Review the ELB listener TLS security policy

Use a supported security policy for an ELB HTTPS listener and restrict obsolete TLS protocols and weak cipher suites.

Description

In a Crossplane Listener, sslPolicy names the ELB security policy that determines the TLS protocols and cipher suites allowed for HTTPS client connections. It does not take an individual cipher-suite name. A policy that permits obsolete protocols or weak cipher suites can weaken connection security.

This policy applies between the client and load balancer. Encryption from the load balancer to its backends needs a separate review.

Potential impact

  • Clients can connect using obsolete TLS protocols or weak cipher suites.
  • If a vulnerable option is negotiated, the confidentiality or integrity of the connection may be weakened.

Remediation

  • Set sslPolicy to a security policy name supported by the listener. Choose an appropriate policy requiring TLS 1.2 or later, considering organizational requirements and client compatibility.
  • Check the HTTPS listener certificate and the options actually negotiated, and test that obsolete protocols are rejected.
  • Review backend encryption and certificate settings separately.

Examples

These partial examples compare HTTPS listener policies. Supply the remaining required settings, including the load balancer, certificates and default actions, separately.

Before

yaml
apiVersion: elbv2.aws.crossplane.io/v1alpha1
kind: Listener
metadata:
  name: test-listener
spec:
  forProvider:
    region: us-east-1
    port: 443
    protocol: HTTPS
    sslPolicy: ELBSecurityPolicy-2016-08
  providerConfigRef:
    name: example

ELBSecurityPolicy-2016-08 also permits TLS 1.0 and TLS 1.1.

After

yaml
apiVersion: elbv2.aws.crossplane.io/v1alpha1
kind: Listener
metadata:
  name: test-listener
spec:
  forProvider:
    region: us-east-1
    port: 443
    protocol: HTTPS
    sslPolicy: ELBSecurityPolicy-TLS13-1-2-2021-06
  providerConfigRef:
    name: example

ELBSecurityPolicy-TLS13-1-2-2021-06 permits TLS 1.2 and TLS 1.3. Confirm that required clients can connect using this policy before changing it.

References