Review HTTPS enforcement for the S3 bucket

Block unencrypted HTTP requests to S3.

Description

HTTP requests to S3 leave data unencrypted in transit, creating risks of disclosure or tampering. To enforce HTTPS, explicitly deny requests with aws:SecureTransport set to false for both the bucket and its objects.

An Allow statement restricted to HTTPS does not deny HTTP requests allowed by another policy. Review the actual grants and explicit deny conditions together.

Potential impact

  • Request contents and uploaded or downloaded data can be intercepted or modified in transit.
  • Authorized access may still use an unprotected path where HTTPS is required.

Remediation

  • Apply a Deny for aws:SecureTransport = false to both the bucket ARN and object ARNs.
  • Preserve required permissions and network restrictions, and configure clients to use HTTPS.
  • Review AWS service calls whose network context may be redacted; scope necessary service-principal exceptions with aws:PrincipalIsAWSService.

Examples

These policy excerpts omit the bucket resource. The first denies requests from the specified IP address; it is neither an IP allow-list nor an HTTPS requirement. Preserve required IP restrictions when adding transport conditions to your actual policy.

Before

hcl
resource "aws_s3_bucket_policy" "example" {
  bucket = aws_s3_bucket.b.id

  policy = <<EOF
{
    "Version": "2012-10-17",
    "Id": "MYBUCKETPOLICY",
    "Statement": [
      {
        "Sid": "IPAllow",
        "Effect": "Deny",
        "Principal": "*",
        "Action": "s3:*",
        "Resource": [
          "${aws_s3_bucket.b.arn}",
          "${aws_s3_bucket.b.arn}/*"
        ],
        "Condition": {
          "IpAddress": {
            "aws:SourceIp": "8.8.8.8/32"
          }
        }
      }
    ]
}
EOF
}

After

hcl
resource "aws_s3_bucket_policy" "example" {
  bucket = aws_s3_bucket.b.id

  policy = <<EOF
{
    "Version": "2012-10-17",
    "Id": "MYBUCKETPOLICY",
    "Statement": [
      {
        "Sid": "IPAllow",
        "Effect": "Deny",
        "Principal": "*",
        "Action": "s3:*",
        "Resource": [
          "${aws_s3_bucket.b.arn}",
          "${aws_s3_bucket.b.arn}/*"
        ],
        "Condition": {
          "Bool": {
            "aws:SecureTransport": "false"
          }
        }
      }
    ]
}
EOF
}

Explanation:

The second explicitly denies unencrypted requests to the bucket and objects. This statement does not itself grant access to HTTPS requests.

References