AWS Security ChangesHomeSearch

AWS amazon-mq: Remove hostname_verification option from Amazon MQ mTLS docs

Service: amazon-mq · 2026-10-01 · Security-related medium

File: amazon-mq/latest/developer-guide/configure-mtls.md · Type: network

Summary

Deletes the documented `management.ssl.hostname_verification` configuration option (hostname verification mode with values `wildcard`/`none`) from the Amazon MQ for RabbitMQ mTLS configuration page.

Security assessment

Removing documentation of the hostname verification mode (which previously allowed `none`, i.e. disabling TLS hostname checks) eliminates guidance for weakening certificate hostname validation, reducing the risk of man-in-the-middle attacks against broker TLS connections.

Evidence

-`management.ssl.hostname_verification`

Diff

diff --git a/amazon-mq/latest/developer-guide/configure-mtls.md b/amazon-mq/latest/developer-guide/configure-mtls.md
index 281ccab..a8b2740 100644
--- a//amazon-mq/latest/developer-guide/configure-mtls.md
+++ b//amazon-mq/latest/developer-guide/configure-mtls.md
@@ -67,5 +66,0 @@ Maximum certificate chain depth for verification.
-`management.ssl.hostname_verification`
-    
-
-Hostname verification mode. Supported values: `wildcard`, `none`
-