Checks whether a Redis instance in a virtual private cloud (VPC) has password authentication enabled.
Scenarios
Password authentication for Redis instances in VPCs enhances access security.
Risk level
Default risk level: High.
You can change the risk level as needed.
Detection logic
-
A Redis instance is compliant if password authentication is enabled in a VPC.
-
A Redis instance is non-compliant if it uses a classic network or if password authentication is disabled in a VPC. Apply the Corrective actions to fix non-compliant instances.
Rule details
|
Parameter |
Description |
|
Rule name |
Enable password authentication for a Redis instance |
|
Rule identifier |
redis-instance-open-auth-mode |
|
Tag |
Redis |
|
Automatic remediation |
Not supported |
|
Rule trigger |
Configuration change |
|
Supported resource types |
Redis instance |
|
Input parameters |
None |
Corrective actions
Disable passwordless access for the Redis instance in the VPC. Disable passwordless access in a VPC.