설명
ansible.builtin.uri로 http:// 주소를 요청하면 전송 구간이 암호화되지 않습니다.
잠재적 영향
통신을 가로챌 수 있는 주체가 요청과 응답의 토큰, 쿠키 또는 데이터를 읽거나 변조할 수 있습니다.
해결 방법
대상이 HTTPS를 지원하도록 구성하고 URL을 https://로 변경하세요. 인증서 검증을 유지하고, HTTP만 가능한 대상은 민감한 데이터를 보내지 않도록 사용 범위를 제한하세요.
예시
예시는 같은 상태 확인 요청을 HTTPS로 바꿉니다. 서버가 HTTPS와 신뢰할 수 있는 인증서를 제공해야 합니다.
변경 전
yaml
- name: Check site status
hosts: localhost
tasks:
- name: Request site over HTTP
ansible.builtin.uri:
url: "http://www.example.com"
method: GET
register: site_response
변경 후
yaml
- name: Check site status
hosts: localhost
tasks:
- name: Request site over HTTPS
ansible.builtin.uri:
url: "https://www.example.com"
method: GET
register: site_response