Review ELB protocol security settings

Do not allow obsolete SSL/TLS protocols on Classic ELB listeners.

Description

A Classic ELB security policy that permits SSLv2, SSLv3, TLS 1.0 or TLS 1.1 allows clients to connect with outdated encryption protocols. Such connections may be exposed to known protocol weaknesses or fail the service’s transport security requirements.

Check the protocols and ciphers actually applied to the listener, not just the policy name. A frontend policy does not configure TLS for backend connections.

Potential impact

  • Connections that negotiate obsolete protocols may provide weaker protection for confidential data.
  • Removing an outdated policy can disconnect older clients, so compatibility needs to be checked.

Remediation

Remove policies permitting obsolete protocols and select a suitable Classic ELB policy, such as ELBSecurityPolicy-TLS-1-2-2017-01 for TLS 1.2. Check certificate and client compatibility, then associate it through PolicyNames on the HTTPS or SSL listener. Verify the protocols and ciphers negotiated after the change.

Examples

These excerpts compare policy definitions only. Applying the policy requires a certificate and listener, with MySSLPolicy in that listener's PolicyNames.

Before

yaml
Resources:
  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      Policies:
        - PolicyName: MySSLPolicy
          PolicyType: SSLNegotiationPolicyType
          Attributes:
            - Name: Protocol-SSLv2
              Value: true

This historical policy configuration permits SSLv2. Do not retain it on an operational listener.

After

yaml
Resources:
  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      Policies:
        - PolicyName: MySSLPolicy
          PolicyType: SSLNegotiationPolicyType
          Attributes:
            - Name: Reference-Security-Policy
              Value: ELBSecurityPolicy-TLS-1-2-2017-01

This references a predefined policy that permits only TLS 1.2. Defining the policy alone does not associate it with a listener.

References