AWS Security ChangesHomeSearch

AWS AmazonRDS: Add TLS key-exchange group (ssl_groups) docs for RDS PostgreSQL

Service: AmazonRDS · 2026-09-27 · Documentation high

File: AmazonRDS/latest/UserGuide/PostgreSQL.Concepts.General.SSL.md · Type: encryption

Summary

Adds a new section documenting the RDS for PostgreSQL `ssl_groups` parameter for TLS key exchange, including default and allowlisted values for PostgreSQL 18 (X25519MLKEM768, SecP256r1MLKEM768, X25519, prime256v1, secp384r1), ordering/server-preference behavior, interaction with TLS 1.2 RSA key exchange, and guidance to enforce TLS 1.3 and rds.force_ssl to restrict key exchange to the specified groups.

Security assessment

The added section documents a TLS/SSL encryption-related configuration parameter (`ssl_groups`) and post-quantum ML-KEM key-exchange groups, plus guidance to enforce TLS 1.3 and rds.force_ssl and to restrict ciphers to ECDHE suites. This is security hardening/best-practice documentation for encrypted database connections, but it does not reference or remediate any specific vulnerability, CVE, or incident.

Evidence

+The `ssl_groups` parameter specifies the named groups to use for TLS key exchange. For more information, see the [ssl_groups](https://www.postgresql.org/docs/current/runtime-config-connection.html#GUC-SSL-GROUPS) in the PostgreSQL documentation.

Diff

diff --git a/AmazonRDS/latest/UserGuide/PostgreSQL.Concepts.General.SSL.md b/AmazonRDS/latest/UserGuide/PostgreSQL.Concepts.General.SSL.md
index 5a6031200..cde897194 100644
--- a//AmazonRDS/latest/UserGuide/PostgreSQL.Concepts.General.SSL.md
+++ b//AmazonRDS/latest/UserGuide/PostgreSQL.Concepts.General.SSL.md
@@ -7 +7 @@
-Connecting to a PostgreSQL DB instance over SSLRequiring an SSL connection to a PostgreSQL DB instanceDetermining the SSL connection statusSSL cipher suites in RDS for PostgreSQL
+Connecting to a PostgreSQL DB instance over SSLRequiring an SSL connection to a PostgreSQL DB instanceDetermining the SSL connection statusSSL cipher suites in RDS for PostgreSQLTLS key-exchange groups in RDS for PostgreSQL
@@ -26,0 +27,2 @@ SSL support is available in all AWS Regions for PostgreSQL. Amazon RDS creates a
+  * TLS key-exchange groups in RDS for PostgreSQL
+
@@ -206,0 +209,25 @@ To ensure database connections use SSL, set the `rds.force_ssl parameter` to 1 i
+## TLS key-exchange groups in RDS for PostgreSQL
+
+The `ssl_groups` parameter specifies the named groups to use for TLS key exchange. For more information, see the [ssl_groups](https://www.postgresql.org/docs/current/runtime-config-connection.html#GUC-SSL-GROUPS) in the PostgreSQL documentation.
+
+In RDS for PostgreSQL 18 and later, you can modify the `ssl_groups` parameter to use specific values from the allowlisted groups. This is a dynamic parameter that doesn't require a reboot.
+
+The following table lists the default and allowlisted custom `ssl_groups` values by engine major version.
+
+PostgreSQL engine version | Default `ssl_groups` values | Allowlisted custom `ssl_groups` values  
+---|---|---  
+18 | `prime256v1:X25519` |  `X25519MLKEM768` `SecP256r1MLKEM768` `X25519` `prime256v1` `secp384r1`  
+  
+When you configure `ssl_groups`, keep the following behavior in mind:
+
+  * The order of the list sets the server preference. The first group in the list that the client also supports is used for a connection.
+
+  * `ssl_groups` applies only to key exchange that uses named groups. For example, `ssl_groups` is ignored by TLS v1.2 cipher suites that use RSA key exchange. To use only the specified groups, make sure that `rds.force_ssl` is enabled. Then either set `ssl_min_protocol_version` to `TLSv1.3`, or restrict `ssl_ciphers` to ECDHE-based suites for TLS v1.2-based connections.
+
+ML-KEM groups require TLS v1.3. To enforce that they are used, set `ssl_min_protocol_version` to `TLSv1.3`.
+
+
+
+
+For more information about modifying parameters and parameter groups, see [Parameter groups for Amazon RDS](./USER_WorkingWithParamGroups.html).
+