Control: 5.6 Ensure that URL signature is allowed only over https
Description
URL signature is a URL that grants access rights to OSS. You can add signature information to a URL so that you can forward the URL to the third party for authorized access. A URL signature can be provided to the third party for authorized access.
Remediation
Using the management console:
- Logon to OSS console.
- In the bucket-list pane, click on a target OSS bucket.
- Click on
Filesin top middle of the console. - Click on
View Detailsin the right column on a target object. - Set
HTTPStoEnabled.
Default Value:
Enabled.
Usage
Run the control in your terminal:
powerpipe control run alicloud_compliance.control.cis_v200_5_6Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run alicloud_compliance.control.cis_v200_5_6 --shareSQL
This control uses a named query:
select 'arn:acs:::' || account_id as resource, 'info' as status, 'Manual verification required.' as reason , account_id as account_idfrom alicloud_account;