Description
An HTTPS or SSL listener on a Classic Load Balancer can provide weaker protection if its policy permits weak ciphers or obsolete TLS versions. Using HTTPS alone is insufficient; review the security policy actually associated with the listener.
Potential impact
- Negotiating a weak combination can reduce transport protection or fail organizational TLS requirements.
- Changing a policy without checking compatibility can prevent older clients from connecting.
Remediation
- Select a policy supported by that load balancer type that meets the required TLS-version and cipher standards. Disable unnecessary weak ciphers and obsolete protocols.
- Check the listener's actual policy association, certificate and client compatibility, then test TLS connections after the change.
- Manage client-to-load-balancer TLS separately from encryption to target servers. If stronger policies or TLS 1.3 are required, consider a load balancer that supports them.
Examples
These Classic ELB examples require subnets and security groups in the same VPC and a valid certificate ARN. Target registration and network rules must be configured separately. Both use HTTP to the target servers, so neither provides end-to-end encryption.
Before
Parameters:
SubnetIds:
Type: List<AWS::EC2::Subnet::Id>
SecurityGroupIds:
Type: List<AWS::EC2::SecurityGroup::Id>
CertificateArn:
Type: String
Resources:
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
Subnets: !Ref SubnetIds
SecurityGroups: !Ref SecurityGroupIds
Listeners:
- InstancePort: "80"
InstanceProtocol: HTTP
LoadBalancerPort: "443"
Protocol: HTTPS
SSLCertificateId: !Ref CertificateArn
PolicyNames:
- My-SSLNegotiation-Policy
Policies:
- PolicyName: My-SSLNegotiation-Policy
PolicyType: SSLNegotiationPolicyType
Attributes:
- Name: Reference-Security-Policy
Value: ELBSecurityPolicy-2015-05
ELBSecurityPolicy-2015-05 permits TLS 1.0 and 1.1 and the 3DES cipher.
After
Parameters:
SubnetIds:
Type: List<AWS::EC2::Subnet::Id>
SecurityGroupIds:
Type: List<AWS::EC2::SecurityGroup::Id>
CertificateArn:
Type: String
Resources:
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
Subnets: !Ref SubnetIds
SecurityGroups: !Ref SecurityGroupIds
Listeners:
- InstancePort: "80"
InstanceProtocol: HTTP
LoadBalancerPort: "443"
Protocol: HTTPS
SSLCertificateId: !Ref CertificateArn
PolicyNames:
- My-SSLNegotiation-Policy
Policies:
- PolicyName: My-SSLNegotiation-Policy
PolicyType: SSLNegotiationPolicyType
Attributes:
- Name: Reference-Security-Policy
Value: ELBSecurityPolicy-TLS-1-2-2017-01
ELBSecurityPolicy-TLS-1-2-2017-01 permits only TLS 1.2 and excludes 3DES. It still includes static RSA and CBC ciphers, so verify it against the organization's complete cipher requirements.