Description
If a load balancer’s TLS listener permits obsolete protocols or weak ciphers, client connection protection may be weaker and required security standards may not be met. The security policy applied to the listener determines what is permitted.
SslPolicy is an AWS security policy name, not a protocol name. Choose a policy for the actual listener type, such as HTTPS on an ALB or TLS on an NLB, and assess connections where TLS terminates elsewhere separately.
Potential impact
- Permitted weak connection options can reduce transport protection.
- Security requirements may be violated or client connections may fail.
Remediation
Select a security policy supported by the load balancer and listener that permits only required TLS versions and ciphers. Configure a valid certificate on the TLS-terminating listener, then test client compatibility and actual negotiation. Protect other segments carrying sensitive traffic separately.
Examples
These examples compare security policies on an ALB HTTPS listener. Supply actual security groups, subnets, target groups and certificate_arn. Check client TLS support before changing the policy.
Before
- name: ALB 생성
community.aws.elb_application_lb:
name: myelb
security_groups:
- sg-12345678
subnets:
- subnet-012345678
- subnet-abcdef000
listeners:
- Protocol: HTTPS
Port: 443
SslPolicy: ELBSecurityPolicy-2016-08
Certificates:
- CertificateArn: "{{ certificate_arn }}"
DefaultActions:
- Type: forward
TargetGroupName: app-tg
state: present
ELBSecurityPolicy-2016-08 also permits TLS 1.0 and 1.1. It does not meet requirements that prohibit those versions.
After
- name: ALB 생성
community.aws.elb_application_lb:
name: myelb
security_groups:
- sg-12345678
subnets:
- subnet-012345678
- subnet-abcdef000
listeners:
- Protocol: HTTPS
Port: 443
SslPolicy: ELBSecurityPolicy-TLS13-1-2-2021-06
Certificates:
- CertificateArn: "{{ certificate_arn }}"
DefaultActions:
- Type: forward
TargetGroupName: app-tg
state: present
ELBSecurityPolicy-TLS13-1-2-2021-06 restricts connections to TLS 1.2 and 1.3. Verify that the certificate and clients also support the policy.