AWS Security ChangesHomeSearch

AWS apigateway: Add TLS_1_2 security policy cipher suite details

Service: apigateway · 2026-09-27 · Documentation medium

File: apigateway/latest/developerguide/apigateway-security-policies-list.md · Type: encryption

Summary

Adds a new entry for the TLS_1_2 security policy (edge-optimized custom domain names only) listing supported TLS 1.3 and TLS 1.2 cipher suites.

Security assessment

Documents the cipher suites supported by a TLS security policy, which is security-relevant configuration guidance for transport encryption, but it does not fix a specific vulnerability.

Evidence

+TLS_1_2 (edge-optimized custom domain names only) |  TLS1.3 TLS1.2 | 

Diff

diff --git a/apigateway/latest/developerguide/apigateway-security-policies-list.md b/apigateway/latest/developerguide/apigateway-security-policies-list.md
index fa0006f3a..f9c11e7a4 100644
--- a//apigateway/latest/developerguide/apigateway-security-policies-list.md
+++ b//apigateway/latest/developerguide/apigateway-security-policies-list.md
@@ -263,0 +264,27 @@ SecurityPolicy_TLS12_2018_EDGE |  TLS1.3 TLS1.2 |
+TLS_1_2 (edge-optimized custom domain names only) |  TLS1.3 TLS1.2 | 
+
+###### TLS1.3
+
+  * TLS_AES_128_GCM_SHA256
+  * TLS_AES_256_GCM_SHA384
+  * TLS_CHACHA20_POLY1305_SHA256
+
+
+
+###### TLS1.2
+
+  * ECDHE-ECDSA-AES128-GCM-SHA256
+  * ECDHE-ECDSA-AES128-SHA256
+  * ECDHE-ECDSA-AES256-GCM-SHA384
+  * ECDHE-ECDSA-CHACHA20-POLY1305
+  * ECDHE-ECDSA-AES256-SHA384
+  * ECDHE-RSA-AES128-GCM-SHA256
+  * ECDHE-RSA-AES128-SHA256
+  * ECDHE-RSA-AES256-GCM-SHA384
+  * ECDHE-RSA-CHACHA20-POLY1305
+  * ECDHE-RSA-AES256-SHA384
+  * AES128-GCM-SHA256
+  * AES256-GCM-SHA384
+  * AES128-SHA256
+
+