Aqua CSPM

Insecure Ciphers

Quick Info

Plugin TitleInsecure Ciphers
CloudAWS
CategoryELB
DescriptionDetect use of insecure ciphers on ELBs
More InfoVarious security vulnerabilities have rendered several ciphers insecure. Only the recommended ciphers should be used.
AWS Linkhttp://docs.aws.amazon.com/ElasticLoadBalancing/latest/DeveloperGuide/elb-security-policy-options.html
Recommended ActionUpdate your ELBs to use the recommended cipher suites

Detailed Remediation Steps

  1. Log into the AWS Management Console.
  2. Select the “Services” option and search for EC2.
  3. In the “EC2 Dashboard” scroll down and look for “Load Balancers” and click on “Load Balancers” to get into “Load Balancers” dashboard.
  4. Select the “Load Balancer” which needs to be verified.
  5. Select the “Listeners” tab from the bottom panel and scroll down to the “Cipher” column of HTTPS Listener and click on “Change” option.
  6. From “Select a Cipher” panel select either of “Predefined Security Policy” and “Custom Security Policy”.
  7. Scan the “SSL Cipher Section” from selected “Security Policy” for any insecure ciphers. Refer to the link for all secure ciphers. https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/elb-ssl-security-policy.html#ssl-ciphers
  8. Scroll down and click on “Save” button to make the changes.