AWS Security ChangesHomeSearch

AWS redshift: Redshift: postpones TLS 1.2 minimum enforcement to Oct 31, 2026

Service: redshift · 2026-09-27 · Documentation medium

File: redshift/latest/mgmt/behavior-changes.md · Type: network

Summary

Updates Amazon Redshift behavior-change dates: SUPER large-string feature to Patch 206, ODBC 1.x end-of-support to December 31, 2026, and the minimum TLS version (1.2) enforcement start date from September 30, 2026 to October 31, 2026. All edits are scheduling/patch-version wording changes, not new security controls.

Security assessment

The only security-relevant content is a date-only change to the documented enforcement of minimum TLS 1.2 for incoming connections; it describes deprecation of TLS 1.0/1.1 (mitigating downgrade/interception risks) but no specific vulnerability or CVE is referenced. The remaining edits are patch-version and driver end-of-support date updates with no exploit or incident evidence.

Evidence

+Beginning October 31, 2026, Amazon Redshift will enforce a minimum Transport Layer Security (TLS) version of 1.2. Incoming connections that use TLS versions 1.0 or 1.1 will be rejected. This applies to both Amazon Redshift provisioned clusters and serverless workgroups. Amazon Redshift data warehouses not using TLS will not be affected by this change.

Diff

diff --git a/redshift/latest/mgmt/behavior-changes.md b/redshift/latest/mgmt/behavior-changes.md
index 4f67efafa..7c477b831 100644
--- a//redshift/latest/mgmt/behavior-changes.md
+++ b//redshift/latest/mgmt/behavior-changes.md
@@ -21 +21 @@ The following describes upcoming behavior changes.
-  * SUPER data type supports larger individual strings starting with Patch 205
+  * SUPER data type supports larger individual strings starting with Patch 206
@@ -33 +33 @@ The following describes upcoming behavior changes.
-  * End of support for the Amazon Redshift ODBC 1.x driver on September 30, 2026
+  * End of support for the Amazon Redshift ODBC 1.x driver on December 31, 2026
@@ -41 +41 @@ The following describes upcoming behavior changes.
-  * Minimum Transport Layer Security (TLS) version changes effective starting September 30, 2026
+  * Minimum Transport Layer Security (TLS) version changes effective starting October 31, 2026
@@ -48 +48 @@ The following describes upcoming behavior changes.
-### SUPER data type supports larger individual strings starting with Patch 205
+### SUPER data type supports larger individual strings starting with Patch 206
@@ -50 +50 @@ The following describes upcoming behavior changes.
-Starting with Patch 205, Amazon Redshift supports individual strings up to 16,000,000 bytes within the SUPER data type (used to store semistructured data). This limit also applies to in-memory string operations. To use this capability, create a database parameter group and set the `enable_large_strings_opt_in` parameter to `Yes`. Then, attach the parameter group to your data warehouse. For provisioned clusters, you must reboot the cluster to apply the parameter change.
+Starting with Patch 206, Amazon Redshift supports individual strings up to 16,000,000 bytes within the SUPER data type (used to store semistructured data). This limit also applies to in-memory string operations. To use this capability, create a database parameter group and set the `enable_large_strings_opt_in` parameter to `Yes`. Then, attach the parameter group to your data warehouse. For provisioned clusters, you must reboot the cluster to apply the parameter change.
@@ -164 +164 @@ For more information about patch versions, see [Cluster versions for Amazon Reds
-### End of support for the Amazon Redshift ODBC 1.x driver on September 30, 2026
+### End of support for the Amazon Redshift ODBC 1.x driver on December 31, 2026
@@ -166 +166 @@ For more information about patch versions, see [Cluster versions for Amazon Reds
-Beginning September 30, 2026, Amazon Redshift will discontinue support for the [ODBC 1.x driver](https://docs.aws.amazon.com/redshift/latest/mgmt/configure-odbc-connection.html). Based on customer feedback, we have extended the original end-of-support date from June 30, 2026 to September 30, 2026, to provide additional time for migration. This applies to both Amazon Redshift provisioned clusters and serverless workgroups.
+Beginning December 31, 2026, Amazon Redshift will discontinue support for the [ODBC 1.x driver](https://docs.aws.amazon.com/redshift/latest/mgmt/configure-odbc-connection.html). Based on customer feedback, we have extended the original end-of-support date from September 30, 2026 to December 31, 2026, to provide additional time for migration. This applies to both Amazon Redshift provisioned clusters and serverless workgroups.
@@ -181 +181 @@ You may be impacted by this if you use any version of the [ODBC 1.x driver](http
-To continue receiving technical support for your Amazon Redshift ODBC driver connections, please migrate to the latest [Amazon Redshift ODBC 2.x driver](https://docs.aws.amazon.com/redshift/latest/mgmt/odbc20-install.html) before September 29, 2026.
+To continue receiving technical support for your Amazon Redshift ODBC driver connections, please migrate to the latest [Amazon Redshift ODBC 2.x driver](https://docs.aws.amazon.com/redshift/latest/mgmt/odbc20-install.html) before December 30, 2026.
@@ -218 +218 @@ Starting February 16, 2026, Amazon Redshift will no longer support the usage of
-### Minimum Transport Layer Security (TLS) version changes effective starting September 30, 2026
+### Minimum Transport Layer Security (TLS) version changes effective starting October 31, 2026
@@ -220 +220 @@ Starting February 16, 2026, Amazon Redshift will no longer support the usage of
-Beginning September 30, 2026, Amazon Redshift will enforce a minimum Transport Layer Security (TLS) version of 1.2. Incoming connections that use TLS versions 1.0 or 1.1 will be rejected. This applies to both Amazon Redshift provisioned clusters and serverless workgroups. Amazon Redshift data warehouses not using TLS will not be affected by this change.
+Beginning October 31, 2026, Amazon Redshift will enforce a minimum Transport Layer Security (TLS) version of 1.2. Incoming connections that use TLS versions 1.0 or 1.1 will be rejected. This applies to both Amazon Redshift provisioned clusters and serverless workgroups. Amazon Redshift data warehouses not using TLS will not be affected by this change.