More Info:

Your Amazon API Gateway APIs should be using SSL certificates to verify that HTTP requests made to your backend system are from API Gateway service.

Risk Level

Medium

Address

Security

Compliance Standards

NIST

Triage and Remediation

Check Cause

  1. Sign in to the AWS Management Console.
  2. Navigate to the API Gateway service by typing ‘API Gateway’ in the search bar and selecting it from the dropdown menu.
  3. In the API Gateway dashboard, you will see a list of all your APIs. Select the API you want to check.
  4. Once you’ve selected the API, navigate to the ‘Custom Domain Names’ section in the left-hand menu. Here, you can see if an SSL certificate is associated with your API. If there is no SSL certificate, or if it’s expired, then it’s a misconfiguration.

Additional Reading: