Review certificate validation in Ansible API Gateway management

Keep server certificate validation enabled when connecting to AWS management APIs.

Description

Setting Ansible validate_certs to false disables server certificate validation for communication with AWS management APIs. An attacker able to interfere with that connection and impersonate the server may expose credentials or alter management requests and responses.

This option does not configure TLS between API clients and API Gateway or backend certificates. Its default is true, so omitting it does not disable certificate validation.

Potential impact

  • Server impersonation can allow management requests or responses to be altered.
  • Automation credentials and processed data may be disclosed.

Remediation

Keep validate_certs: true. If certificate errors occur, check the endpoint and certificate chain rather than disabling validation, and supply required trusted CAs through options such as aws_ca_bundle in a supported module. Review API client and backend TLS configuration separately.

Examples

These task excerpts use the older aws_api_gateway name. Use the module name supported by the installed Ansible collection and supply the actual api_id and my_api.yml.

Before

yaml
- name: update API
  aws_api_gateway:
    api_id: abc123321cba
    state: present
    swagger_file: my_api.yml
    validate_certs: no

validate_certs: no disables server certificate validation between Ansible and the AWS API.

After

yaml
- name: update API
  aws_api_gateway:
    api_id: abc123321cba
    state: present
    swagger_file: my_api.yml
    validate_certs: yes

validate_certs: yes validates the server certificate. The certificate chain for the AWS API endpoint must be trusted.

References