AWS redshift: Add verify-full SSL recommendation to JDBC config options
Summary
Adds a Note in the JDBC driver configuration options reference recommending `verify-full` for SSL connections whenever possible.
Security assessment
The note promotes the strongest JDBC SSL verification mode, which checks the server certificate and hostname and prevents MITM/spoofing of the Redshift endpoint. It is hardening guidance, not a response to a specific disclosed vulnerability.
Evidence
+We recommend using `verify-full` for SSL connections whenever possible.
Diff
diff --git a/redshift/latest/mgmt/jdbc20-configuration-options.md b/redshift/latest/mgmt/jdbc20-configuration-options.md index 2805b3629..5ad5c87b6 100644 --- a//redshift/latest/mgmt/jdbc20-configuration-options.md +++ b//redshift/latest/mgmt/jdbc20-configuration-options.md @@ -1487,0 +1488,4 @@ The driver verifies that the certificate comes from a trusted CA and that the ho +###### Note + +We recommend using `verify-full` for SSL connections whenever possible. +