Description
An HTTPS or TLS listener's security policy determines the permitted TLS protocols and ciphers. An outdated policy, or one that does not meet your requirements, may provide insufficient connection protection. SslPolicy takes the name of an AWS security policy supported by the load balancer, not an individual cipher name.
Do not add TLS-only settings indiscriminately to plain HTTP or TCP listeners. If the connection requires encryption, configure the appropriate listener protocol and a valid certificate together.
Potential impact
- Allowing weak protocols or ciphers can reduce the protection of communications.
- Unsupported policies or incorrect certificate settings can cause deployment failures or disrupt client connections.
Remediation
- Identify the load balancer type and listener protocol, then select an appropriate policy from AWS's protocol and cipher lists. ALBs do not support custom security policies.
- Check client compatibility and certificate validity and domains before changing the policy. Confirm required inputs and listener-update behavior in your Ansible collection version too.
- Test the deployed listener policy and actual TLS negotiation. A client-to-load-balancer TLS policy alone does not verify the backend connection.
Examples
These alternatives change the HTTPS listener policy on the same ALB. Provide actual security group and subnet IDs from different Availability Zones, a certificate ARN, and the target group. Check your collection's update behavior to preserve existing listeners and other required settings.
Before
- name: elb3
community.aws.elb_application_lb:
name: myelb
security_groups:
- "{{ alb_security_group_id }}"
subnets:
- "{{ alb_subnet_a_id }}"
- "{{ alb_subnet_b_id }}"
listeners:
- Protocol: HTTPS
Port: 443
SslPolicy: ELBSecurityPolicy-2016-08
Certificates:
- CertificateArn: "{{ certificate_arn }}"
DefaultActions:
- Type: forward
TargetGroupName: "{{ target_group_name }}"
state: present
ELBSecurityPolicy-2016-08 is an older policy that also permits TLS 1.0 and 1.1. Review whether those protocol versions are needed.
After
- name: elb1
community.aws.elb_application_lb:
name: myelb
security_groups:
- "{{ alb_security_group_id }}"
subnets:
- "{{ alb_subnet_a_id }}"
- "{{ alb_subnet_b_id }}"
listeners:
- Protocol: HTTPS
Port: 443
SslPolicy: ELBSecurityPolicy-TLS13-1-2-2021-06
Certificates:
- CertificateArn: "{{ certificate_arn }}"
DefaultActions:
- Type: forward
TargetGroupName: "{{ target_group_name }}"
state: present
The replacement policy supports TLS 1.2 and 1.3 without permitting TLS 1.0 or 1.1. Check that its cipher set and client compatibility meet the actual requirements.