π‘οΈ AWS ELB Load Balancer listener is configured with an outdated security policyπ’
- Contextual name: π‘οΈ Load Balancer listener is configured with an outdated security policyπ’
- ID:
/ce/ca/aws/elb/load-balancer-listener-security-policy - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicβ
- π§ prod.logic.yamlπ’
Similar Policiesβ
- AWS Security Hub: [ELB.17] Application and Network Load Balancers with listeners should use recommended security policies
Descriptionβ
Descriptionβ
This policy identifies AWS Application and Network Load Balancers with listeners configured to use outdated SSL/TLS security policies that permit deprecated protocol versions or weak cryptographic ciphers.
Rationaleβ
AWS provides predefined security policies for load balancer listeners that govern the protocols and cipher suites used during the SSL/TLS handshake. Older protocol versions, such as TLS 1.0 and TLS 1.1, are considered insecure and have been deprecated by industry standards and major compliance frameworks.
Modern security policies (for example,
ELBSecurityPolicy-TLS13-1-3-2021-06) enforce stronger cryptographic controls by requiring TLS 1.2 or TLS 1.3 and by limiting connections to secure, approved cipher suites. Using these policies helps protect data in transit from known cryptographic weaknesses and downgrade attacks.Auditβ
This policy flags an AWS ELB Load Balancer as
INCOMPLIANTif any related AWS ELB Load Balancer Listener is configured with aPolicy Namethat is not one of the following recommended policies:... see more
Remediationβ
Remediationβ
Update the SSL/TLS Security Policy for a Load Balancer Listenerβ
Applying an up-to-date security policy ensures that only secure protocol versions and strong cryptographic ciphers are used for client connections.
From Command Lineβ
Run the following command to update the SSL/TLS policy associated with the HTTPS listener:
aws elbv2 modify-listener \
--listener-arn {{listener-arn}} \
--ssl-policy ELBSecurityPolicy-TLS13-1-3-2021-06