Review ELB transport encryption

Check encryption for client and backend connections separately.

Description

When a Classic ELB connection uses HTTP, credentials or sensitive request data on that connection can travel in plaintext. Check protection for both the client-to-ELB and ELB-to-backend connections.

Port 443 alone does not enable encryption. Conversely, a TCP listener can pass TLS through unchanged, so identify where encryption actually terminates.

Potential impact

  • An attacker who can observe or alter a plaintext connection may expose data or session information.
  • Incorrect certificate or backend protocol changes can disrupt connectivity.

Remediation

If TLS terminates at the ELB, set Protocol to HTTPS or SSL and associate a valid server certificate and an appropriate TLS policy. If backend encryption is required, configure an InstanceProtocol and port supported by the server. Configure a separate backend authentication policy when backend certificate verification is required, and test both connections.

Examples

These listener excerpts omit networking and TLS policies. Replace the certificate ARN with the actual certificate. The after example requires the backend to serve HTTPS on port 80.

Before

yaml
Resources:
  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      Listeners:
        - InstancePort: "80"
          InstanceProtocol: HTTP
          LoadBalancerPort: "443"
          Protocol: HTTP

Although the client port is 443, both Protocol and InstanceProtocol are HTTP, so both connections use plaintext HTTP.

After

yaml
Resources:
  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      Listeners:
        - InstancePort: "80"
          InstanceProtocol: HTTPS
          LoadBalancerPort: "443"
          Protocol: HTTPS
          SSLCertificateId: arn:aws:iam::123456789012:server-certificate/my-server-certificate

This specifies HTTPS for both connections. It does not add a backend certificate verification policy; check the required server authentication separately.

References