AWS Security ChangesHomeSearch

AWS mgn: FSx ONTAP cert auth scope and PKCS#8 key conversion update

Service: mgn · 2026-09-27 · Documentation low

File: mgn/latest/ug/fsx-ontap.md · Type: encryption

Summary

Removed 'and iSCSI targets' from the statement that certificate-based authentication is required, and updated the key conversion command to output a .pk8 file then move it into place.

Security assessment

Clarifies where certificate-based authentication/TLS validation applies (ONTAP REST API only, not iSCSI) and corrects the PKCS#8 key conversion step; it is authentication/key-handling documentation accuracy, not a vulnerability fix.

Evidence

**Certificate-based authentication is required for MGN to access the ONTAP REST API.** MGN handles TLS validation internally using AWS Certificate Authorities.

Diff

diff --git a/mgn/latest/ug/fsx-ontap.md b/mgn/latest/ug/fsx-ontap.md
index b8981009c..a49563f05 100644
--- a//mgn/latest/ug/fsx-ontap.md
+++ b//mgn/latest/ug/fsx-ontap.md
@@ -198 +198 @@ For detailed instructions on creating and configuring FSx for ONTAP file systems
-**Certificate-based authentication is required for MGN to access the ONTAP REST API and iSCSI targets.** MGN handles TLS validation internally using AWS Certificate Authorities.
+**Certificate-based authentication is required for MGN to access the ONTAP REST API.** MGN handles TLS validation internally using AWS Certificate Authorities.
@@ -220 +220,2 @@ The private key must be in PKCS#8 format (`-----BEGIN PRIVATE KEY-----`). If you
-      -in fsx-mgn-client.key -out fsx-mgn-client.key
+      -in fsx-mgn-client.key -out fsx-mgn-client.key.pk8
+    [~]$ mv fsx-mgn-client.key.pk8 fsx-mgn-client.key