AWS res: Release notes 2025.12: S3 TLS/logging, IAM, Cognito perms fixes
Summary
Adds the December 2025 (release 2025.12) revision entry documenting security-relevant enhancements and fixes: S3 bucket access logging, SSL/TLS required on all S3 communications, DynamoDB point-in-time recovery, root-only /opt/cognito_auth permissions, AD-join disable option, and a fix for users bypassing allowed instance types.
Security assessment
The entry documents concrete weaknesses that were remediated: an overly permissive directory (/opt/cognito_auth) tightened to root-only, enforcement of TLS on S3 bucket communications plus S3 access logging for audit, DynamoDB point-in-time recovery, and a fix for users manually bypassing allowed instance types (a policy/authorization bypass). These are specific security controls and fixes, not generic guidance.
Evidence
+ * Updated permissions of /opt/cognito_auth directory to root-only access.
Diff
diff --git a/res/archive/release-minus-3/ug/revisions.md b/res/archive/release-minus-3/ug/revisions.md index 80a34b9cc..0727e6876 100644 --- a//res/archive/release-minus-3/ug/revisions.md +++ b//res/archive/release-minus-3/ug/revisions.md @@ -12,0 +13,24 @@ Date | Change +December 2025 | + + * Release version 2025.12 Enhancements + * Propagation of custom CloudFormation tags to all RES components during deployment. + * Allow administrators to disable Active Directory joining for Windows hosts. + * Enable administrators to set default schedules for VDI desktop instances. + * S3 bucket access logging enabled for compliance and audit requirements. + * SSL/TLS encryption required on all S3 bucket communications. + * Enabled point-in-time recovery for RES managed DynamoDB tables. + * Updated permissions of /opt/cognito_auth directory to root-only access. +Changes + * Migrated VDC-related APIs out of the VDC EC2 host to the backend Lambda. +Bug Fixes + * Refreshing Allowed Instance Types when launching a new VDI. + * Fixed missing dependencies for efs_utils. + * Fixed cost dashboard total number of sessions in RES portal. + * Fixed issue where users could manually bypass the allowed instance types. + * Addressed race condition that could block DCV connection for Linux VDIs. + * Added missing operating systems from Software Stack page OS drop-down menu. + * Fixed frequent logout issue when using custom domain with Chrome. + * Fixed issue where the runtime SSSD configurations are not applied after disabling AD join. + * Fixed RES environment deletion failure caused by remaining VDI role. + +