Description
Without transit encryption on an ElastiCache Redis replication group, application and cache data can travel in plaintext. Encryption at rest does not protect this connection.
Potential impact
- An attacker with access to the communication path may obtain session data or sensitive cached information.
- The risk of data alteration increases, and transport-encryption requirements may not be met.
Remediation
- Set
TransitEncryptionEnabledtotrueand configure clients to use TLS and verify the server certificate. - Check whether the engine version supports updating an existing replication group. For a supported transition, set
TransitEncryptionModetopreferredwhile migrating clients, then switch torequiredto reject plaintext connections. - Review network access, user permissions and encryption at rest separately.
Examples
These excerpts show only replication-group encryption settings. Configure a supported engine version, subnet group, nodes and other required properties for your deployment.
Before
yaml
Resources:
ReplicationGroup:
Type: AWS::ElastiCache::ReplicationGroup
Properties:
Engine: redis
AtRestEncryptionEnabled: true
TransitEncryptionEnabled: false
Transit encryption is disabled. AtRestEncryptionEnabled: true protects stored data, not client connections.
After
yaml
Resources:
ReplicationGroup:
Type: AWS::ElastiCache::ReplicationGroup
Properties:
Engine: redis
AtRestEncryptionEnabled: true
TransitEncryptionEnabled: true
Transit encryption is enabled. Verify that clients use TLS and that no mode allowing plaintext connections remains after migration.