AWS redshift: Add note recommending verify-full for SSL connections
Summary
Adds a Note to the Redshift SSL support page recommending that customers use `verify-full` for SSL connections whenever possible.
Security assessment
The added note steers users toward `verify-full`, which validates both the certificate chain and the hostname, mitigating man-in-the-middle attacks on Redshift SSL connections. It is general best-practice guidance rather than a fix for a named vulnerability or incident.
Evidence
+We recommend using `verify-full` for SSL connections whenever possible.
Diff
diff --git a/redshift/latest/mgmt/connecting-ssl-support.md b/redshift/latest/mgmt/connecting-ssl-support.md index 4061d3557..14173a070 100644 --- a//redshift/latest/mgmt/connecting-ssl-support.md +++ b//redshift/latest/mgmt/connecting-ssl-support.md @@ -18,0 +19,4 @@ To support SSL connections, Amazon Redshift creates and installs an [AWS Certifi +###### Note + +We recommend using `verify-full` for SSL connections whenever possible. +