Alicloud SLB policy allows outdated TLS versions

Remove TLS 1.0 and TLS 1.1 from the allowed versions.

Description

An SLB policy that allows TLS 1.0 or TLS 1.1 permits connections using outdated protocols. Require TLS 1.2 or later to maintain the intended transport protection.

Potential impact

Allowing old protocols can permit connections with known weaknesses or fail organizational TLS requirements.

Remediation

Remove TLSv1.0 and TLSv1.1 from tls_versions and use supported TLSv1.2 and TLSv1.3 versions. Check cipher compatibility and client connections before applying the policy to a listener.

Examples

The examples exclude TLS 1.1. Review cipher suites separately and prefer forward secrecy unless compatibility requires otherwise.

Before

hcl
resource "alicloud_slb_tls_cipher_policy" "policy" {
  tls_cipher_policy_name = "Test-example_value"
  tls_versions           = ["TLSv1.1", "TLSv1.2"]
  ciphers                = ["AES256-SHA", "AES256-SHA256", "AES128-GCM-SHA256"]
}

After

hcl
resource "alicloud_slb_tls_cipher_policy" "policy" {
  tls_cipher_policy_name = "Test-example_value"
  tls_versions           = ["TLSv1.2", "TLSv1.3"]
  ciphers                = ["AES256-SHA256", "AES128-GCM-SHA256", "TLS_AES_256_GCM_SHA384"]
}

References