Description
An OpenSearch domain that does not enforce HTTPS can accept HTTP requests. If clients use unencrypted connections, search data or credentials in transit may be exposed or altered.
HTTPS enforcement protects the connection between clients and the domain endpoint. Node-to-node encryption, encryption at rest and access permissions are separate settings.
Potential impact
- An attacker on the network path may read or alter requests and responses sent over HTTP.
- Sensitive data or credentials in unencrypted requests may be disclosed.
Remediation
Set domain_endpoint_options.enforce_https to true and choose a TLS security policy supported by the service and clients. Test that clients use HTTPS and validate the server certificate. Restrict domain access policies and network access to the identities and networks that need them.
Examples
These excerpts update the endpoint settings of the same existing domain. Supply its actual name as opensearch_domain_name. Domain creation, engine version and capacity settings are omitted.
Before
- name: Configure an existing OpenSearch domain endpoint
community.aws.opensearch:
domain_name: "{{ opensearch_domain_name }}"
domain_endpoint_options:
enforce_https: false
This does not require HTTPS-only connections. It does not mean every request uses HTTP, but it does not block HTTP access.
After
- name: Configure an existing OpenSearch domain endpoint
community.aws.opensearch:
domain_name: "{{ opensearch_domain_name }}"
domain_endpoint_options:
enforce_https: true
The domain endpoint accepts HTTPS only. Verify the clients’ actual connections and certificate validation as well.