NIFCLOUD ELB uses HTTP

Encrypt traffic between external clients and the ELB.

Description

An internet-facing ELB using HTTP transfers user requests and responses without encryption.

Potential impact

Credentials or personal data may be exposed, or request contents altered, along the network path.

Remediation

Set protocol to HTTPS on nifcloud_elb and assign a valid certificate with ssl_certificate_id. Verify client connections and separately assess protection for the backend connection.

Examples

These excerpts add HTTPS and a certificate. TLS terminates at the ELB, so traffic forwarded to the backend is plain text. Configure the backend port and omitted network settings for the actual environment.

Before

hcl
resource "nifcloud_elb" "example" {
  availability_zone = "east-11"
  instance_port     = 80
  protocol          = "HTTP"
  lb_port           = 80

  network_interface {
    network_id     = "net-COMMON_GLOBAL"
    is_vip_network = true
  }
}

After

hcl
resource "nifcloud_elb" "example" {
  availability_zone = "east-11"
  instance_port     = 443
  protocol          = "HTTPS"
  ssl_certificate_id = var.ssl_certificate_id
  lb_port           = 443

  network_interface {
    network_id     = "net-COMMON_GLOBAL"
    is_vip_network = true
  }
}

References