Publicado el Deja un comentario

AWS Direct Connect announces 100G expansion in Auckland, New Zealand

Today, AWS announced the expansion of 100 Gbps dedicated connections at the existing AWS Direct Connect location in the Datacom Orbit DH6 data center near Auckland, New Zealand. You can now establish private, direct network access to all public AWS Regions (except those in China), AWS GovCloud Regions, and AWS Local Zones from this location. This is the second AWS Direct Connect location in New Zealand to provide 100 Gbps connections with MACsec encryption capabilities.

The Direct Connect service enables you to establish a private, physical network connection between AWS and your data center, office, or colocation environment. These private connections can provide a more consistent network experience than those made over the public internet.

For more information on the over 150 Direct Connect locations worldwide, visit the locations section of the Direct Connect product detail pages. Or, visit our getting started page to learn more about how to purchase and deploy Direct Connect.

 

​Today, AWS announced the expansion of 100 Gbps dedicated connections at the existing AWS Direct Connect location in the Datacom Orbit DH6 data center near Auckland, New Zealand. You can now establish private, direct network access to all public AWS Regions (except those in China), AWS GovCloud Regions, and AWS Local Zones from this location. This is the second AWS Direct Connect location in New Zealand to provide 100 Gbps connections with MACsec encryption capabilities.
The Direct Connect service enables you to establish a private, physical network connection between AWS and your data center, office, or colocation environment. These private connections can provide a more consistent network experience than those made over the public internet.
For more information on the over 150 Direct Connect locations worldwide, visit the locations section of the Direct Connect product detail pages. Or, visit our getting started page to learn more about how to purchase and deploy Direct Connect.  

Publicado el Deja un comentario

Amazon CloudWatch expands auto-enablement to Amazon CloudFront logs and 3 additional resource types

Amazon CloudWatch now supports automatic enablement of Amazon CloudFront Standard access logs, AWS Security Hub CSPM finding logs, and Amazon Bedrock AgentCore memory and gateway logs and traces to CloudWatch Logs. Customers can set up enablement rules that automatically configure telemetry for both existing and newly created resources, ensuring consistent monitoring coverage without manual setup.

Enablement rules can be scoped to the organization, specific accounts, or specific resources based on resource tags to standardize telemetry collection. For example, a central security team can create a single rule to automatically send CloudFront access logs and Security Hub findings for all resources across their organization to CloudWatch Logs.

CloudWatch’s auto-enablement capability is available in all AWS commercial regions. Log ingestion will be billed according to CloudWatch Pricing.

Amazon CloudFront access logs and AWS Security Hub CSPM findings support organization-wide enablement rules. Bedrock AgentCore memory and gateway telemetry support account-level enablement rules. To learn more about enablement rules in Amazon CloudWatch, visit the Amazon CloudWatch documentation.

 

​Amazon CloudWatch now supports automatic enablement of Amazon CloudFront Standard access logs, AWS Security Hub CSPM finding logs, and Amazon Bedrock AgentCore memory and gateway logs and traces to CloudWatch Logs. Customers can set up enablement rules that automatically configure telemetry for both existing and newly created resources, ensuring consistent monitoring coverage without manual setup.
Enablement rules can be scoped to the organization, specific accounts, or specific resources based on resource tags to standardize telemetry collection. For example, a central security team can create a single rule to automatically send CloudFront access logs and Security Hub findings for all resources across their organization to CloudWatch Logs.
CloudWatch’s auto-enablement capability is available in all AWS commercial regions. Log ingestion will be billed according to CloudWatch Pricing.
Amazon CloudFront access logs and AWS Security Hub CSPM findings support organization-wide enablement rules. Bedrock AgentCore memory and gateway telemetry support account-level enablement rules. To learn more about enablement rules in Amazon CloudWatch, visit the Amazon CloudWatch documentation.  

Publicado el Deja un comentario

3 nuevos modelos MAI de clase mundial ya disponibles en Foundry

3 nuevos modelos MAI de clase mundial ya disponibles en Foundry

Imagen con el texto: Image-2, Transcribe-1, Voice-1, sobre un fondo color crema y diferentes imágenes alrededor del texto

Por: Mustafa Suleyman.

Presentamos MAI-Transcribe-1, junto a MAI-Voice-1 y MAI-Image-2. Calidad de clase mundial a velocidades relámpago, ahora disponibles a los precios más competitivos.

Disponibles ahora en Microsoft Foundry y MAI Playground.

MAI-Transcribe-1 ofrece transcripción de voz a texto de última generación en los 25 idiomas más utilizados1, según el estándar industrial de FLEURS.2 Diseñado para ofrecer calidad de clase mundial en entornos reales y desordenados, su velocidad de transcripción por lotes es 2,5 veces superior a la de Microsoft Azure Fast que ya ofrece. Además, es muy eficiente, lo que hace que MAI-Transcribe-1 no solo sea el más preciso, sino también ultrarrápido. Ahora está disponible en Foundry con el mejor precio de cualquier proveedor de nube grande.

Gráfico de barras con la tasa de error por palabra en lenguajes de modelos

MAI-Voice-1 es nuestro modelo de generación de voz de primera gama. Construido para generar un habla natural y realista, rica en matices, rango emocional y expresión que preserva la identidad del hablante incluso en contenido de formato largo.

Hoy añadimos la capacidad de crear su propia voz personalizada de manera segura y protegida en Microsoft Foundry con solo unos segundos de audio. MAI-Voice-1 puede transformar la facilidad con la que los desarrolladores pueden crear experiencias y agentes de voz, con alta calidad y alta velocidad.

El modelo puede generar 60 segundos de audio en solo un segundo, y un uso muy eficiente de la GPU ofrece esa calidad y velocidad de forma asequible. Oír es creer, así que vívanlo por ustedes mismos con Copilot Audio Expressions o Copilot Podcasts.

MAI-Image-2 tiene un rendimiento y velocidad turbo en generación de imágenes en Copilot tras debutar como una de las 3 familias de modelos más destacadas en la clasificación de Arena.ai. Los usuarios experimentan tiempos de generación al menos el doble de rápidos en Foundry y Copilot con una calidad similar, basándose en datos reales de tráfico de producción. También se llevaban a cabo despliegues faseados en Bing y PowerPoint.

MAI-Image-2 fue creado con fotógrafos, diseñadores y narradores visuales que exigen luz natural, tonos y texturas de piel precisos, y texto claro dentro de la imagen para diagramas, maquetaciones y gráficos. Una vez más, la velocidad y la calidad no tienen costes elevados: MAI-Image-2 se ofrece a un precio competitivo por desempeño.

Los clientes ya han comenzado a adoptar MAI-Image-2 para trabajos creativos. WPP, uno de los mayores grupos de marketing y comunicación del mundo, es uno de los primeros socios empresariales que construyen a gran escala con MAI-Image-2.

«MAI-Imagen-2 es un verdadero cambio de juego. Es una plataforma que no solo responde a la compleja sutileza de la dirección creativa, sino que respeta a profundidad la pura destreza que implica generar imágenes reales listas para la campaña», dijo Rob Reilly, director creativo global de WPP. «WPP tiene algunos de los mejores talentos creativos del mundo y MAI-Image-2 los hace aún mejores.»

Modelos MAI: Mejores, más rápidos y más baratos que nuestros competidores.

Desplegamos estos modelos de primera gama con rapidez, para alimentar nuestros propios productos de consumo y comerciales. Estamos entusiasmados de compartir las mejoras en calidad, velocidad y eficiencia con nuestros clientes de Microsoft Foundry con precios muy competitivos.

· MAI-Transcribe-1 empieza en 0,36 dólares la hora.

· MAI-Voz-1 empieza en 22 dólares por cada 1 millón de caracteres.

· MAI-Image-2 comienza en 5 dólares por cada 1 millón de tokens para entrada de texto y 33 dólares por 1 millón de tokens para la salida de imagen.

Disponible ya en Microsoft Foundry y MAI Playground.

A partir de hoy, cualquier desarrollador puede construir con modelos MAI, incluido MAI-Transcribe-1, a través de Microsoft Foundry. También pueden probarlos en el MAI Playground (solo en EE. UU.).

¿Les interesan los modelos MAI pero no tienen acceso a Foundry? Rellenen este formulario y nos pondremos en contacto.

Modelos diseñados para ser mejores desde dentro hacia fuera.

En Microsoft AI, construimos una IA Humanista. Tenemos una visión distinta al crear nuestros modelos de IA: poner a los humanos en el centro, optimizar la manera en que las personas se comunican en verdad, entrenar para un uso práctico. Pronto verán más modelos nuestros en Foundry y directo en los productos y experiencias de Microsoft.

En consonancia con nuestro compromiso con una IA segura y responsable, estos modelos MAI fueron desarrollados, probados y seleccionados de manera rigurosa en equipo rojo. A través de Microsoft Foundry, los desarrolladores disponen de barreras integradas, gobernanza y controles empresariales diseñados para apoyar un despliegue seguro y conforme a gran escala.

Tarjetas modelo

Descargar Tarjeta Modelo para MAI-Transcribe-1

Descargar tarjeta modelo para MAI-Voice-1

Descargar Tarjeta de Modelo para MAI-Imagen-2

1. Los 25 principales idiomas por uso de productos de Microsoft.

2. De entre las 25 principales lenguas globales, MAI-Transcribe-1 ocupa el primer lugar por FLEURS en 11 idiomas principales. Gana contra Whisper-large-v3 en los 14 restantes y contra Gemini 3.1 Flash en 11 de esos 14.

The post 3 nuevos modelos MAI de clase mundial ya disponibles en Foundry appeared first on Source LATAM.

 

​The post 3 nuevos modelos MAI de clase mundial ya disponibles en Foundry appeared first on Source LATAM.  

Publicado el Deja un comentario

Amazon CloudWatch now supports OpenTelemetry metrics in public preview

Amazon CloudWatch now supports native OpenTelemetry (OTel) metrics in public preview, enabling you to send metrics directly using the OpenTelemetry Protocol (OTLP) without custom conversion logic or additional tooling. You can now combine your custom OpenTelemetry metrics with AWS vended metrics from over 70 services and query them using PromQL — no additional agents or code changes required.

With native OTel support, a team running microservices on Amazon EKS and on-premises servers can now send OTel metrics from both environments directly to CloudWatch. They can correlate application-level metrics like order processing latency from their on-premises services with EKS pod CPU utilization and Application Load Balancer request counts, then use PromQL to build unified dashboards and alarms that span their entire infrastructure. CloudWatch anomaly detection works with OTel metrics, automatically identifying unusual patterns without requiring you to set static thresholds. Query Studio, a new console experience for PromQL, lets you write queries, explore metrics, create alarms, and build dashboards directly in the CloudWatch console.

Native OpenTelemetry metrics support is available in public preview in US East (N. Virginia), US West (Oregon), Asia Pacific (Sydney), Asia Pacific (Singapore), and Europe (Ireland). There is no charge for OpenTelemetry metrics or querying during preview. To learn more, see the Amazon CloudWatch OpenTelemetry documentation.

 

​Amazon CloudWatch now supports native OpenTelemetry (OTel) metrics in public preview, enabling you to send metrics directly using the OpenTelemetry Protocol (OTLP) without custom conversion logic or additional tooling. You can now combine your custom OpenTelemetry metrics with AWS vended metrics from over 70 services and query them using PromQL — no additional agents or code changes required. With native OTel support, a team running microservices on Amazon EKS and on-premises servers can now send OTel metrics from both environments directly to CloudWatch. They can correlate application-level metrics like order processing latency from their on-premises services with EKS pod CPU utilization and Application Load Balancer request counts, then use PromQL to build unified dashboards and alarms that span their entire infrastructure. CloudWatch anomaly detection works with OTel metrics, automatically identifying unusual patterns without requiring you to set static thresholds. Query Studio, a new console experience for PromQL, lets you write queries, explore metrics, create alarms, and build dashboards directly in the CloudWatch console. Native OpenTelemetry metrics support is available in public preview in US East (N. Virginia), US West (Oregon), Asia Pacific (Sydney), Asia Pacific (Singapore), and Europe (Ireland). There is no charge for OpenTelemetry metrics or querying during preview. To learn more, see the Amazon CloudWatch OpenTelemetry documentation.  

Publicado el Deja un comentario

Amazon ECS announces Managed Daemons for ECS Managed Instances

Amazon ECS announces Managed Daemons for ECS Managed Instances, enabling organizations to centrally deploy and manage software agents such as security, observability, and networking across their container infrastructure independent of application deployments. By decoupling daemon lifecycle management from application operations, Managed Daemons helps guarantee reliable agent coverage across all workloads, simplifies deployments and version updates, and improves resource utilization by running a single daemon task per managed instance.

With Managed Daemons, you can create a daemon for one or more Managed Instances capacity providers in your cluster. ECS places exactly one daemon task per managed instance and guarantees that daemons are running before any application tasks are placed, so cross-cutting functions such as logging, tracing, and metrics collection are always available. ECS orchestrates daemons as independent processes bound to the instance lifecycle rather than individual application tasks, allowing platform administrators to manage them independently from application teams. When you update daemon versions, ECS drains existing instances and provisions new instances with the updated daemon, automatically replacing service tasks with circuit breaker protection and rollback capabilities for reliable coverage across all your workloads.

To get started, you can use AWS Console, CLI, CloudFormation, or AWS SDKs to register a daemon task definition specifying your container image, then create a daemon with associated capacity providers in your clusters. This feature is now available in all AWS Regions. For more details, refer to our documentation and launch blog post. There is no additional cost – you pay only for the standard compute resources consumed by your daemon tasks. 

 

​Amazon ECS announces Managed Daemons for ECS Managed Instances, enabling organizations to centrally deploy and manage software agents such as security, observability, and networking across their container infrastructure independent of application deployments. By decoupling daemon lifecycle management from application operations, Managed Daemons helps guarantee reliable agent coverage across all workloads, simplifies deployments and version updates, and improves resource utilization by running a single daemon task per managed instance. With Managed Daemons, you can create a daemon for one or more Managed Instances capacity providers in your cluster. ECS places exactly one daemon task per managed instance and guarantees that daemons are running before any application tasks are placed, so cross-cutting functions such as logging, tracing, and metrics collection are always available. ECS orchestrates daemons as independent processes bound to the instance lifecycle rather than individual application tasks, allowing platform administrators to manage them independently from application teams. When you update daemon versions, ECS drains existing instances and provisions new instances with the updated daemon, automatically replacing service tasks with circuit breaker protection and rollback capabilities for reliable coverage across all your workloads. To get started, you can use AWS Console, CLI, CloudFormation, or AWS SDKs to register a daemon task definition specifying your container image, then create a daemon with associated capacity providers in your clusters. This feature is now available in all AWS Regions. For more details, refer to our documentation and launch blog post. There is no additional cost – you pay only for the standard compute resources consumed by your daemon tasks.   

Publicado el Deja un comentario

Amazon Bedrock now supports structured outputs to AWS GovCloud (US) Regions

Amazon Bedrock is a fully managed service that provides access to a wide selection of high-performing foundation models from leading AI companies through a single API. Today, Amazon Bedrock expands structured outputs support to AWS GovCloud (US) Regions. Structured outputs enables foundation models to return consistent, schema-compliant, machine-readable responses—making it well-suited for government and regulated workloads that must meet strict compliance and data handling requirements.

Structured outputs helps with common production tasks, such as extracting key fields and powering workflows that use APIs or tools, where even minor formatting errors can break downstream systems. By ensuring schema compliance, it reduces the need for custom validation logic and lowers operational overhead by minimizing failed requests and retries—so you can confidently deploy AI applications that require predictable, machine-readable outputs. You can use structured outputs either by defining a JSON schema that describes your desired response format or by using strict tool definitions to ensure a model’s tool calls match your specifications.

Structured outputs is now generally available in all commercial AWS and AWS GovCloud (US) Regions where Amazon Bedrock is supported. To learn more about structured outputs and the supported models, visit the Amazon Bedrock documentation.

 

​Amazon Bedrock is a fully managed service that provides access to a wide selection of high-performing foundation models from leading AI companies through a single API. Today, Amazon Bedrock expands structured outputs support to AWS GovCloud (US) Regions. Structured outputs enables foundation models to return consistent, schema-compliant, machine-readable responses—making it well-suited for government and regulated workloads that must meet strict compliance and data handling requirements.
Structured outputs helps with common production tasks, such as extracting key fields and powering workflows that use APIs or tools, where even minor formatting errors can break downstream systems. By ensuring schema compliance, it reduces the need for custom validation logic and lowers operational overhead by minimizing failed requests and retries—so you can confidently deploy AI applications that require predictable, machine-readable outputs. You can use structured outputs either by defining a JSON schema that describes your desired response format or by using strict tool definitions to ensure a model’s tool calls match your specifications.
Structured outputs is now generally available in all commercial AWS and AWS GovCloud (US) Regions where Amazon Bedrock is supported. To learn more about structured outputs and the supported models, visit the Amazon Bedrock documentation.  

Publicado el Deja un comentario

Amazon SES Mail Manager adds new features for enhanced security and email processing

Amazon Simple Email Service (SES) Mail Manager now offers enhancements to email security and processing while simplifying email infrastructure migrations. These enhancements include optional TLS and certificate-based authentication (mTLS) support in Ingress Endpoint, and two new rule actions: Invoke Lambda function and Bounce.

These enhancements benefit organizations seeking to maintain compatibility with legacy systems while implementing stronger security controls, and advanced email routing capabilities. For example customers can now configure STARTTLS as an optional TLS configuration, enabling legacy systems that don’t support STARTTLS to connect to Mail Manager. With Mutual TLS (mTLS) in Ingress Endpoint customers can now used certificate-based authentication for enhanced security. The Invoke Lambda function rule action allows direct invocation of AWS Lambda functions from rule sets, enabling custom email processing workflows and the Bounce rule action provides RFC-compliant SMTP responses to sending servers.

These new enhancements are available today in all AWS Regions where Amazon SES Mail Manager is offered, except for the Middle East (UAE) and Middle East (Bahrain) regions. To learn more about Amazon SES Mail Manager and how these features can help streamline your email operations, visit https://aws.amazon.com/ses/.

 

​Amazon Simple Email Service (SES) Mail Manager now offers enhancements to email security and processing while simplifying email infrastructure migrations. These enhancements include optional TLS and certificate-based authentication (mTLS) support in Ingress Endpoint, and two new rule actions: Invoke Lambda function and Bounce. These enhancements benefit organizations seeking to maintain compatibility with legacy systems while implementing stronger security controls, and advanced email routing capabilities. For example customers can now configure STARTTLS as an optional TLS configuration, enabling legacy systems that don’t support STARTTLS to connect to Mail Manager. With Mutual TLS (mTLS) in Ingress Endpoint customers can now used certificate-based authentication for enhanced security. The Invoke Lambda function rule action allows direct invocation of AWS Lambda functions from rule sets, enabling custom email processing workflows and the Bounce rule action provides RFC-compliant SMTP responses to sending servers.
These new enhancements are available today in all AWS Regions where Amazon SES Mail Manager is offered, except for the Middle East (UAE) and Middle East (Bahrain) regions. To learn more about Amazon SES Mail Manager and how these features can help streamline your email operations, visit https://aws.amazon.com/ses/.  

Publicado el Deja un comentario

Amazon SageMaker Data Agent now supports geo-specific inference for Japan and Australia

Amazon SageMaker Data Agent now supports cross-region inference profiles for Japan and Australia through Amazon Bedrock. With this update, inference requests from Data Agent in the Asia Pacific (Tokyo) and Asia Pacific (Sydney) regions are processed within their respective geographies, supporting data sovereignty requirements for customers in Japan and Australia.

Data Agent provides an AI-powered conversational experience for data exploration, Python and SQL code generation, troubleshooting, and analytics directly within Amazon SageMaker Unified Studio Notebook and Query Editor. With geo-specific inference through JP-CRIS (Japan Cross-Region Inference) and AU-CRIS (Australia Cross-Region Inference), you can use Data Agent with confidence that your inference requests are routed exclusively within your geography over the AWS Global Network. Customers in regulated industries such as financial services, healthcare, and the public sector can meet data residency requirements while using the full set of Data Agent capabilities.

To get started, open a project in SageMaker Unified Studio in a supported region and use Data Agent in notebooks or Query Editor. For more information, see SageMaker Data Agent in the Amazon SageMaker Unified Studio User Guide.

 

​Amazon SageMaker Data Agent now supports cross-region inference profiles for Japan and Australia through Amazon Bedrock. With this update, inference requests from Data Agent in the Asia Pacific (Tokyo) and Asia Pacific (Sydney) regions are processed within their respective geographies, supporting data sovereignty requirements for customers in Japan and Australia.
Data Agent provides an AI-powered conversational experience for data exploration, Python and SQL code generation, troubleshooting, and analytics directly within Amazon SageMaker Unified Studio Notebook and Query Editor. With geo-specific inference through JP-CRIS (Japan Cross-Region Inference) and AU-CRIS (Australia Cross-Region Inference), you can use Data Agent with confidence that your inference requests are routed exclusively within your geography over the AWS Global Network. Customers in regulated industries such as financial services, healthcare, and the public sector can meet data residency requirements while using the full set of Data Agent capabilities.
To get started, open a project in SageMaker Unified Studio in a supported region and use Data Agent in notebooks or Query Editor. For more information, see SageMaker Data Agent in the Amazon SageMaker Unified Studio User Guide.  

Publicado el Deja un comentario

AWS VPC Encryption Controls now available in AWS GovCloud (US) Regions

AWS launches VPC Encryption Controls in AWS GovCloud (US) Regions to make it easy to audit and enforce encryption in transit within and across Amazon Virtual Private Clouds (VPC), and demonstrate compliance with encryption standards. You can turn it on your existing VPCs to monitor encryption status of traffic flows and identify VPC resources that are unintentionally allowing plaintext traffic. This feature also makes it easy to enforce encryption across different network paths by automatically (and transparently) turning on hardware-based AES-256 encryption on traffic between multiple VPC resources including AWS Fargate, Network Load Balancers, and Application Load Balancers.

To meet stringent compliance standards like HIPAA, PCI DSS, FedRAMP, and FIPS 140-2, government customers rely on both application layer encryption and the hardware-based encryption that AWS offers across different network paths. AWS provides hardware-based AES-256 encryption transparently between modern EC2 Nitro instances. AWS also encrypts all network traffic between AWS data centers in and across Availability Zones, and AWS Regions before the traffic leaves our secure facilities. All inter-region traffic that uses VPC Peering, Transit Gateway Peering, or AWS Cloud WAN receives an additional layer of transparent encryption before leaving AWS data centers. Prior to this release, customers had to track and confirm encryption across all network paths. With VPC Encryption Controls, customers can now monitor, enforce and demonstrate encryption within and across Virtual Private Clouds (VPCs) in just a few clicks. Your information security team can turn it on centrally to maintain a secure and compliant environment, and generate audit logs for compliance and reporting.

With this launch, VPC Encryption Controls is now available in AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions. To learn more about this feature and its use cases, please see our documentation.

 

​AWS launches VPC Encryption Controls in AWS GovCloud (US) Regions to make it easy to audit and enforce encryption in transit within and across Amazon Virtual Private Clouds (VPC), and demonstrate compliance with encryption standards. You can turn it on your existing VPCs to monitor encryption status of traffic flows and identify VPC resources that are unintentionally allowing plaintext traffic. This feature also makes it easy to enforce encryption across different network paths by automatically (and transparently) turning on hardware-based AES-256 encryption on traffic between multiple VPC resources including AWS Fargate, Network Load Balancers, and Application Load Balancers.
To meet stringent compliance standards like HIPAA, PCI DSS, FedRAMP, and FIPS 140-2, government customers rely on both application layer encryption and the hardware-based encryption that AWS offers across different network paths. AWS provides hardware-based AES-256 encryption transparently between modern EC2 Nitro instances. AWS also encrypts all network traffic between AWS data centers in and across Availability Zones, and AWS Regions before the traffic leaves our secure facilities. All inter-region traffic that uses VPC Peering, Transit Gateway Peering, or AWS Cloud WAN receives an additional layer of transparent encryption before leaving AWS data centers. Prior to this release, customers had to track and confirm encryption across all network paths. With VPC Encryption Controls, customers can now monitor, enforce and demonstrate encryption within and across Virtual Private Clouds (VPCs) in just a few clicks. Your information security team can turn it on centrally to maintain a secure and compliant environment, and generate audit logs for compliance and reporting.
With this launch, VPC Encryption Controls is now available in AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions. To learn more about this feature and its use cases, please see our documentation.  

Publicado el Deja un comentario

Amazon CloudFront now supports SHA-256 for signed URLs and signed cookies

Amazon CloudFront now supports SHA-256 as a hash algorithm for creating signed URLs and signed cookies. SHA-256 provides an improved security posture with stronger collision detection and alignment with modern cryptographic standards, giving you stronger cryptographic signing when restricting access to content. Previously, CloudFront signed URLs and signed cookies used SHA-1 exclusively for signature generation. This feature helps you meet security and compliance requirements that mandate SHA-256 for digital signatures, while also future-proofing your content delivery workflows.

To use SHA-256, include the Hash-Algorithm=SHA256 query parameter in your signed URLs, or the CloudFront-Hash-Algorithm=SHA256 cookie attribute for signed cookies. Existing signed URLs and signed cookies that don’t specify a hash algorithm continue to use SHA-1, so this change is fully backwards compatible.

This feature is available in all edge locations where Amazon CloudFront is available. There is no additional cost to use SHA-256 signing. To learn more, see Create a signed URL using a canned policy or Set signed cookies using a canned policy in the Amazon CloudFront Developer Guide.

 

​Amazon CloudFront now supports SHA-256 as a hash algorithm for creating signed URLs and signed cookies. SHA-256 provides an improved security posture with stronger collision detection and alignment with modern cryptographic standards, giving you stronger cryptographic signing when restricting access to content. Previously, CloudFront signed URLs and signed cookies used SHA-1 exclusively for signature generation. This feature helps you meet security and compliance requirements that mandate SHA-256 for digital signatures, while also future-proofing your content delivery workflows. To use SHA-256, include the Hash-Algorithm=SHA256 query parameter in your signed URLs, or the CloudFront-Hash-Algorithm=SHA256 cookie attribute for signed cookies. Existing signed URLs and signed cookies that don’t specify a hash algorithm continue to use SHA-1, so this change is fully backwards compatible.
This feature is available in all edge locations where Amazon CloudFront is available. There is no additional cost to use SHA-256 signing. To learn more, see Create a signed URL using a canned policy or Set signed cookies using a canned policy in the Amazon CloudFront Developer Guide.