Medium RDS Regional

RDS DB proxies should require TLS encryption for connections

Description

Flags Amazon RDS DB proxies that do not require TLS for client connections. Without RequireTLS, traffic between the client and the proxy traverses the VPC unencrypted.


Remediation

Modify each DB proxy and enable RequireTLS.

Steps

  1. Open the Amazon RDS console and choose Proxies.
  2. Select the proxy and choose Edit.
  3. Enable Require Transport Layer Security (RequireTLS).
  4. Save the changes.