AWS Security ChangesHomeSearch

AWS redshift: Add Fetch/UseDeclareFetch ODBC options and SSL verify-full note

Service: redshift · 2026-09-27 · Documentation medium

File: redshift/latest/mgmt/odbc20-configuration-options.md · Type: encryption

Summary

Documents new ODBC driver options Fetch and UseDeclareFetch for batched result retrieval, rewrites the StreamingCursorRows description to clarify memory behavior and precedence, and adds a note recommending verify-full for SSL connections.

Security assessment

The bulk of the change documents performance/memory tuning options (Fetch, UseDeclareFetch, StreamingCursorRows) with no security impact, but the added note explicitly recommends the strongest TLS verification mode (verify-full), which prevents man-in-the-middle/certificate-spoofing on ODBC connections. This is security best-practice guidance rather than a fix for a specific vulnerability, so it is security documentation at medium severity.

Evidence

We recommend using `verify-full` for SSL connections whenever possible.

Diff

diff --git a/redshift/latest/mgmt/odbc20-configuration-options.md b/redshift/latest/mgmt/odbc20-configuration-options.md
index 4f38e68ce..8538a2d77 100644
--- a//redshift/latest/mgmt/odbc20-configuration-options.md
+++ b//redshift/latest/mgmt/odbc20-configuration-options.md
@@ -7 +7 @@
-AccessKeyIDapp_idApplicationNameapp_nameAuthProfileAuthTypeAutoCreateBoolsAsCharCaFileclient_idclient_ secretClusterIdcompressionDatabaseDatabaseMetadataCurrentDbOnlydbgroups_filterDriverDSNEnableTableTypesEndpointUrlForceLowercasegroup_federationhttps_proxy_hosthttps_proxy_passwordhttps_proxy_porthttps_proxy_usernameIAMidc_client_display_nameidc_regionidp_hostidp_portidp_response_timeoutidp_tenantidp_partitionidp_use_https_proxyInstanceProfileissuer_urlKeepAliveKeepAliveCountKeepAliveIntervalKeepAliveIdlelisten_portlogin_urlloginToRpLogLevelLogPathLoginTimeoutMaxLongVarcharSizeMaxVarcharSizeMin_TLSpartner_spidPassword | PWDplugin_namePort | PortNumberPrefer_PQpreferred_roleProfileprovider_nameProxyHostProxyPortProxyPwdProxyUidReadOnlyregionSecretAccessKeySessionTokenServer | HostName | Hostssl_insecureSSLModeStreamingCursorRowsStsConnectionTimeoutStsEndpointUrltokentoken_typeUID | User | LogonIDUseUnicodeweb_identity_token
+AccessKeyIDapp_idApplicationNameapp_nameAuthProfileAuthTypeAutoCreateBoolsAsCharCaFileclient_idclient_ secretClusterIdcompressionDatabaseDatabaseMetadataCurrentDbOnlydbgroups_filterDriverDSNEnableTableTypesEndpointUrlFetchForceLowercasegroup_federationhttps_proxy_hosthttps_proxy_passwordhttps_proxy_porthttps_proxy_usernameIAMidc_client_display_nameidc_regionidp_hostidp_portidp_response_timeoutidp_tenantidp_partitionidp_use_https_proxyInstanceProfileissuer_urlKeepAliveKeepAliveCountKeepAliveIntervalKeepAliveIdlelisten_portlogin_urlloginToRpLogLevelLogPathLoginTimeoutMaxLongVarcharSizeMaxVarcharSizeMin_TLSpartner_spidPassword | PWDplugin_namePort | PortNumberPrefer_PQpreferred_roleProfileprovider_nameProxyHostProxyPortProxyPwdProxyUidReadOnlyregionSecretAccessKeySessionTokenServer | HostName | Hostssl_insecureSSLModeStreamingCursorRowsStsConnectionTimeoutStsEndpointUrltokentoken_typeUID | User | LogonIDUseDeclareFetchUseUnicodeweb_identity_token
@@ -62,0 +63,2 @@ Following are descriptions for the options that you can specify for the Amazon R
+  * Fetch
+
@@ -172,0 +175,2 @@ Following are descriptions for the options that you can specify for the Amazon R
+  * UseDeclareFetch
+
@@ -505,0 +510,13 @@ This parameter is optional.
+## Fetch
+
+  * Default Value – 100
+
+  * Data Type – Integer
+
+
+
+
+When Declare/Fetch mode is enabled, this option controls how many rows the driver retrieves per round-trip, letting you tune the balance between memory use and network overhead for your workload. A larger value fetches more rows at once, reducing the number of round-trips to the server at the cost of higher memory per fetch. A smaller value lowers memory use but increases how often the driver goes back to the server. It sets the number of rows the driver returns at a time when `UseDeclareFetch` is enabled. For more information, see UseDeclareFetch.
+
+This parameter is optional.
+
@@ -1353,0 +1371,4 @@ The SSL certificate verification mode to use when connecting to Amazon Redshift.
+###### Note
+
+We recommend using `verify-full` for SSL connections whenever possible.
+
@@ -1365 +1386 @@ This parameter is optional.
-The number of rows the driver fetches per batch when using streaming cursor mode. When set to a positive integer and the cursor type is forward-only, the driver reads rows from the server in batches of the specified size instead of loading the entire result set into memory.
+Limits how many rows the driver holds in memory at one time for a forward-only cursor, so that large result sets don't have to load into memory all at once.
@@ -1369 +1390,3 @@ Set the property to one of the following values:
-  * 0: Disabled. The driver loads the entire result set into memory (default).
+  * 0: The driver loads the entire result set into memory before returning rows to the application (default). Very large result sets can consume a large amount of memory.
+
+  * Positive integer: For a forward-only cursor, the driver keeps only that many rows in memory at a time. It returns those rows to the application, releases them, and then fetches the next batch once the application has consumed the current one.
@@ -1371 +1393,0 @@ Set the property to one of the following values:
-  * Positive integer: The number of rows per streaming batch.
@@ -1374,0 +1397 @@ Set the property to one of the following values:
+This option has no effect on scrollable cursors, which always use the in-memory behavior. Note that on Windows, the Amazon Redshift ODBC Driver DSN Setup dialog pre-populates this field with a value of 100.
@@ -1380 +1403 @@ Streaming cursor mode requires a forward-only cursor. If the Client Side Cursor
-This option replaces the `UseDeclareFetch` and `Fetch` (Cache Size) options from ODBC driver version 1.x. Unlike the previous server-side cursor approach, streaming cursor mode does not require transaction wrapping or multiple server round-trips.
+`StreamingCursorRows` and `UseDeclareFetch` both batch results instead of loading the entire result set into memory. `UseDeclareFetch` uses a server-side cursor and generally delivers significantly higher throughput, so prefer it when fetch performance is your primary concern. `StreamingCursorRows` does not require transaction wrapping or a server-side cursor; choose it when those properties matter more than peak speed – a forward-only stream with a bounded memory footprint. If `UseDeclareFetch` is enabled, it takes priority and forces `StreamingCursorRows` to 0. For more information, see UseDeclareFetch.
@@ -1460,0 +1484,24 @@ This parameter is required if you use database authentication.
+## UseDeclareFetch
+
+  * Default Value – 0
+
+  * Data Type – Boolean
+
+
+
+
+When a query returns a result set too large to hold in memory, enabling this option lets the driver process it in fixed-size batches instead of buffering the entire result at once, keeping the client's memory footprint bounded and predictable regardless of how many rows the query returns. It is a boolean specifying whether the driver uses Declare/Fetch mode, returning a set number of rows at a time. To set the number of rows returned per batch, use the `Fetch` option. For more information, see Fetch.
+
+  * 1 | TRUE: The driver uses Declare/Fetch mode and returns the number of rows specified by the `Fetch` option at a time.
+
+  * 0 | FALSE: The driver returns the entire query result at once.
+
+
+
+
+This parameter is optional.
+
+###### Note
+
+If `UseDeclareFetch` is enabled, the driver disables streaming cursor mode and overrides `StreamingCursorRows` to 0, regardless of the value set in your DSN or connection string. For more information, see StreamingCursorRows.
+