Home icon

Enhance security and performance with TLS 1.3 and Perfect Forward Secrecy on Amazon OpenSearch Service

Big Data Blog



Amazon OpenSearch Service has introduced a new TLS security policy (Policy-Min-TLS-1-2-PFS-2023-10) that enhances security and performance for domain endpoint communications.

  • Supports latest TLS 1.3 protocol and TLS 1.2 with Perfect Forward Secrecy (PFS)
  • Provides stronger encryption and protection against potential key compromises
  • Enables faster connection times with reduced latency
  • Can be enabled for new domains using AWS CLI with specific configuration options
  • Existing domains can update their TLS policy through domain configuration updates

The new policy offers significant improvements in data security and connection performance, recommended for all OpenSearch Service domains.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Apr 30
2026
Amazon OpenSearch Service now supports index-level encryption
Jun 25
2025
Implement secure hybrid and multicloud log ingestion with Amazon OpenSearch Ingestion
Apr 30
2025
Amazon OpenSearch Service now supports OpenSearch version 2.19
Jul 25
2025
Trusted identity propagation using IAM Identity Center for Amazon OpenSearch Service

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.