Description
Without node-to-node encryption, data can move between nodes in an Elasticsearch or OpenSearch domain without encryption. Client-facing HTTPS and encryption at rest do not replace protection of this internal connection.
Potential impact
- An attacker with access to the internal communication path may obtain replication or search data.
- The domain may not meet encryption requirements for sensitive logs or search indexes.
Remediation
- Set
NodeToNodeEncryptionOptions.Enabledtotrue. - Check update support for the existing domain’s version and assess service impact, then verify the applied encryption state.
- Configure client HTTPS, encryption at rest and access permissions separately.
Examples
These excerpts show domain encryption properties only. Configure the engine version, nodes, storage and access policy for the actual workload.
Before
yaml
Resources:
OpenSearchDomain:
Type: AWS::OpenSearchService::Domain
Properties:
DomainName: my-domain
EncryptionAtRestOptions:
Enabled: true
Only encryption at rest is explicit. Check the actual node-to-node encryption configuration before assessing internal traffic protection.
After
yaml
Resources:
OpenSearchDomain:
Type: AWS::OpenSearchService::Domain
Properties:
DomainName: my-domain
NodeToNodeEncryptionOptions:
Enabled: true
EncryptionAtRestOptions:
Enabled: true
Node-to-node encryption is explicit alongside encryption at rest. HTTPS for client connections still needs separate configuration.