Description
When EnforceHTTPS is false on an Elasticsearch or OpenSearch domain, clients can also use HTTP. Search requests, responses and credentials sent over HTTP can be exposed along the communication path.
Potential impact
- An attacker with access to the path can intercept or alter plaintext requests and responses.
- The domain may fail to meet a policy requiring TLS.
Remediation
- Set
DomainEndpointOptions.EnforceHTTPStotrue. - Select a TLS policy supported by the service and clients, and configure clients to use HTTPS with server certificate verification.
- Verify that plaintext requests are rejected, and manage node-to-node encryption and encryption at rest separately.
Examples
These excerpts show endpoint settings only. Configure other required domain settings and the access policy separately.
Before
yaml
Resources:
OpenSearchDomain:
Type: AWS::OpenSearchService::Domain
Properties:
DomainEndpointOptions:
EnforceHTTPS: false
TLSSecurityPolicy: Policy-Min-TLS-1-2-2019-07
The TLS policy applies to HTTPS connections, but EnforceHTTPS: false does not block HTTP access.
After
yaml
Resources:
OpenSearchDomain:
Type: AWS::OpenSearchService::Domain
Properties:
DomainEndpointOptions:
EnforceHTTPS: true
TLSSecurityPolicy: Policy-Min-TLS-1-2-2019-07
The domain endpoint requires HTTPS. This alone does not restrict caller permissions or encrypt stored data.