Medium
RDS
Regional
RDS DB proxies should require TLS encryption for connections
Description
Flags Amazon RDS DB proxies that do not require TLS for client connections. Without RequireTLS, traffic between the client and the proxy traverses the VPC unencrypted.
Remediation
Modify each DB proxy and enable RequireTLS.
Steps
- Open the Amazon RDS console and choose Proxies.
- Select the proxy and choose Edit.
- Enable Require Transport Layer Security (RequireTLS).
- Save the changes.