AWS Secrets Manager now supports hybrid post-quantum key exchange using ML-KEM (Module-Lattice-based Key-Encapsulation Mechanism) to secure TLS connections for retrieving and managing secrets. This protection is automatically enabled in Secrets Manager Agent (version 2.0.0+), AWS Lambda Extension (version 19+), and Secrets Manager CSI Driver (version 2.0.0+). For SDK-based clients, hybrid post-quantum key exchange is available in supported AWS SDKs including Rust, Go, Node.js, Kotlin, Python (with OpenSSL 3.5+), and Java v2 (v2.35.11+).
With this launch, your applications retrieve secrets over TLS connections that combine classical key exchange with post-quantum cryptography, helping protect against both traditional cryptographic attacks and future quantum computing threats known as “harvest now, decrypt later” (HNDL). No code changes, configuration updates, or migration effort are required for customers using the latest client versions except for Java v2. For example, a microservice requiring multiple secrets at startup can now retrieve them over quantum-resistant TLS connections by simply upgrading to the latest Secrets Manager Agent version. You can verify hybrid post-quantum key exchange is active by checking CloudTrail logs for the “X25519MLKEM768” key exchange algorithm in the tlsDetails field of GetSecretValue API calls.
Hybrid post-quantum key exchange using ML-KEM for AWS Secrets Manager is available in all AWS Regions where AWS Secrets Manager is supported. To learn more, visit the AWS Secrets Manager documentation and the AWS Post-Quantum Cryptography migration page.
Categories: general:products/aws-secrets-manager
Source: Amazon Web Services
Latest Posts
- Microsoft Copilot Studio – Use MCP-compliant tools in agent workflows [MC1301505]
![Microsoft Copilot Studio - Use MCP-compliant tools in agent workflows [MC1301505] 2 pexels brunocortes1969 29367732](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Dynamics 365 Supply Chain Management – Enable precise serial and batch capture in cluster picking [MC1301473]
![Dynamics 365 Supply Chain Management - Enable precise serial and batch capture in cluster picking [MC1301473] 3 pexels steve 26628057](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Dynamics 365 Commerce – Enable associates to use the nearest store payment terminal [MC1301477]
![Dynamics 365 Commerce - Enable associates to use the nearest store payment terminal [MC1301477] 4 pexels apasaric 325185](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Dynamics 365 Commerce – Display distance in kilometers on the Store Commerce app [MC1301490]
![Dynamics 365 Commerce - Display distance in kilometers on the Store Commerce app [MC1301490] 5 pexels cantuariabruno 774448](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Microsoft Copilot Studio - Use MCP-compliant tools in agent workflows [MC1301505] 2 pexels brunocortes1969 29367732](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-brunocortes1969-29367732-150x150.webp)
![Dynamics 365 Supply Chain Management - Enable precise serial and batch capture in cluster picking [MC1301473] 3 pexels steve 26628057](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-steve-26628057-150x150.webp)
![Dynamics 365 Commerce - Enable associates to use the nearest store payment terminal [MC1301477] 4 pexels apasaric 325185](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-apasaric-325185-150x150.webp)
![Dynamics 365 Commerce - Display distance in kilometers on the Store Commerce app [MC1301490] 5 pexels cantuariabruno 774448](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-cantuariabruno-774448-150x150.webp)
