Description
An internet-facing ELB using HTTP transfers user requests and responses without encryption.
Potential impact
Credentials or personal data may be exposed, or request contents altered, along the network path.
Remediation
Set protocol to HTTPS on nifcloud_elb and assign a valid certificate with ssl_certificate_id. Verify client connections and separately assess protection for the backend connection.
Examples
These excerpts add HTTPS and a certificate. TLS terminates at the ELB, so traffic forwarded to the backend is plain text. Configure the backend port and omitted network settings for the actual environment.
Before
hcl
resource "nifcloud_elb" "example" {
availability_zone = "east-11"
instance_port = 80
protocol = "HTTP"
lb_port = 80
network_interface {
network_id = "net-COMMON_GLOBAL"
is_vip_network = true
}
}
After
hcl
resource "nifcloud_elb" "example" {
availability_zone = "east-11"
instance_port = 443
protocol = "HTTPS"
ssl_certificate_id = var.ssl_certificate_id
lb_port = 443
network_interface {
network_id = "net-COMMON_GLOBAL"
is_vip_network = true
}
}