Description
In a Crossplane Listener, sslPolicy names the ELB security policy that determines the TLS protocols and cipher suites allowed for HTTPS client connections. It does not take an individual cipher-suite name. A policy that permits obsolete protocols or weak cipher suites can weaken connection security.
This policy applies between the client and load balancer. Encryption from the load balancer to its backends needs a separate review.
Potential impact
- Clients can connect using obsolete TLS protocols or weak cipher suites.
- If a vulnerable option is negotiated, the confidentiality or integrity of the connection may be weakened.
Remediation
- Set
sslPolicyto a security policy name supported by the listener. Choose an appropriate policy requiring TLS 1.2 or later, considering organizational requirements and client compatibility. - Check the HTTPS listener certificate and the options actually negotiated, and test that obsolete protocols are rejected.
- Review backend encryption and certificate settings separately.
Examples
These partial examples compare HTTPS listener policies. Supply the remaining required settings, including the load balancer, certificates and default actions, separately.
Before
apiVersion: elbv2.aws.crossplane.io/v1alpha1
kind: Listener
metadata:
name: test-listener
spec:
forProvider:
region: us-east-1
port: 443
protocol: HTTPS
sslPolicy: ELBSecurityPolicy-2016-08
providerConfigRef:
name: example
ELBSecurityPolicy-2016-08 also permits TLS 1.0 and TLS 1.1.
After
apiVersion: elbv2.aws.crossplane.io/v1alpha1
kind: Listener
metadata:
name: test-listener
spec:
forProvider:
region: us-east-1
port: 443
protocol: HTTPS
sslPolicy: ELBSecurityPolicy-TLS13-1-2-2021-06
providerConfigRef:
name: example
ELBSecurityPolicy-TLS13-1-2-2021-06 permits TLS 1.2 and TLS 1.3. Confirm that required clients can connect using this policy before changing it.