AWS Security ChangesHomeSearch

AWS amazon-mq: Add guidance on validating Amazon MQ broker TLS certificates

Service: amazon-mq · 2026-09-27 · Documentation medium

File: amazon-mq/latest/developer-guide/data-protection.md · Type: encryption

Summary

Adds a new section to the Amazon MQ data protection page explaining how clients should validate the broker TLS server certificate: use the broker endpoint FQDN from DescribeBroker as the reference identifier, match it against dNSName entries in the certificate subjectAltName (SAN) extension per RFC 9525, and ignore the Common Name (CN). Includes an Important note warning against disabling certificate verification or pinning an individual certificate/subject because Amazon MQ rotates broker certificates, a Note about default library behavior, and a pointer to the broker TLS certificates page. The page's in-page security navigation entry is also renamed from 'Identity and access management' to 'Broker TLS certificates'.

Security assessment

The added text is prescriptive security guidance for TLS trust establishment (hostname/SAN verification, no CN-only matching, no disabled verification, no certificate pinning) rather than a response to a specific vulnerability, incident, or CVE, so security_issue_related is false while it clearly documents a security best practice. The content protects against man-in-the-middle/interception from improper certificate validation and against outage-prone pinning of rotating Amazon MQ broker certificates, making it security-adjacent hardening guidance of medium impact rather than a credential, authz, or data-exposure fix.

Evidence

+Do not disable certificate verification, and do not pin an individual broker certificate or a specific certificate subject. Amazon MQ rotates broker certificates, and the contents of the certificate subject can change. Clients that pin a certificate or a subject value might fail to connect after a certificate is rotated.

Diff

diff --git a/amazon-mq/latest/developer-guide/data-protection.md b/amazon-mq/latest/developer-guide/data-protection.md
index bd357fc41..91cb22baf 100644
--- a//amazon-mq/latest/developer-guide/data-protection.md
+++ b//amazon-mq/latest/developer-guide/data-protection.md
@@ -401,0 +402,30 @@ For more information about KMS keys, see [AWS KMS keys](https://docs.aws.amazon.
+### Validating the broker TLS server certificate
+
+Amazon MQ brokers present a server certificate that identifies the broker by its fully qualified domain name (FQDN). Your client is responsible for verifying this certificate when it establishes a TLS connection.
+
+**Example FQDN:**
+    
+    
+    b-1234a5b6-78cd-901e-2fgh-3i45j6k178l9.mq.ap-southeast-2.amazonaws.com
+
+We recommend that you configure your client to verify the broker certificate as described in [RFC 9525, Service Identity in TLS](https://www.rfc-editor.org/rfc/rfc9525.html). When your client connects to an Amazon MQ broker, it should do the following:
+
+  * **Use the broker endpoint FQDN as the reference identifier.** Use the FQDN from the broker endpoint returned by the `DescribeBroker` operation, or shown on the broker details page in the Amazon MQ console. Do not derive the identifier from an IP address or from a DNS alias of your own.
+
+  * **Verify the identifier against the`subjectAltName` extension.** Match the broker FQDN against the `dNSName` entries in the certificate `subjectAltName` (SAN) extension.
+
+  * **Do not use the Common Name (CN).** The CN does not identify the broker, and it cannot contain the broker FQDN. Clients that match only the CN, or that require a specific value in the CN, might fail to connect.
+
+
+
+
+###### Important
+
+Do not disable certificate verification, and do not pin an individual broker certificate or a specific certificate subject. Amazon MQ rotates broker certificates, and the contents of the certificate subject can change. Clients that pin a certificate or a subject value might fail to connect after a certificate is rotated.
+
+###### Note
+
+Most TLS client libraries verify the broker FQDN against the `subjectAltName` extension by default when you supply the broker endpoint host name. If your client overrides the verification hostname, or supplies its own verification callback, make sure that it uses the broker FQDN and matches against `subjectAltName`.
+
+For more information about Amazon MQ broker certificates, including the certificate types that Amazon MQ issues and annotated examples of each, see [Amazon MQ broker TLS certificates](./amazon-mq-certificates.html).
+
@@ -488 +518 @@ Security
-Identity and access management
+Broker TLS certificates