Review the TLS security policy on an ELB listener

Use TLS protocols and ciphers appropriate for the listener and client requirements.

Description

If a load balancer’s TLS listener permits obsolete protocols or weak ciphers, client connection protection may be weaker and required security standards may not be met. The security policy applied to the listener determines what is permitted.

SslPolicy is an AWS security policy name, not a protocol name. Choose a policy for the actual listener type, such as HTTPS on an ALB or TLS on an NLB, and assess connections where TLS terminates elsewhere separately.

Potential impact

  • Permitted weak connection options can reduce transport protection.
  • Security requirements may be violated or client connections may fail.

Remediation

Select a security policy supported by the load balancer and listener that permits only required TLS versions and ciphers. Configure a valid certificate on the TLS-terminating listener, then test client compatibility and actual negotiation. Protect other segments carrying sensitive traffic separately.

Examples

These examples compare security policies on an ALB HTTPS listener. Supply actual security groups, subnets, target groups and certificate_arn. Check client TLS support before changing the policy.

Before

yaml
- name: ALB 생성
  community.aws.elb_application_lb:
    name: myelb
    security_groups:
      - sg-12345678
    subnets:
      - subnet-012345678
      - subnet-abcdef000
    listeners:
      - Protocol: HTTPS
        Port: 443
        SslPolicy: ELBSecurityPolicy-2016-08
        Certificates:
          - CertificateArn: "{{ certificate_arn }}"
        DefaultActions:
          - Type: forward
            TargetGroupName: app-tg
    state: present

ELBSecurityPolicy-2016-08 also permits TLS 1.0 and 1.1. It does not meet requirements that prohibit those versions.

After

yaml
- name: ALB 생성
  community.aws.elb_application_lb:
    name: myelb
    security_groups:
      - sg-12345678
    subnets:
      - subnet-012345678
      - subnet-abcdef000
    listeners:
      - Protocol: HTTPS
        Port: 443
        SslPolicy: ELBSecurityPolicy-TLS13-1-2-2021-06
        Certificates:
          - CertificateArn: "{{ certificate_arn }}"
        DefaultActions:
          - Type: forward
            TargetGroupName: app-tg
    state: present

ELBSecurityPolicy-TLS13-1-2-2021-06 restricts connections to TLS 1.2 and 1.3. Verify that the certificate and clients also support the policy.

References