AWS Config Rule: Elasticsearch Node to Node Encryption Check


Fernando Honig

Last Update לפני 8 חודשים

Description: Check that Amazon ElasticSearch Service nodes are encrypted end to end. The rule is NON_COMPLIANT if the node-to-node encryption is disabled on the domain.

Trigger type: Configuration changes

AWS Region: All supported AWS regions except Asia Pacific (Jakarta), Africa (Cape Town), Asia Pacific (Hyderabad), Asia Pacific (Osaka), Asia Pacific (Melbourne), Europe (Milan), Europe (Spain), Europe (Zurich) Region

How to Resolve Manually

To resolve this manually, go to your AWS Management Console and select Elasticsearch from Services.

Node-to-node encryption on new domains requires Elasticsearch 6.0 or later. Enabling the feature on existing domains requires Elasticsearch 6.7 or later

Choose the existing domain that is NON_COMPLIANT -> Actions, and Modify encryptions.

