Description
Without HTTPS enforcement at an Elasticsearch domain endpoint, clients may connect over plaintext HTTP. Unencrypted search requests and responses can expose sensitive information to an attacker with access to the network path.
Potential impact
- Plaintext requests and responses can expose search data or authentication information.
- Data in transit can be vulnerable to tampering.
Remediation
Set domainEndpointOptions.enforceHttps to true. Maintain a supported TLS security policy and client certificate verification, and confirm that HTTP connections are rejected.
Examples
These excerpts compare only the HTTPS setting for a Pulumi AWS Elasticsearch domain. Configure the remaining domain settings separately.
Before
yaml
resources:
my-elasticsearch-domain:
type: aws:elasticsearch:Domain
properties:
domainEndpointOptions:
enforceHttps: false
tlsSecurityPolicy: Policy-Min-TLS-1-2-2019-07
After
yaml
resources:
my-elasticsearch-domain:
type: aws:elasticsearch:Domain
properties:
domainEndpointOptions:
enforceHttps: true
tlsSecurityPolicy: Policy-Min-TLS-1-2-2019-07
The after example requires HTTPS. Manage encryption at rest, node-to-node encryption and access permissions separately.