fix: acm certificate export defaults to ENABLED when options block is omitted#47414
Open
kantajpn wants to merge 1 commit intohashicorp:mainfrom
Open
fix: acm certificate export defaults to ENABLED when options block is omitted#47414kantajpn wants to merge 1 commit intohashicorp:mainfrom
kantajpn wants to merge 1 commit intohashicorp:mainfrom
Conversation
Contributor
Community GuidelinesThis comment is added to every new Pull Request to provide quick reference to how the Terraform AWS Provider is maintained. Please review the information below, and thank you for contributing to the community that keeps the provider thriving! 🚀 Voting for Prioritization
Pull Request Authors
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rollback Plan
If a change needs to be reverted, we will publish an updated version of the library.
Changes to Security Controls
This fix changes the default value of
exportinoptionsfromENABLEDtoDISABLED, which reduces the attack surface by preventing unintended certificate exports. No other security controls are affected.Description
When the options block is omitted from
aws_acm_certificate, theexportattribute incorrectly defaults toENABLEDinstead ofDISABLED.The root cause is that
certificate_transparency_logging_preferencehas Default:ENABLED, which causes the options object to always be sent to the AWS API even when the block is omitted. When AWS receives anOptionsobject without an explicit Export value, it sets Export toENABLED. In contrast, when no Options object is sent at all (e.g., via AWS CLI), AWS defaults toDISABLED.This fix explicitly sets Export:
DISABLEDin expandCertificateOptions when no value is provided, matching the behavior of the AWS CLI and Console.Relations
Closes #46498
References
Output from Acceptance Testing
I was unable to run acceptance tests due to the cost of AWS Private CA. The existing
TestAccACMCertificate_emailValidation testcovers this fix by verifying that options.0.export defaults to DISABLED when the options block is omitted.