Description
Web requests sent as plain HTTP through a load balancer are not encrypted. Changing the port number to 443 alone does not enable TLS.
Potential impact
An attacker with access to the traffic path may read or alter requests and responses.
Remediation
Forward to a server that handles TLS, or configure load balancer TLS termination with a valid certificate. Set load_balancer_port and instance_port to match the actual service configuration.
Examples
The examples change forwarding from port 80 to port 443. After the change, the backend server must handle TLS on port 443 with a valid certificate.
Before
hcl
resource "nifcloud_load_balancer" "example" {
load_balancer_name = "example"
instance_port = 80
load_balancer_port = 80
}
After
hcl
resource "nifcloud_load_balancer" "example" {
load_balancer_name = "example"
instance_port = 443
load_balancer_port = 443
}