説明
Elasticsearchドメインのdomain_endpoint_options.enforce_httpsがfalseの場合、クライアントは平文のHTTPでアクセスできます。
想定される影響
HTTPで送受信する検索リクエストやレスポンスが、通信経路で漏えい・改ざんされるおそれがあります。
対処方法
enforce_httpsをtrueに設定し、クライアントもHTTPSエンドポイントを使うように変更してください。
例
以下は既存のElasticsearchドメインのエンドポイント設定を変更する例です。ノード間通信と保存データの暗号化は別の設定です。
変更前
hcl
resource "aws_elasticsearch_domain" "example" {
domain_name = "my-elasticsearch-domain"
elasticsearch_version = "7.10"
domain_endpoint_options {
enforce_https = false
}
}
変更後
hcl
resource "aws_elasticsearch_domain" "example" {
domain_name = "my-elasticsearch-domain"
elasticsearch_version = "7.10"
domain_endpoint_options {
enforce_https = true
}
}