation is not available for connections through RDS Proxy. It applies only to direct connections to your database. 

Diff

diff --git a/AmazonRDS/latest/AuroraUserGuide/rds-proxy.howitworks.md b/AmazonRDS/latest/AuroraUserGuide/rds-proxy.howitworks.md
index 3937c5951..565003c85 100644
--- a//AmazonRDS/latest/AuroraUserGuide/rds-proxy.howitworks.md
+++ b//AmazonRDS/latest/AuroraUserGuide/rds-proxy.howitworks.md
@@ -206 +206 @@ TLS 1.3 supports hybrid post-quantum key exchange through named groups. These na
-RDS Proxy does not currently support these hybrid post-quantum named groups. Post-quantum key-exchange negotiation applies only to direct connections to your database, not to connections through RDS Proxy. 
+RDS Proxy currently does not support hybrid post-quantum named groups. As a result, post-quantum key-exchange negotiation is not available for connections through RDS Proxy. It applies only to direct connections to your database.