Description
When a Classic ELB connection uses HTTP, credentials or sensitive request data on that connection can travel in plaintext. Check protection for both the client-to-ELB and ELB-to-backend connections.
Port 443 alone does not enable encryption. Conversely, a TCP listener can pass TLS through unchanged, so identify where encryption actually terminates.
Potential impact
- An attacker who can observe or alter a plaintext connection may expose data or session information.
- Incorrect certificate or backend protocol changes can disrupt connectivity.
Remediation
If TLS terminates at the ELB, set Protocol to HTTPS or SSL and associate a valid server certificate and an appropriate TLS policy. If backend encryption is required, configure an InstanceProtocol and port supported by the server. Configure a separate backend authentication policy when backend certificate verification is required, and test both connections.
Examples
These listener excerpts omit networking and TLS policies. Replace the certificate ARN with the actual certificate. The after example requires the backend to serve HTTPS on port 80.
Before
Resources:
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
Listeners:
- InstancePort: "80"
InstanceProtocol: HTTP
LoadBalancerPort: "443"
Protocol: HTTP
Although the client port is 443, both Protocol and InstanceProtocol are HTTP, so both connections use plaintext HTTP.
After
Resources:
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
Listeners:
- InstancePort: "80"
InstanceProtocol: HTTPS
LoadBalancerPort: "443"
Protocol: HTTPS
SSLCertificateId: arn:aws:iam::123456789012:server-certificate/my-server-certificate
This specifies HTTPS for both connections. It does not add a backend certificate verification policy; check the required server authentication separately.