AWS iot-sitewise: Document FIPS 140-3 endpoints for IoT SiteWise VPC endpoints
Summary
Adds guidance on using FIPS 140-3 validated cryptographic module endpoints (data and control plane) through interface VPC endpoints, including how to enable FIPS via AWS_USE_FIPS_ENDPOINT.
Security assessment
Documents FIPS 140-3 compliant endpoints and how to enable them, which is security best-practice guidance for cryptographic compliance; no specific vulnerability or incident is referenced.
Evidence
If you require FIPS 140-3 validated cryptographic modules when you access AWS IoT SiteWise through the interface VPC endpoint, use the following FIPS endpoints instead.
Diff
diff --git a/iot-sitewise/latest/userguide/vpc-endpoint-access.md b/iot-sitewise/latest/userguide/vpc-endpoint-access.md index ee3bf6e98..2080a1fef 100644 --- a//iot-sitewise/latest/userguide/vpc-endpoint-access.md +++ b//iot-sitewise/latest/userguide/vpc-endpoint-access.md @@ -23,0 +24,15 @@ _If you enable private DNS for the endpoint_ , you can make API requests to AWS +If you require FIPS 140-3 validated cryptographic modules when you access AWS IoT SiteWise through the interface VPC endpoint, use the following FIPS endpoints instead. The FIPS endpoints are available through the same interface VPC endpoints with private DNS enabled, in the AWS Regions where AWS IoT SiteWise supports FIPS endpoints. For the list of AWS IoT SiteWise FIPS endpoints, see [AWS IoT SiteWise endpoints and quotas](https://docs.aws.amazon.com/general/latest/gr/iot-sitewise.html) in the _AWS General Reference Guide_. + + * For the **data plane** API operations, use the following FIPS endpoint. Replace `region` with your AWS Region. + + data.iotsitewise-fips.region.amazonaws.com + + * For the **control plane** API operations, use the following FIPS endpoint. Replace `region` with your AWS Region. + + api.iotsitewise-fips.region.amazonaws.com + + + + +To use the FIPS endpoints with the AWS CLI and AWS SDKs, you can specify the FIPS endpoint hostname directly, or you can enable the FIPS endpoint configuration option instead. For example, set the `AWS_USE_FIPS_ENDPOINT` environment variable to `true`, or use the equivalent option for your SDK. For more information, see [Dual-stack and FIPS endpoints](https://docs.aws.amazon.com/sdkref/latest/guide/feature-endpoints.html) in the _AWS SDKs and Tools Reference Guide_. +