ElastiCache transit encryption is disabled

Use TLS for ElastiCache Redis connections and check whether plaintext connections remain allowed.

Description

Without transit encryption on an ElastiCache Redis replication group, application and cache data can travel in plaintext. Encryption at rest does not protect this connection.

Potential impact

  • An attacker with access to the communication path may obtain session data or sensitive cached information.
  • The risk of data alteration increases, and transport-encryption requirements may not be met.

Remediation

  • Set TransitEncryptionEnabled to true and configure clients to use TLS and verify the server certificate.
  • Check whether the engine version supports updating an existing replication group. For a supported transition, set TransitEncryptionMode to preferred while migrating clients, then switch to required to reject plaintext connections.
  • Review network access, user permissions and encryption at rest separately.

Examples

These excerpts show only replication-group encryption settings. Configure a supported engine version, subnet group, nodes and other required properties for your deployment.

Before

yaml
Resources:
  ReplicationGroup:
    Type: AWS::ElastiCache::ReplicationGroup
    Properties:
      Engine: redis
      AtRestEncryptionEnabled: true
      TransitEncryptionEnabled: false

Transit encryption is disabled. AtRestEncryptionEnabled: true protects stored data, not client connections.

After

yaml
Resources:
  ReplicationGroup:
    Type: AWS::ElastiCache::ReplicationGroup
    Properties:
      Engine: redis
      AtRestEncryptionEnabled: true
      TransitEncryptionEnabled: true

Transit encryption is enabled. Verify that clients use TLS and that no mode allowing plaintext connections remains after migration.

References