AWS amazon-mq: Reference RabbitMQ TLS certificate verification guidance
Summary
Adds a sentence noting that TLS clients are responsible for verifying the broker certificate, with a cross-reference to the RabbitMQ TLS certificate verification best-practices page.
Security assessment
A short cross-reference reminding users that TLS clients must verify the broker certificate, pointing to dedicated guidance; it documents a security responsibility but introduces no concrete vulnerability fix.
Evidence
+Clients that connect to a broker over TLS are responsible for verifying the broker certificate. For guidance, see [Best practices for TLS certificate verification in Amazon MQ for RabbitMQ](./verify-broker-certificate-rabbitmq.html).
Diff
diff --git a/amazon-mq/latest/developer-guide/best-practices-broker-setup.md b/amazon-mq/latest/developer-guide/best-practices-broker-setup.md index 8567d6df1..b40fd70a4 100644 --- a//amazon-mq/latest/developer-guide/best-practices-broker-setup.md +++ b//amazon-mq/latest/developer-guide/best-practices-broker-setup.md @@ -46,0 +47,2 @@ To avoid connection churn, use multiple channels over a single connection. Appli +Clients that connect to a broker over TLS are responsible for verifying the broker certificate. For guidance, see [Best practices for TLS certificate verification in Amazon MQ for RabbitMQ](./verify-broker-certificate-rabbitmq.html). +