AWS Classic ELB cipher policies need review

Remove weak ciphers from the TLS policy applied to the listener.

Description

Allowing weak ciphers such as RC4 or DES on a Classic ELB TLS listener can weaken protection between clients and the load balancer. Review the active protocols and ciphers in the policy actually attached to the listener.

Defining a policy and applying it to a listener are separate steps. Also check that the certificate key type and clients support the selected ciphers.

Potential impact

  • Connections negotiated with weak ciphers can provide weaker protection for traffic.
  • The configuration may fail required TLS standards or reject incompatible clients.

Remediation

Remove weak ciphers and use a security policy supported by the Classic Load Balancer that meets your requirements. Attach it to the TLS listener and check protocol, cipher and certificate compatibility. Test that intended clients connect and disallowed ciphers are rejected.

Examples

These are excerpts of a custom Classic ELB policy. The load balancer, certificate and listener association are omitted.

Before

hcl
resource "aws_load_balancer_policy" "elb_ssl_policy" {
  load_balancer_name = aws_elb.wu_tang.name
  policy_name        = "wu-tang-ssl"
  policy_type_name   = "SSLNegotiationPolicyType"

  policy_attribute {
    name  = "RC4-SHA"
    value = "true"
  }
}

This enables RC4-SHA. Remove it from production policies.

After

hcl
resource "aws_load_balancer_policy" "elb_ssl_policy" {
  load_balancer_name = aws_elb.wu_tang.name
  policy_name        = "wu-tang-ssl"
  policy_type_name   = "SSLNegotiationPolicyType"

  policy_attribute {
    name  = "ECDHE-ECDSA-AES128-GCM-SHA256"
    value = "true"
  }

  policy_attribute {
    name  = "Protocol-TLSv1.2"
    value = "true"
  }
}

This selects TLS 1.2 and ECDHE-ECDSA-AES128-GCM-SHA256. The ECDSA-only example needs a compatible certificate; select RSA-compatible ciphers when using an RSA certificate.

References