ELB TLS security policy needs review

Remove obsolete protocols and weak ciphers from active Classic ELB TLS policies, and verify compatibility with actual clients.

Description

An HTTPS or SSL listener on a Classic Load Balancer can provide weaker protection if its policy permits weak ciphers or obsolete TLS versions. Using HTTPS alone is insufficient; review the security policy actually associated with the listener.

Potential impact

  • Negotiating a weak combination can reduce transport protection or fail organizational TLS requirements.
  • Changing a policy without checking compatibility can prevent older clients from connecting.

Remediation

  • Select a policy supported by that load balancer type that meets the required TLS-version and cipher standards. Disable unnecessary weak ciphers and obsolete protocols.
  • Check the listener's actual policy association, certificate and client compatibility, then test TLS connections after the change.
  • Manage client-to-load-balancer TLS separately from encryption to target servers. If stronger policies or TLS 1.3 are required, consider a load balancer that supports them.

Examples

These Classic ELB examples require subnets and security groups in the same VPC and a valid certificate ARN. Target registration and network rules must be configured separately. Both use HTTP to the target servers, so neither provides end-to-end encryption.

Before

yaml
Parameters:
  SubnetIds:
    Type: List<AWS::EC2::Subnet::Id>
  SecurityGroupIds:
    Type: List<AWS::EC2::SecurityGroup::Id>
  CertificateArn:
    Type: String
Resources:
  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      Subnets: !Ref SubnetIds
      SecurityGroups: !Ref SecurityGroupIds
      Listeners:
        - InstancePort: "80"
          InstanceProtocol: HTTP
          LoadBalancerPort: "443"
          Protocol: HTTPS
          SSLCertificateId: !Ref CertificateArn
          PolicyNames:
            - My-SSLNegotiation-Policy
      Policies:
        - PolicyName: My-SSLNegotiation-Policy
          PolicyType: SSLNegotiationPolicyType
          Attributes:
            - Name: Reference-Security-Policy
              Value: ELBSecurityPolicy-2015-05

ELBSecurityPolicy-2015-05 permits TLS 1.0 and 1.1 and the 3DES cipher.

After

yaml
Parameters:
  SubnetIds:
    Type: List<AWS::EC2::Subnet::Id>
  SecurityGroupIds:
    Type: List<AWS::EC2::SecurityGroup::Id>
  CertificateArn:
    Type: String
Resources:
  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      Subnets: !Ref SubnetIds
      SecurityGroups: !Ref SecurityGroupIds
      Listeners:
        - InstancePort: "80"
          InstanceProtocol: HTTP
          LoadBalancerPort: "443"
          Protocol: HTTPS
          SSLCertificateId: !Ref CertificateArn
          PolicyNames:
            - My-SSLNegotiation-Policy
      Policies:
        - PolicyName: My-SSLNegotiation-Policy
          PolicyType: SSLNegotiationPolicyType
          Attributes:
            - Name: Reference-Security-Policy
              Value: ELBSecurityPolicy-TLS-1-2-2017-01

ELBSecurityPolicy-TLS-1-2-2017-01 permits only TLS 1.2 and excludes 3DES. It still includes static RSA and CBC ciphers, so verify it against the organization's complete cipher requirements.

References