Description
A Classic ELB security policy that permits SSLv2, SSLv3, TLS 1.0 or TLS 1.1 allows clients to connect with outdated encryption protocols. Such connections may be exposed to known protocol weaknesses or fail the service’s transport security requirements.
Check the protocols and ciphers actually applied to the listener, not just the policy name. A frontend policy does not configure TLS for backend connections.
Potential impact
- Connections that negotiate obsolete protocols may provide weaker protection for confidential data.
- Removing an outdated policy can disconnect older clients, so compatibility needs to be checked.
Remediation
Remove policies permitting obsolete protocols and select a suitable Classic ELB policy, such as ELBSecurityPolicy-TLS-1-2-2017-01 for TLS 1.2. Check certificate and client compatibility, then associate it through PolicyNames on the HTTPS or SSL listener. Verify the protocols and ciphers negotiated after the change.
Examples
These excerpts compare policy definitions only. Applying the policy requires a certificate and listener, with MySSLPolicy in that listener's PolicyNames.
Before
Resources:
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
Policies:
- PolicyName: MySSLPolicy
PolicyType: SSLNegotiationPolicyType
Attributes:
- Name: Protocol-SSLv2
Value: true
This historical policy configuration permits SSLv2. Do not retain it on an operational listener.
After
Resources:
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
Policies:
- PolicyName: MySSLPolicy
PolicyType: SSLNegotiationPolicyType
Attributes:
- Name: Reference-Security-Policy
Value: ELBSecurityPolicy-TLS-1-2-2017-01
This references a predefined policy that permits only TLS 1.2. Defining the policy alone does not associate it with a listener.