More Info:

Cloud CDN regional url maps should be configured to block HTTP connection and allow only HTTPS connections.

Risk Level

High

Address

Security

Compliance Standards

GDPR, PCIDSS, NIST, HITRUST, SOC2, NISTCSF

Triage and Remediation

Remediation

To remediate this misconfiguration in GCP using GCP console, you can follow the below steps:

  1. Open the GCP console and navigate to the Cloud CDN page.

  2. Click on the name of the CDN you want to remediate.

  3. Click on the “Url maps” tab.

  4. Select the URL map which you want to remediate.

  5. Click on the “Edit” button at the top of the page.

  6. In the “Host and path rules” section, select the rule which you want to remediate.

  7. In the “Backend service” section, click on the “Advanced” dropdown.

  8. Under “Frontend protocol”, select “HTTPS only”.

  9. Click on the “Save” button to save the changes.

  10. Repeat steps 6-9 for all the rules in the URL map.

  11. Verify that the CDN regional URL maps are now accepting HTTPS connections only by testing it.

By following these steps, you can remediate the misconfiguration of accepting HTTP connections in Cloud CDN regional URL maps in GCP using GCP console.

Additional Reading: