7.4 Enforcing Encryption in Transit: ELB Security Policies, TLS & HTTPS-Only Access

Key Takeaways

  • ALB HTTPS listeners should use an explicit security policy; the API default ELBSecurityPolicy-2016-08 still permits older TLS versions.

  • An HTTP listener that only redirects to HTTPS, plus HTTPS target groups, keeps ALB traffic encrypted from client to target.

  • An NLB TCP listener passes TLS through untouched when only the targets may decrypt traffic; ALB mTLS verify mode authenticates client certificates at the load balancer.

  • Deny statements with aws:SecureTransport false and s3:TlsVersion NumericLessThan 1.3 require HTTPS and TLS 1.3 for S3 access.

  • Databases need their own settings, such as rds.force_ssl for RDS for PostgreSQL and require_secure_transport for RDS for MySQL.

Last updated: September 2026

7.4 Enforcing Encryption in Transit: ELB Security Policies, TLS & HTTPS-Only Access

Skill 5.1.1 asks you to design mechanisms that require encryption when clients connect to resources, for example by configuring Elastic Load Balancing security policies and enforcing TLS. The exam cares less about TLS internals (general TLS concepts were removed from the outline) and more about where each AWS service lets you reject plaintext or weak connections.


Elastic Load Balancing

Application Load Balancer (ALB)

  • HTTPS listener with a certificate from ACM (or imported into ACM or IAM), plus an HTTP listener whose only action redirects to HTTPS (HTTP 301). The AWS Config managed rule alb-http-to-https-redirection-check detects ALBs that don't redirect.
  • Security policy: selects the TLS protocol versions and ciphers the listener accepts. When you create an HTTPS listener in the console, the default policy is ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09, which allows TLS 1.3 and TLS 1.2 with restricted ciphers and hybrid post-quantum key exchange. When you create a listener with the API or CLI without naming a policy, the default is the older ELBSecurityPolicy-2016-08, so infrastructure-as-code templates should always set the policy explicitly.
  • Policy families: TLS 1.3-only policies, FIPS policies (for workloads that must use FIPS 140 validated cryptography), and post-quantum (PQ) policies. Choose the strictest policy your clients support.
  • Mutual TLS (mTLS): In verify mode, the ALB authenticates client certificates against a trust store (CA bundle in S3, optional revocation lists). In passthrough mode, the ALB forwards the client certificate chain to targets in HTTP headers for the application to verify.
  • Re-encryption to targets: Use HTTPS target groups so traffic stays encrypted from the ALB to the targets. The ALB doesn't validate the target's certificate, so self-signed certificates on targets work, but the ALB can't detect an impersonating target.

Network Load Balancer (NLB)

  • A TLS listener terminates TLS on the NLB with an ACM certificate and a security policy, then re-encrypts to TLS targets or forwards in plaintext.
  • A TCP listener passes TLS through untouched when targets must terminate TLS themselves (for example, for end-to-end encryption or client-certificate authentication at the target).

Amazon CloudFront

SettingRecommended ValueEffect
Viewer protocol policyRedirect HTTP to HTTPS, or HTTPS onlyBlocks or upgrades plaintext viewer requests
Viewer security policy (minimum protocol)TLSv1.2_2021 or newerRejects clients using older TLS versions or weak ciphers
Origin protocol policyHTTPS onlyEncrypts traffic from edge to origin
Response headers policyAdd Strict-Transport-Security (HSTS)Tells browsers to use HTTPS for future visits

The viewer certificate for a custom domain must be in ACM in us-east-1.


Requiring TLS in Resource Policies

Many services accept both HTTP and HTTPS endpoints, or accept TLS 1.2 by default. Resource policies close the gap:

{
  "Sid": "DenyInsecureTransport",
  "Effect": "Deny",
  "Principal": "*",
  "Action": "s3:*",
  "Resource": [
    "arn:aws:s3:::payments-data",
    "arn:aws:s3:::payments-data/*"
  ],
  "Condition": { "Bool": { "aws:SecureTransport": "false" } }
}
  • aws:SecureTransport works in S3 bucket policies, SQS queue policies, SNS topic policies, and other resource policies. The Config rule s3-bucket-ssl-requests-only checks S3 buckets for it.
  • s3:TlsVersion is a numeric condition key; "NumericLessThan": { "s3:TlsVersion": "1.3" } in a deny statement requires TLS 1.3. AWS service endpoints already require at least TLS 1.2.
  • EFS file system policies can deny aws:SecureTransport false so that clients must mount with TLS (mount -t efs -o tls).

Enforcing TLS on Data Services

ServiceHow to Require Encryption in Transit
Amazon RDS for PostgreSQL / SQL ServerSet the rds.force_ssl parameter to 1
Amazon RDS for MySQL / MariaDBSet require_secure_transport to ON
Amazon RedshiftSet the require_ssl parameter to true
Amazon ElastiCacheEnable in-transit encryption on the cluster
Amazon OpenSearch ServiceRequire HTTPS for all traffic and choose a TLS security policy (TLS 1.2 minimum)
Amazon API Gateway custom domainsSelect a TLS 1.2 (or stricter) security policy; enable mutual TLS with a trust store in S3 if clients must present certificates
Amazon SNSUse HTTPS subscriptions and deny aws:SecureTransport false in the topic policy

Detecting Gaps at Scale

  • AWS Config managed rules such as alb-http-to-https-redirection-check and s3-bucket-ssl-requests-only, deployed through a conformance pack, find non-compliant resources across accounts.
  • Security Hub CSPM controls report load balancers with HTTP listeners or outdated TLS policies.
  • AWS Firewall Manager can apply consistent AWS WAF and security group policies, and SCPs can deny CreateListener and ModifyListener calls unless the elasticloadbalancing:ListenerProtocol is HTTPS or TLS and the elasticloadbalancing:SecurityPolicy is an approved TLS 1.2 or 1.3 policy.

Specialty Exam Pitfalls

  1. Relying on the API default policy: A listener created by script without a policy gets ELBSecurityPolicy-2016-08; specify a TLS 1.2 or 1.3 policy explicitly.
  2. Assuming HTTPS to the ALB means HTTPS to targets: Configure HTTPS target groups when data must stay encrypted inside the VPC.
  3. Terminating TLS where end-to-end encryption is required: Use an NLB TCP listener (TLS passthrough) if only the target may decrypt.
  4. Forgetting non-HTTP services: Databases and caches need their own TLS settings; a secure load balancer doesn't protect database connections.
Loading diagram...
Where Encryption in Transit Is Enforced
Test Your Knowledge

A security audit finds that several Application Load Balancers created by an infrastructure-as-code pipeline accept TLS 1.0 and TLS 1.1 connections, although load balancers created in the console by the same team only accept TLS 1.2 and 1.3. What is the most likely cause and fix?

A

The pipeline's certificates were imported instead of issued by ACM; reissue them in ACM.

B

Listeners created through the API or CLI without a security policy use the older ELBSecurityPolicy-2016-08 default; set an explicit TLS 1.2 or TLS 1.3 security policy in the templates.

C

The ALBs are missing an AWS WAF web ACL, which is what blocks old TLS versions.

D

The target groups use HTTP instead of HTTPS; change the target group protocol.

Test Your Knowledge

A financial application must ensure that TLS is terminated only on the application servers, because the servers verify client certificates themselves. The load balancer must not decrypt traffic. Which load balancer configuration meets this requirement?

A

An Application Load Balancer with an HTTPS listener and mutual TLS in verify mode.

B

A Network Load Balancer with a TLS listener that re-encrypts to TLS targets.

C

An Application Load Balancer with an HTTP listener that forwards to HTTPS targets.

D

A Network Load Balancer with a TCP listener on port 443 that passes the TLS session through to the targets.

Test Your Knowledge

A company must prove that an S3 bucket holding regulated data never accepts requests over plain HTTP and only accepts TLS 1.3 connections. Which bucket policy statements satisfy both requirements?

A

A Deny statement for all principals when aws:SecureTransport is false, and a Deny statement when s3:TlsVersion is NumericLessThan 1.3.

B

An Allow statement for all principals when aws:SecureTransport is true.

C

A Deny statement when aws:SourceIp is outside the corporate range.

D

Default encryption with SSE-KMS and S3 Bucket Keys enabled.

Test Your Knowledge

A company's application connects to an Amazon RDS for PostgreSQL database. A compliance rule requires the database itself to reject any unencrypted client connection, regardless of how individual applications are configured. What should the security engineer configure?

A

Enable encryption at rest with a customer managed KMS key.

B

Place the database in a private subnet with a restrictive security group.

C

Set the rds.force_ssl parameter to 1 in the DB parameter group associated with the instance.

D

Enable IAM database authentication.

Sections you finish are checked off in the contents.