AWS IoT Core announces new certificate signing & key generation algorithms
Share
Services
Today, [AWS IoT Core](https://aws.amazon.com/iot-core/) announced the support for new algorithms for certificate signing and key generation, expanding the [list of already supported](https://docs.aws.amazon.com/iot/latest/developerguide/x509-client-certs.html#x509-cert-algorithms) asymmetric X.509 client certificate signature schemes. AWS IoT Core is a managed service that allows customers to connect billions of Internet of Things (IoT) devices to AWS and uses X.509 certificates as one of the means to authenticate client and device connections to AWS cloud. The support for Rivest Shamir Adleman Signature Scheme with Appendix based on the Probabilistic Signature Scheme (RSASSA-PSS) signing and P-521 elliptic curve key algorithms, provide developers more flexibility to strengthen the security posture of their IoT solutions and comply with organization’s specific cryptographic standard compliance requirements.
Using RSASSA-PSS, developers can now sign X.509 client certificates with the new signature scheme, or register their already signed client certificates and/or the corresponding certificate authorities (CA) with AWS IoT Core. Similarly, with P-521, AWS IoT Core is adding support for additional elliptic curve key algorithm, which enables developers to sign client certificates with CA’s that have P-521 keys, and register such client certificates and/or the corresponding CA’s.
The addition of RSASSA-PSS signing and P-521 key algorithms are offered at no additional charge beyond the standard [AWS IoT Core pricing](https://aws.amazon.com/iot-core/pricing/). The feature is generally available in [all commercial regions where AWS IoT Core is available](https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/). To get started, please refer to [technical documentation](https://docs.aws.amazon.com/iot/latest/developerguide/x509-client-certs.html).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share