ALB Security Policies ELBSecurityPolicy-2015-05 and ELBSecurityPolicy-2016-08 are not identical depending on region

2

This page for Application Load Balancers states that Security Policies ELBSecurityPolicy-2015-05 and ELBSecurityPolicy-2016-08 are identical.

When using region us-east-1, the two policies appear to be identical.

When using region us-east-2 or ca-central-1, the two policies are not identical. ELBSecurityPolicy-2015-05 has an additional cipher, DHE-RSA-AES128-SHA, that is not present in the output for aws elbv2 describe-ssl-policies ELBSecurityPolicy-2016-08.

I have not checked all regions.

Either the documentation or the security policies per region should be updated.

  • Confirmed as well. Very interesting. The additional policy (DHE-RSA-AES128-SHA) isn't advertised in the ELBv2 (ALB) documentation at all. It is shown on the ELB Classic security policy page for the ELBSecurityPolicy-2015-03 and ELBSecurityPolicy-2015-02 policies.

Rachel
preguntada hace un año316 visualizaciones
1 Respuesta
0

Hello Rachel!

Thank you for contacting AWS re:Post!

I appreciate you for taking the time to bring this issue to our attention. I understand that the security policies claimed to be identical is not the same across all regions. Your examples of us-east-1 vs. us-east-2 helped identify this gap.

I have raised this issue with the service team. I am happy to let you know that they are working on the fix.

Please keep an eye out on https://aws.amazon.com/blogs/aws/ and https://aws.amazon.com/new/ for further updates on releases.

profile pictureAWS
respondido hace un año

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas