Review HTTPS enforcement for an OpenSearch domain

Restrict requests between clients and the domain to HTTPS.

Description

An OpenSearch domain that does not enforce HTTPS can accept HTTP requests. If clients use unencrypted connections, search data or credentials in transit may be exposed or altered.

HTTPS enforcement protects the connection between clients and the domain endpoint. Node-to-node encryption, encryption at rest and access permissions are separate settings.

Potential impact

  • An attacker on the network path may read or alter requests and responses sent over HTTP.
  • Sensitive data or credentials in unencrypted requests may be disclosed.

Remediation

Set domain_endpoint_options.enforce_https to true and choose a TLS security policy supported by the service and clients. Test that clients use HTTPS and validate the server certificate. Restrict domain access policies and network access to the identities and networks that need them.

Examples

These excerpts update the endpoint settings of the same existing domain. Supply its actual name as opensearch_domain_name. Domain creation, engine version and capacity settings are omitted.

Before

yaml
- name: Configure an existing OpenSearch domain endpoint
  community.aws.opensearch:
    domain_name: "{{ opensearch_domain_name }}"
    domain_endpoint_options:
      enforce_https: false

This does not require HTTPS-only connections. It does not mean every request uses HTTP, but it does not block HTTP access.

After

yaml
- name: Configure an existing OpenSearch domain endpoint
  community.aws.opensearch:
    domain_name: "{{ opensearch_domain_name }}"
    domain_endpoint_options:
      enforce_https: true

The domain endpoint accepts HTTPS only. Verify the clients’ actual connections and certificate validation as well.

References