ElastiCache replication group with transit encryption disabled

Protect ElastiCache replication-group client connections and node-to-node traffic with TLS.

Description

Caches often process sensitive information such as sessions, tokens and temporary data. ElastiCache encryption in transit protects connections between clients and cache nodes, and communication between nodes.

Without transit encryption, cache requests and responses can travel in plaintext even on an internal network. Encryption at rest and authentication require separate configuration.

Potential impact

A party able to intercept the connection path could obtain cached values containing session or authentication information. The configuration may also fail confidentiality and integrity requirements for data in transit.

Remediation

  • Set transit_encryption_enabled = true on a supported replication group and verify application TLS connections and certificate validation.
  • Changing this setting on an existing group is supported for Valkey 7.2 or later and Redis OSS 7 or later. For older versions, first plan an upgrade to a supported version and the connection transition.
  • If plaintext connections were allowed during migration, require TLS after moving the clients. Manage encryption at rest and authentication as well.

Examples

These Redis OSS replication-group excerpts require an engine and node type supported in the Region, together with the necessary VPC, subnets and security groups.

Before

hcl
resource "aws_elasticache_replication_group" "example" {
  automatic_failover_enabled    = true
  preferred_cache_cluster_azs            = ["us-west-2a", "us-west-2b"]
  replication_group_id          = "tf-rep-group-1"
  description = "test description"
  node_type                     = "cache.m4.large"
  num_cache_clusters         = 2
  port                          = 6379
}

Transit encryption is not explicitly enabled. Check the chosen engine's defaults and actual connection settings.

After

hcl
resource "aws_elasticache_replication_group" "example" {
  automatic_failover_enabled    = true
  preferred_cache_cluster_azs            = ["us-west-2a", "us-west-2b"]
  replication_group_id          = "tf-rep-group-1"
  description = "test description"
  node_type                     = "cache.m4.large"
  num_cache_clusters         = 2
  port                          = 6379
  transit_encryption_enabled    = true
}

This enables transit encryption. Applications must also connect with TLS, and existing connections need a verified transition.

References