OpenSearch domain does not require HTTPS

Require HTTPS connections to Elasticsearch and OpenSearch domains.

Description

When EnforceHTTPS is false on an Elasticsearch or OpenSearch domain, clients can also use HTTP. Search requests, responses and credentials sent over HTTP can be exposed along the communication path.

Potential impact

  • An attacker with access to the path can intercept or alter plaintext requests and responses.
  • The domain may fail to meet a policy requiring TLS.

Remediation

  • Set DomainEndpointOptions.EnforceHTTPS to true.
  • Select a TLS policy supported by the service and clients, and configure clients to use HTTPS with server certificate verification.
  • Verify that plaintext requests are rejected, and manage node-to-node encryption and encryption at rest separately.

Examples

These excerpts show endpoint settings only. Configure other required domain settings and the access policy separately.

Before

yaml
Resources:
  OpenSearchDomain:
    Type: AWS::OpenSearchService::Domain
    Properties:
      DomainEndpointOptions:
        EnforceHTTPS: false
        TLSSecurityPolicy: Policy-Min-TLS-1-2-2019-07

The TLS policy applies to HTTPS connections, but EnforceHTTPS: false does not block HTTP access.

After

yaml
Resources:
  OpenSearchDomain:
    Type: AWS::OpenSearchService::Domain
    Properties:
      DomainEndpointOptions:
        EnforceHTTPS: true
        TLSSecurityPolicy: Policy-Min-TLS-1-2-2019-07

The domain endpoint requires HTTPS. This alone does not restrict caller permissions or encrypt stored data.

References