ELB listener security policy needs review

Configure an appropriate AWS security policy and certificate for HTTPS or TLS listeners, and verify the allowed protocols and ciphers.

Description

An HTTPS or TLS listener's security policy determines the permitted TLS protocols and ciphers. An outdated policy, or one that does not meet your requirements, may provide insufficient connection protection. SslPolicy takes the name of an AWS security policy supported by the load balancer, not an individual cipher name.

Do not add TLS-only settings indiscriminately to plain HTTP or TCP listeners. If the connection requires encryption, configure the appropriate listener protocol and a valid certificate together.

Potential impact

  • Allowing weak protocols or ciphers can reduce the protection of communications.
  • Unsupported policies or incorrect certificate settings can cause deployment failures or disrupt client connections.

Remediation

  • Identify the load balancer type and listener protocol, then select an appropriate policy from AWS's protocol and cipher lists. ALBs do not support custom security policies.
  • Check client compatibility and certificate validity and domains before changing the policy. Confirm required inputs and listener-update behavior in your Ansible collection version too.
  • Test the deployed listener policy and actual TLS negotiation. A client-to-load-balancer TLS policy alone does not verify the backend connection.

Examples

These alternatives change the HTTPS listener policy on the same ALB. Provide actual security group and subnet IDs from different Availability Zones, a certificate ARN, and the target group. Check your collection's update behavior to preserve existing listeners and other required settings.

Before

yaml
- name: elb3
  community.aws.elb_application_lb:
    name: myelb
    security_groups:
      - "{{ alb_security_group_id }}"
    subnets:
      - "{{ alb_subnet_a_id }}"
      - "{{ alb_subnet_b_id }}"
    listeners:
      - Protocol: HTTPS
        Port: 443
        SslPolicy: ELBSecurityPolicy-2016-08
        Certificates:
          - CertificateArn: "{{ certificate_arn }}"
        DefaultActions:
          - Type: forward
            TargetGroupName: "{{ target_group_name }}"
    state: present

ELBSecurityPolicy-2016-08 is an older policy that also permits TLS 1.0 and 1.1. Review whether those protocol versions are needed.

After

yaml
- name: elb1
  community.aws.elb_application_lb:
    name: myelb
    security_groups:
      - "{{ alb_security_group_id }}"
    subnets:
      - "{{ alb_subnet_a_id }}"
      - "{{ alb_subnet_b_id }}"
    listeners:
      - Protocol: HTTPS
        Port: 443
        SslPolicy: ELBSecurityPolicy-TLS13-1-2-2021-06
        Certificates:
          - CertificateArn: "{{ certificate_arn }}"
        DefaultActions:
          - Type: forward
            TargetGroupName: "{{ target_group_name }}"
    state: present

The replacement policy supports TLS 1.2 and 1.3 without permitting TLS 1.0 or 1.1. Check that its cipher set and client compatibility meet the actual requirements.

References