5 ms·
This further reinforces the pattern of terminating TLS at the LB. While this is generally justifiable, it does decrease defense-in-depth.
by DGAP 8y ago
This further reinforces the pattern of terminating TLS at the LB. While this is generally justifiable, it does decrease defense-in-depth.
- jontro 8y agoAfter choosing the certificate and the policy, I click Next:Configure Routing. I can choose the communication protocol (TCP or TLS) that will be used between my NLB and my targets. If I choose TLS, communication is encrypted; this allows you to make use of complete end-to-end encryption in transit: You can still communicate over ssl internally. What do you mean with it will decreases the defence?
- scarface74 8y agoBut then what’s the purpose of terminating at the LB? The two advantages are that it takes the load off of your web server having to decrypt traffic and autorenwal of SSL certs. Once you have to manage your own certs and decrypt at your server, both of those advantages are removed.
- jontro 8y agoHaving the public facing certificate managed by acm and not worrying about deploying those on the instances is a win. I'm not sure how the certificate validation is done LB <-> instance, but if you can have a private CA and use that for intra-communication it would still keep everything encrypted properly
- dc_gregory 8y agoAuto generated self signed certs on the servers
- scarface74 8y agoWhat’s the threat model for someone intercepting traffic between a load balancer and an EC2 instance?
- outworlder 8y agoI'd like to know too. This seems like a case of being on the other side of the airtight hatchway. https://blogs.msdn.microsoft.com/oldnewthing/20060508-22/?p=31283 https://blogs.msdn.microsoft.com/oldnewthing/20060508-22/?p=...
- zokier 8y agoThat is generally AWS stance on the matter too; VPC is considered secure enough. I remember reading something about it in their own blog, but now I could only find this where it is explained: https://kev.inburke.com/kevin/aws-alb-validation-tls-reply/ https://kev.inburke.com/kevin/aws-alb-validation-tls-reply/
- scarface74 8y agoI’ve watched the reinvent videos where they describe the custom hardware NICs they use with their own custom ARM chips to ensure security and that traffic isn’t spoofed.
- tmd83 8y agoWhat's the threat vector if it's not a cloud environment? Also if you have access to either the LB or host wouldn't you get access to the certificate there anyway to decrypt the traffic?
- scarface74 8y agoI agree. Realistically, it’s just as safe to do ssl termination at the LB. However, it’s generally interpreted that to meet certain security compliance’s like HIPAA you have to have end to end encryption and encryption at rest. Someone posted a quoted from the HIPAA regulations where it could be interpreted as not being the case. I don’t think I would risk taking that chance though from a compliance standpoint.
- illumin8 8y agoPlease see this tweet from an AWS principal engineer: https://twitter.com/colmmacc/status/1088516445145784320 https://twitter.com/colmmacc/status/1088516445145784320 "... well, NLB runs on Amazon VPC. On VPC we encapsulate, authenticate and secure traffic at the packet level. Packets can't be spoofed or MITMd on VPC. Traffic only goes where you send it. That makes it possible to use a self-signed, or even expired, certificate on your end."
- a2dictator 8y agoI've had multiple arguments for & against TLS termination. Just to be clear I think TLS termination at the physical LB is a good practice. More specifically I believe that you need to define your trust boundary & setup TLS to terminate before / at your trust boundary. Now if compliance is your only (superfluous) goal, without regard for practical & effective security, then I do not have an answer, but for all other cases, running TLS end to end is bad security practice & contrary to beliefs it actually makes the env less secure, not more.