AWS Security ChangesHomeSearch

AWS mgn: Correct PKCS#8 client key conversion commands for FSx ONTAP

Service: mgn · 2026-09-27 · Documentation low

File: mgn/latest/ug/fsx-ontap-generate-certs.md · Type: encryption

Summary

Updated both the scripted and step-by-step instructions to convert the client key to PKCS#8 using a temporary .pk8 output file and then move it back over the original key.

Security assessment

Change fixes the key-format conversion procedure so the client private key is properly converted to PKCS#8 (required for certificate-based auth to FSx for ONTAP), avoiding an in-place conversion that fails; it is credential/key-material handling guidance, not a response to a specific vulnerability.

Evidence

      -in fsx-mgn-client.key -out fsx-mgn-client.key.pk8

Diff

diff --git a/mgn/latest/ug/fsx-ontap-generate-certs.md b/mgn/latest/ug/fsx-ontap-generate-certs.md
index 2b745164c..4bdff05de 100644
--- a//mgn/latest/ug/fsx-ontap-generate-certs.md
+++ b//mgn/latest/ug/fsx-ontap-generate-certs.md
@@ -69 +69,2 @@ To generate a self-signed CA and client certificate, save the following script a
-      -in fsx-mgn-client.key -out fsx-mgn-client.key
+      -in fsx-mgn-client.key -out fsx-mgn-client.key.pk8
+    mv fsx-mgn-client.key.pk8 fsx-mgn-client.key
@@ -145 +146,2 @@ If you prefer to run each step individually:
-      -in fsx-mgn-client.key -out fsx-mgn-client.key
+      -in fsx-mgn-client.key -out fsx-mgn-client.key.pk8
+    [~]$ mv fsx-mgn-client.key.pk8 fsx-mgn-client.key