Description
An Elasticsearch domain permits plaintext HTTP client access when domain_endpoint_options.enforce_https is false.
Potential impact
Search requests and responses sent over HTTP can be exposed or modified in transit.
Remediation
Set enforce_https to true and update clients to use the HTTPS endpoint.
Examples
The examples change the endpoint setting of an existing Elasticsearch domain. Node-to-node and at-rest encryption are separate settings.
Before
hcl
resource "aws_elasticsearch_domain" "example" {
domain_name = "my-elasticsearch-domain"
elasticsearch_version = "7.10"
domain_endpoint_options {
enforce_https = false
}
}
After
hcl
resource "aws_elasticsearch_domain" "example" {
domain_name = "my-elasticsearch-domain"
elasticsearch_version = "7.10"
domain_endpoint_options {
enforce_https = true
}
}