AWS Security ChangesHomeSearch

AWS res: Release notes 2025.12: S3 TLS/logging, IAM, Cognito perms fixes

Service: res · 2026-09-29 · Security-related high

File: res/archive/release-minus-3/ug/revisions.md · Type: authz

Summary

Adds the December 2025 (release 2025.12) revision entry documenting security-relevant enhancements and fixes: S3 bucket access logging, SSL/TLS required on all S3 communications, DynamoDB point-in-time recovery, root-only /opt/cognito_auth permissions, AD-join disable option, and a fix for users bypassing allowed instance types.

Security assessment

The entry documents concrete weaknesses that were remediated: an overly permissive directory (/opt/cognito_auth) tightened to root-only, enforcement of TLS on S3 bucket communications plus S3 access logging for audit, DynamoDB point-in-time recovery, and a fix for users manually bypassing allowed instance types (a policy/authorization bypass). These are specific security controls and fixes, not generic guidance.

Evidence

+    * Updated permissions of /opt/cognito_auth directory to root-only access.

Diff

diff --git a/res/archive/release-minus-3/ug/revisions.md b/res/archive/release-minus-3/ug/revisions.md
index 80a34b9cc..0727e6876 100644
--- a//res/archive/release-minus-3/ug/revisions.md
+++ b//res/archive/release-minus-3/ug/revisions.md
@@ -12,0 +13,24 @@ Date | Change
+December 2025 | 
+
+  * Release version 2025.12 Enhancements
+    * Propagation of custom CloudFormation tags to all RES components during deployment.
+    * Allow administrators to disable Active Directory joining for Windows hosts.
+    * Enable administrators to set default schedules for VDI desktop instances.
+    * S3 bucket access logging enabled for compliance and audit requirements.
+    * SSL/TLS encryption required on all S3 bucket communications.
+    * Enabled point-in-time recovery for RES managed DynamoDB tables.
+    * Updated permissions of /opt/cognito_auth directory to root-only access.
+Changes
+    * Migrated VDC-related APIs out of the VDC EC2 host to the backend Lambda.
+Bug Fixes
+    * Refreshing Allowed Instance Types when launching a new VDI.
+    * Fixed missing dependencies for efs_utils.
+    * Fixed cost dashboard total number of sessions in RES portal.
+    * Fixed issue where users could manually bypass the allowed instance types.
+    * Addressed race condition that could block DCV connection for Linux VDIs.
+    * Added missing operating systems from Software Stack page OS drop-down menu.
+    * Fixed frequent logout issue when using custom domain with Chrome.
+    * Fixed issue where the runtime SSSD configurations are not applied after disabling AD join.
+    * Fixed RES environment deletion failure caused by remaining VDI role.
+
+