Elasticsearch domain does not enforce HTTPS

Require HTTPS connections to the search domain.

Description

An Elasticsearch domain permits plaintext HTTP client access when domain_endpoint_options.enforce_https is false.

Potential impact

Search requests and responses sent over HTTP can be exposed or modified in transit.

Remediation

Set enforce_https to true and update clients to use the HTTPS endpoint.

Examples

The examples change the endpoint setting of an existing Elasticsearch domain. Node-to-node and at-rest encryption are separate settings.

Before

hcl
resource "aws_elasticsearch_domain" "example" {
  domain_name           = "my-elasticsearch-domain"
  elasticsearch_version = "7.10"

  domain_endpoint_options {
    enforce_https = false
  }
}

After

hcl
resource "aws_elasticsearch_domain" "example" {
  domain_name           = "my-elasticsearch-domain"
  elasticsearch_version = "7.10"

  domain_endpoint_options {
    enforce_https = true
  }
}

References