ALB Security Policies ELBSecurityPolicy-2015-05 and ELBSecurityPolicy-2016-08 are not identical depending on region

2

This page for Application Load Balancers states that Security Policies ELBSecurityPolicy-2015-05 and ELBSecurityPolicy-2016-08 are identical.

When using region us-east-1, the two policies appear to be identical.

When using region us-east-2 or ca-central-1, the two policies are not identical. ELBSecurityPolicy-2015-05 has an additional cipher, DHE-RSA-AES128-SHA, that is not present in the output for aws elbv2 describe-ssl-policies ELBSecurityPolicy-2016-08.

I have not checked all regions.

Either the documentation or the security policies per region should be updated.

  • Confirmed as well. Very interesting. The additional policy (DHE-RSA-AES128-SHA) isn't advertised in the ELBv2 (ALB) documentation at all. It is shown on the ELB Classic security policy page for the ELBSecurityPolicy-2015-03 and ELBSecurityPolicy-2015-02 policies.

1 Answer
0

Hello Rachel!

Thank you for contacting AWS re:Post!

I appreciate you for taking the time to bring this issue to our attention. I understand that the security policies claimed to be identical is not the same across all regions. Your examples of us-east-1 vs. us-east-2 helped identify this gap.

I have raised this issue with the service team. I am happy to let you know that they are working on the fix.

Please keep an eye out on https://aws.amazon.com/blogs/aws/ and https://aws.amazon.com/new/ for further updates on releases.

profile pictureAWS
answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions