Description
An SLB policy that allows TLS 1.0 or TLS 1.1 permits connections using outdated protocols. Require TLS 1.2 or later to maintain the intended transport protection.
Potential impact
Allowing old protocols can permit connections with known weaknesses or fail organizational TLS requirements.
Remediation
Remove TLSv1.0 and TLSv1.1 from tls_versions and use supported TLSv1.2 and TLSv1.3 versions. Check cipher compatibility and client connections before applying the policy to a listener.
Examples
The examples exclude TLS 1.1. Review cipher suites separately and prefer forward secrecy unless compatibility requires otherwise.
Before
hcl
resource "alicloud_slb_tls_cipher_policy" "policy" {
tls_cipher_policy_name = "Test-example_value"
tls_versions = ["TLSv1.1", "TLSv1.2"]
ciphers = ["AES256-SHA", "AES256-SHA256", "AES128-GCM-SHA256"]
}
After
hcl
resource "alicloud_slb_tls_cipher_policy" "policy" {
tls_cipher_policy_name = "Test-example_value"
tls_versions = ["TLSv1.2", "TLSv1.3"]
ciphers = ["AES256-SHA256", "AES128-GCM-SHA256", "TLS_AES_256_GCM_SHA384"]
}