AWS AmazonRDS: Clarified RDS Proxy lacks hybrid post-quantum TLS key exchange
Summary
Reworded the note in the RDS Proxy 'how it works' page to state that RDS Proxy currently does not support hybrid post-quantum named groups, so post-quantum key-exchange negotiation applies only to direct database connections, not proxy connections.
Security assessment
The change is a wording clarification of a TLS capability (post-quantum key exchange) limitation when connecting through RDS Proxy; it documents encryption behavior but fixes no vulnerability and adds no new security control.
Evidence
+RDS Proxy currently does not support hybrid post-quantum named groups. As a result, post-quantum key-exchange negotiation is not available for connections through RDS Proxy. It applies only to direct connections to your database.
Diff
diff --git a/AmazonRDS/latest/UserGuide/rds-proxy.howitworks.md b/AmazonRDS/latest/UserGuide/rds-proxy.howitworks.md index ba9714785..bc1dafe64 100644 --- a//AmazonRDS/latest/UserGuide/rds-proxy.howitworks.md +++ b//AmazonRDS/latest/UserGuide/rds-proxy.howitworks.md @@ -206 +206 @@ TLS 1.3 supports hybrid post-quantum key exchange through named groups. These na -RDS Proxy does not currently support these hybrid post-quantum named groups. Post-quantum key-exchange negotiation applies only to direct connections to your database, not to connections through RDS Proxy. +RDS Proxy currently does not support hybrid post-quantum named groups. As a result, post-quantum key-exchange negotiation is not available for connections through RDS Proxy. It applies only to direct connections to your database.