Description
Setting Ansible validate_certs to false disables server certificate validation for communication with AWS management APIs. An attacker able to interfere with that connection and impersonate the server may expose credentials or alter management requests and responses.
This option does not configure TLS between API clients and API Gateway or backend certificates. Its default is true, so omitting it does not disable certificate validation.
Potential impact
- Server impersonation can allow management requests or responses to be altered.
- Automation credentials and processed data may be disclosed.
Remediation
Keep validate_certs: true. If certificate errors occur, check the endpoint and certificate chain rather than disabling validation, and supply required trusted CAs through options such as aws_ca_bundle in a supported module. Review API client and backend TLS configuration separately.
Examples
These task excerpts use the older aws_api_gateway name. Use the module name supported by the installed Ansible collection and supply the actual api_id and my_api.yml.
Before
- name: update API
aws_api_gateway:
api_id: abc123321cba
state: present
swagger_file: my_api.yml
validate_certs: no
validate_certs: no disables server certificate validation between Ansible and the AWS API.
After
- name: update API
aws_api_gateway:
api_id: abc123321cba
state: present
swagger_file: my_api.yml
validate_certs: yes
validate_certs: yes validates the server certificate. The certificate chain for the AWS API endpoint must be trusted.