AWS AmazonRDS: Add TLS key-exchange group (ssl_groups) docs for RDS PostgreSQL
Summary
Adds a new section documenting the RDS for PostgreSQL `ssl_groups` parameter for TLS key exchange, including default and allowlisted values for PostgreSQL 18 (X25519MLKEM768, SecP256r1MLKEM768, X25519, prime256v1, secp384r1), ordering/server-preference behavior, interaction with TLS 1.2 RSA key exchange, and guidance to enforce TLS 1.3 and rds.force_ssl to restrict key exchange to the specified groups.
Security assessment
The added section documents a TLS/SSL encryption-related configuration parameter (`ssl_groups`) and post-quantum ML-KEM key-exchange groups, plus guidance to enforce TLS 1.3 and rds.force_ssl and to restrict ciphers to ECDHE suites. This is security hardening/best-practice documentation for encrypted database connections, but it does not reference or remediate any specific vulnerability, CVE, or incident.
Evidence
+The `ssl_groups` parameter specifies the named groups to use for TLS key exchange. For more information, see the [ssl_groups](https://www.postgresql.org/docs/current/runtime-config-connection.html#GUC-SSL-GROUPS) in the PostgreSQL documentation.
Diff
diff --git a/AmazonRDS/latest/UserGuide/PostgreSQL.Concepts.General.SSL.md b/AmazonRDS/latest/UserGuide/PostgreSQL.Concepts.General.SSL.md index 5a6031200..cde897194 100644 --- a//AmazonRDS/latest/UserGuide/PostgreSQL.Concepts.General.SSL.md +++ b//AmazonRDS/latest/UserGuide/PostgreSQL.Concepts.General.SSL.md @@ -7 +7 @@ -Connecting to a PostgreSQL DB instance over SSLRequiring an SSL connection to a PostgreSQL DB instanceDetermining the SSL connection statusSSL cipher suites in RDS for PostgreSQL +Connecting to a PostgreSQL DB instance over SSLRequiring an SSL connection to a PostgreSQL DB instanceDetermining the SSL connection statusSSL cipher suites in RDS for PostgreSQLTLS key-exchange groups in RDS for PostgreSQL @@ -26,0 +27,2 @@ SSL support is available in all AWS Regions for PostgreSQL. Amazon RDS creates a + * TLS key-exchange groups in RDS for PostgreSQL + @@ -206,0 +209,25 @@ To ensure database connections use SSL, set the `rds.force_ssl parameter` to 1 i +## TLS key-exchange groups in RDS for PostgreSQL + +The `ssl_groups` parameter specifies the named groups to use for TLS key exchange. For more information, see the [ssl_groups](https://www.postgresql.org/docs/current/runtime-config-connection.html#GUC-SSL-GROUPS) in the PostgreSQL documentation. + +In RDS for PostgreSQL 18 and later, you can modify the `ssl_groups` parameter to use specific values from the allowlisted groups. This is a dynamic parameter that doesn't require a reboot. + +The following table lists the default and allowlisted custom `ssl_groups` values by engine major version. + +PostgreSQL engine version | Default `ssl_groups` values | Allowlisted custom `ssl_groups` values +---|---|--- +18 | `prime256v1:X25519` | `X25519MLKEM768` `SecP256r1MLKEM768` `X25519` `prime256v1` `secp384r1` + +When you configure `ssl_groups`, keep the following behavior in mind: + + * The order of the list sets the server preference. The first group in the list that the client also supports is used for a connection. + + * `ssl_groups` applies only to key exchange that uses named groups. For example, `ssl_groups` is ignored by TLS v1.2 cipher suites that use RSA key exchange. To use only the specified groups, make sure that `rds.force_ssl` is enabled. Then either set `ssl_min_protocol_version` to `TLSv1.3`, or restrict `ssl_ciphers` to ECDHE-based suites for TLS v1.2-based connections. + +ML-KEM groups require TLS v1.3. To enforce that they are used, set `ssl_min_protocol_version` to `TLSv1.3`. + + + + +For more information about modifying parameters and parameter groups, see [Parameter groups for Amazon RDS](./USER_WorkingWithParamGroups.html). +