S3 bucket policy should deny HTTP requests

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Description

At the Amazon S3 bucket level, you can configure permissions through a bucket policy to make objects accessible only through HTTPS. By default, Amazon S3 allows both HTTP and HTTPS requests. To enforce HTTPS-only access, you must explicitly deny HTTP requests. Bucket policies allowing HTTPS but not explicitly denying HTTP do not comply with this security recommendation. Implementing such a policy helps safeguard data by ensuring only encrypted data transfers using HTTPS, thereby enhancing security.

Remediation

For instructions on configuring your Amazon S3 bucket policy to require HTTPS, refer to the Amazon S3 Developer Guide and the IAM User Guide.