AWS Secrets Manager connections now support the latest hybrid post-quantum TLS with Kyber
Share
Services
Connections to [AWS Secrets Manager](/secrets-manager/) now support hybrid post-quantum key establishment using Kyber for transport layer security (TLS) from [Round 3](https://csrc.nist.gov/Projects/post-quantum-cryptography/post-quantum-cryptography-standardization/round-3-submissions) of the NIST Post-Quantum Cryptography (PQC) selection process. This allows you to measure the potential performance impact of the post-quantum algorithm. You can also benefit from the longer-term confidentiality afforded by hybrid post-quantum TLS.
Hybrid post-quantum TLS combines a classical key agreement, such as ECDHE, with a post-quantum key encapsulation mechanism, in this case Kyber, which [NIST has selected for future standardization](https://www.nist.gov/news-events/news/2022/07/pqc-standardization-process-announcing-four-candidates-be-standardized-plus). The result is that your TLS connections inherit the security properties of both the classical and post-quantum key exchanges.
Hybrid post-quantum TLS for connecting to AWS Secrets Manager is available in all AWS Regions except for AWS GovCloud (US), AWS China (Beijing) region, operated by Sinnet, and AWS China (Ningxia) region, operated by NWCD. This hybrid post-quantum TLS cipher performs an additional post-quantum key exchange during the TLS handshake while connecting to Secrets Manager API endpoints.
For more information about hybrid post-quantum TLS support, read the [documentation](https://docs.aws.amazon.com/secretsmanager/latest/userguide/data-protection.html). Learn more about what Amazon is doing to prepare for a post-quantum cryptographic future on the [Amazon Science Blog](https://www.amazon.science/blog/preparing-today-for-a-post-quantum-cryptographic-future).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share