AWS Security ChangesHomeSearch

AWS AmazonRDS: Clarified RDS Proxy lacks hybrid post-quantum TLS key exchange

Service: AmazonRDS · 2026-09-27 · Documentation low

File: AmazonRDS/latest/UserGuide/rds-proxy.howitworks.md · Type: encryption

Summary

Reworded the note in the RDS Proxy 'how it works' page to state that RDS Proxy currently does not support hybrid post-quantum named groups, so post-quantum key-exchange negotiation applies only to direct database connections, not proxy connections.

Security assessment

The change is a wording clarification of a TLS capability (post-quantum key exchange) limitation when connecting through RDS Proxy; it documents encryption behavior but fixes no vulnerability and adds no new security control.

Evidence

+RDS Proxy currently does not support hybrid post-quantum named groups. As a result, post-quantum key-exchange negotiation is not available for connections through RDS Proxy. It applies only to direct connections to your database. 

Diff

diff --git a/AmazonRDS/latest/UserGuide/rds-proxy.howitworks.md b/AmazonRDS/latest/UserGuide/rds-proxy.howitworks.md
index ba9714785..bc1dafe64 100644
--- a//AmazonRDS/latest/UserGuide/rds-proxy.howitworks.md
+++ b//AmazonRDS/latest/UserGuide/rds-proxy.howitworks.md
@@ -206 +206 @@ TLS 1.3 supports hybrid post-quantum key exchange through named groups. These na
-RDS Proxy does not currently support these hybrid post-quantum named groups. Post-quantum key-exchange negotiation applies only to direct connections to your database, not to connections through RDS Proxy. 
+RDS Proxy currently does not support hybrid post-quantum named groups. As a result, post-quantum key-exchange negotiation is not available for connections through RDS Proxy. It applies only to direct connections to your database.