AWS amazon-mq: Remove hostname_verification option from Amazon MQ mTLS docs
Summary
Deletes the documented `management.ssl.hostname_verification` configuration option (hostname verification mode with values `wildcard`/`none`) from the Amazon MQ for RabbitMQ mTLS configuration page.
Security assessment
Removing documentation of the hostname verification mode (which previously allowed `none`, i.e. disabling TLS hostname checks) eliminates guidance for weakening certificate hostname validation, reducing the risk of man-in-the-middle attacks against broker TLS connections.
Evidence
-`management.ssl.hostname_verification`
Diff
diff --git a/amazon-mq/latest/developer-guide/configure-mtls.md b/amazon-mq/latest/developer-guide/configure-mtls.md index 281ccab..a8b2740 100644 --- a//amazon-mq/latest/developer-guide/configure-mtls.md +++ b//amazon-mq/latest/developer-guide/configure-mtls.md @@ -67,5 +66,0 @@ Maximum certificate chain depth for verification. -`management.ssl.hostname_verification` - - -Hostname verification mode. Supported values: `wildcard`, `none` -