When you configure an HTTPS listener for an Application Load Balancer (ALB) instance, a TLS security policy determines the TLS protocol versions and cipher suites supported during TLS negotiation between the ALB instance and the client. During the TLS handshake, the client sends a list of supported protocol versions and cipher suites via the Client Hello message. Based on the configured TLS security policy, the ALB instance selects a protocol version and cipher suite combination supported by both parties to complete the handshake.
ALB provides the following 2 types of policies: default and custom policies.
Default policy: The common TLS security policy preset by the system. It covers various combinations of TLS versions and cipher suites and can be directly selected for use.
Custom policy: If the default policy cannot meet specific security and compliance requirements, you can create a custom policy to flexibly specify TLS versions and cipher suites.
This document describes how to create, edit, and delete a custom TLS security policy in the ALB console.
Prerequisites
Creating a Custom Policy
1. Log in to the ALB console and choose ALB > TLS Security Policy in the left sidebar. 2. Select a region at the top of the page, select the Custom Policy tab, and click Create Custom Policy.
3. In the Create Custom Policy panel displayed on the right, configure the policy information based on the table below. After configuration, click OK.
|
TLS Security Policy Name | Customize the name of the TLS security policy. The TLS security policy name can contain 2 to 128 characters, including letters, digits, Chinese characters, periods, underscores, and hyphens. It must start with a letter or Chinese character. |
Minimum TLS Version | Select the minimum TLS protocol version supported by this policy. You can select it from the drop-down list. The available options include: TLS 1.2, TLS 1.1 and later, and TLS 1.0 and later. If your service has no specific compatibility requirements, it is recommended that you select TLS 1.2 or later to ensure security. |
Enable TLS 1.3. | Determine whether to additionally enable TLS 1.3. After it is enabled, the TLS policy additionally supports TLS 1.3 on top of the selected earliest TLS version. Provided that business compatibility is maintained, it is recommended that you enable TLS 1.3 to improve the security and efficiency of communications. |
Cipher Suite | Select the cipher suites supported by the TLS version. The panel is divided into left and right columns. Left: list of available cipher suites Right: list of selected cipher suites |
Tag | You can select a tag key and a tag value or add a tag. For details, see Creating a Tag. |
Attention:
If TLS 1.2 and TLS 1.3 are enabled, you need to select at least 1 cipher suite that supports TLS 1.2. Otherwise, the policy cannot be created. You need to make sure that corresponding cipher suites are selected for each enabled TLS version.
Editing a Custom Policy
1. Go to the TLS security policy page and select the Custom Policy tab.
2. Locate the target policy and click Edit in the Operation column.
3. In the editing panel, modify information such as TLS Version and Cipher Suite. After the modification is completed, click OK.
Attention:
Modifying a TLS security policy affects the TLS negotiation behavior of associated listeners. It is recommended that you perform this operation during off-peak business hours and verify that client access is normal after the change. If any exceptions occur, you can immediately revert to the original policy to roll back the change.
Deleting a Custom Policy
1. Go to the TLS security policy page and select the Custom Policy tab.
2. Locate the target policy and choose More > Delete in the Operation column.
3. In the displayed Confirm dialog box, confirm that the information is correct, and click OK to complete the deletion.
Attention:
If a custom policy is referenced by an HTTPS listener, you need to first modify the listener's TLS security policy (change it to another policy) or delete the listener before deleting this custom policy.
The system default policy cannot be edited or deleted.