Data protection

OpenSearch (Elasticsearch) domain does not require TLS 1.2 encryption

Platform(s)
Compliance Frameworks

AWS Foundational Security Best Practices Controls, Brazilian General Data Protection (LGPD), CCPA, coppa, CPRA, GDPR, HITRUST, iso_27001_2022, iso_27002_2022, mpa, New Zealand Information Security Manual, NIST 800-171, NIST 800-53, PDPA, pipeda

Description

Amazon OpenSearch Service (Amazon Elasticsearch Service successor) is a managed service that simplifies the deployment, operation, and scaling of OpenSearch clusters in AWS Cloud. It was found that the OpenSearch (Elasticsearch) domain {AwsElasticSearch} does not accept only secured HTTPS connection or TLS version 1.2. Allowing only HTTPS connections can help against attacks such as person-in-the-middle, eavesdrop or manipulating network traffic. TLS 1.2 also contains enhancements over previous TLS versions.