7.4 Enforcing Encryption in Transit: ELB Security Policies, TLS & HTTPS-Only Access
Key Takeaways
ALB HTTPS listeners should use an explicit security policy; the API default ELBSecurityPolicy-2016-08 still permits older TLS versions.
An HTTP listener that only redirects to HTTPS, plus HTTPS target groups, keeps ALB traffic encrypted from client to target.
An NLB TCP listener passes TLS through untouched when only the targets may decrypt traffic; ALB mTLS verify mode authenticates client certificates at the load balancer.
Deny statements with aws:SecureTransport false and s3:TlsVersion NumericLessThan 1.3 require HTTPS and TLS 1.3 for S3 access.
Databases need their own settings, such as rds.force_ssl for RDS for PostgreSQL and require_secure_transport for RDS for MySQL.
7.4 Enforcing Encryption in Transit: ELB Security Policies, TLS & HTTPS-Only Access
Skill 5.1.1 asks you to design mechanisms that require encryption when clients connect to resources, for example by configuring Elastic Load Balancing security policies and enforcing TLS. The exam cares less about TLS internals (general TLS concepts were removed from the outline) and more about where each AWS service lets you reject plaintext or weak connections.
Elastic Load Balancing
Application Load Balancer (ALB)
- HTTPS listener with a certificate from ACM (or imported into ACM or IAM), plus an HTTP listener whose only action redirects to HTTPS (HTTP 301). The AWS Config managed rule
alb-http-to-https-redirection-checkdetects ALBs that don't redirect. - Security policy: selects the TLS protocol versions and ciphers the listener accepts. When you create an HTTPS listener in the console, the default policy is
ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09, which allows TLS 1.3 and TLS 1.2 with restricted ciphers and hybrid post-quantum key exchange. When you create a listener with the API or CLI without naming a policy, the default is the olderELBSecurityPolicy-2016-08, so infrastructure-as-code templates should always set the policy explicitly. - Policy families: TLS 1.3-only policies, FIPS policies (for workloads that must use FIPS 140 validated cryptography), and post-quantum (PQ) policies. Choose the strictest policy your clients support.
- Mutual TLS (mTLS): In verify mode, the ALB authenticates client certificates against a trust store (CA bundle in S3, optional revocation lists). In passthrough mode, the ALB forwards the client certificate chain to targets in HTTP headers for the application to verify.
- Re-encryption to targets: Use HTTPS target groups so traffic stays encrypted from the ALB to the targets. The ALB doesn't validate the target's certificate, so self-signed certificates on targets work, but the ALB can't detect an impersonating target.
Network Load Balancer (NLB)
- A TLS listener terminates TLS on the NLB with an ACM certificate and a security policy, then re-encrypts to TLS targets or forwards in plaintext.
- A TCP listener passes TLS through untouched when targets must terminate TLS themselves (for example, for end-to-end encryption or client-certificate authentication at the target).
Amazon CloudFront
| Setting | Recommended Value | Effect |
|---|---|---|
| Viewer protocol policy | Redirect HTTP to HTTPS, or HTTPS only | Blocks or upgrades plaintext viewer requests |
| Viewer security policy (minimum protocol) | TLSv1.2_2021 or newer | Rejects clients using older TLS versions or weak ciphers |
| Origin protocol policy | HTTPS only | Encrypts traffic from edge to origin |
| Response headers policy | Add Strict-Transport-Security (HSTS) | Tells browsers to use HTTPS for future visits |
The viewer certificate for a custom domain must be in ACM in us-east-1.
Requiring TLS in Resource Policies
Many services accept both HTTP and HTTPS endpoints, or accept TLS 1.2 by default. Resource policies close the gap:
{
"Sid": "DenyInsecureTransport",
"Effect": "Deny",
"Principal": "*",
"Action": "s3:*",
"Resource": [
"arn:aws:s3:::payments-data",
"arn:aws:s3:::payments-data/*"
],
"Condition": { "Bool": { "aws:SecureTransport": "false" } }
}
aws:SecureTransportworks in S3 bucket policies, SQS queue policies, SNS topic policies, and other resource policies. The Config rules3-bucket-ssl-requests-onlychecks S3 buckets for it.s3:TlsVersionis a numeric condition key;"NumericLessThan": { "s3:TlsVersion": "1.3" }in a deny statement requires TLS 1.3. AWS service endpoints already require at least TLS 1.2.- EFS file system policies can deny
aws:SecureTransportfalse so that clients must mount with TLS (mount -t efs -o tls).
Enforcing TLS on Data Services
| Service | How to Require Encryption in Transit |
|---|---|
| Amazon RDS for PostgreSQL / SQL Server | Set the rds.force_ssl parameter to 1 |
| Amazon RDS for MySQL / MariaDB | Set require_secure_transport to ON |
| Amazon Redshift | Set the require_ssl parameter to true |
| Amazon ElastiCache | Enable in-transit encryption on the cluster |
| Amazon OpenSearch Service | Require HTTPS for all traffic and choose a TLS security policy (TLS 1.2 minimum) |
| Amazon API Gateway custom domains | Select a TLS 1.2 (or stricter) security policy; enable mutual TLS with a trust store in S3 if clients must present certificates |
| Amazon SNS | Use HTTPS subscriptions and deny aws:SecureTransport false in the topic policy |
Detecting Gaps at Scale
- AWS Config managed rules such as
alb-http-to-https-redirection-checkands3-bucket-ssl-requests-only, deployed through a conformance pack, find non-compliant resources across accounts. - Security Hub CSPM controls report load balancers with HTTP listeners or outdated TLS policies.
- AWS Firewall Manager can apply consistent AWS WAF and security group policies, and SCPs can deny
CreateListenerandModifyListenercalls unless theelasticloadbalancing:ListenerProtocolis HTTPS or TLS and theelasticloadbalancing:SecurityPolicyis an approved TLS 1.2 or 1.3 policy.
Specialty Exam Pitfalls
- Relying on the API default policy: A listener created by script without a policy gets
ELBSecurityPolicy-2016-08; specify a TLS 1.2 or 1.3 policy explicitly. - Assuming HTTPS to the ALB means HTTPS to targets: Configure HTTPS target groups when data must stay encrypted inside the VPC.
- Terminating TLS where end-to-end encryption is required: Use an NLB TCP listener (TLS passthrough) if only the target may decrypt.
- Forgetting non-HTTP services: Databases and caches need their own TLS settings; a secure load balancer doesn't protect database connections.
A security audit finds that several Application Load Balancers created by an infrastructure-as-code pipeline accept TLS 1.0 and TLS 1.1 connections, although load balancers created in the console by the same team only accept TLS 1.2 and 1.3. What is the most likely cause and fix?
The pipeline's certificates were imported instead of issued by ACM; reissue them in ACM.
Listeners created through the API or CLI without a security policy use the older ELBSecurityPolicy-2016-08 default; set an explicit TLS 1.2 or TLS 1.3 security policy in the templates.
The ALBs are missing an AWS WAF web ACL, which is what blocks old TLS versions.
The target groups use HTTP instead of HTTPS; change the target group protocol.
A financial application must ensure that TLS is terminated only on the application servers, because the servers verify client certificates themselves. The load balancer must not decrypt traffic. Which load balancer configuration meets this requirement?
An Application Load Balancer with an HTTPS listener and mutual TLS in verify mode.
A Network Load Balancer with a TLS listener that re-encrypts to TLS targets.
An Application Load Balancer with an HTTP listener that forwards to HTTPS targets.
A Network Load Balancer with a TCP listener on port 443 that passes the TLS session through to the targets.
A company must prove that an S3 bucket holding regulated data never accepts requests over plain HTTP and only accepts TLS 1.3 connections. Which bucket policy statements satisfy both requirements?
A Deny statement for all principals when aws:SecureTransport is false, and a Deny statement when s3:TlsVersion is NumericLessThan 1.3.
An Allow statement for all principals when aws:SecureTransport is true.
A Deny statement when aws:SourceIp is outside the corporate range.
Default encryption with SSE-KMS and S3 Bucket Keys enabled.
A company's application connects to an Amazon RDS for PostgreSQL database. A compliance rule requires the database itself to reject any unencrypted client connection, regardless of how individual applications are configured. What should the security engineer configure?
Enable encryption at rest with a customer managed KMS key.
Place the database in a private subnet with a restrictive security group.
Set the rds.force_ssl parameter to 1 in the DB parameter group associated with the instance.
Enable IAM database authentication.
Sections you finish are checked off in the contents.