Description
Caches often process sensitive information such as sessions, tokens and temporary data. ElastiCache encryption in transit protects connections between clients and cache nodes, and communication between nodes.
Without transit encryption, cache requests and responses can travel in plaintext even on an internal network. Encryption at rest and authentication require separate configuration.
Potential impact
A party able to intercept the connection path could obtain cached values containing session or authentication information. The configuration may also fail confidentiality and integrity requirements for data in transit.
Remediation
- Set
transit_encryption_enabled = trueon a supported replication group and verify application TLS connections and certificate validation. - Changing this setting on an existing group is supported for Valkey 7.2 or later and Redis OSS 7 or later. For older versions, first plan an upgrade to a supported version and the connection transition.
- If plaintext connections were allowed during migration, require TLS after moving the clients. Manage encryption at rest and authentication as well.
Examples
These Redis OSS replication-group excerpts require an engine and node type supported in the Region, together with the necessary VPC, subnets and security groups.
Before
resource "aws_elasticache_replication_group" "example" {
automatic_failover_enabled = true
preferred_cache_cluster_azs = ["us-west-2a", "us-west-2b"]
replication_group_id = "tf-rep-group-1"
description = "test description"
node_type = "cache.m4.large"
num_cache_clusters = 2
port = 6379
}
Transit encryption is not explicitly enabled. Check the chosen engine's defaults and actual connection settings.
After
resource "aws_elasticache_replication_group" "example" {
automatic_failover_enabled = true
preferred_cache_cluster_azs = ["us-west-2a", "us-west-2b"]
replication_group_id = "tf-rep-group-1"
description = "test description"
node_type = "cache.m4.large"
num_cache_clusters = 2
port = 6379
transit_encryption_enabled = true
}
This enables transit encryption. Applications must also connect with TLS, and existing connections need a verified transition.