3 ms·
Looks like Amazon's EC2 ELBs have a common 1024 DH. I don't see a way to fix it without moving away from ELBs, or getting Amazon to fix it.
by edgan 11y ago
Looks like Amazon's EC2 ELBs have a common 1024 DH. I don't see a way to fix it without moving away from ELBs, or getting Amazon to fix it.
- zowers 11y agohttps://forums.aws.amazon.com/ann.jspa?annID=3061 https://forums.aws.amazon.com/ann.jspa?annID=3061 > Today, Elastic Load Balancing released a new default SSL Security Policy that no longer includes Ephemeral Diffie-Hellman (DHE) ciphersuites. ELB offers predefined SSL Security Policies to simplify the configuration of your load balancer by providing a recommended cipher suite that adheres to AWS security best practices. 1. Select your load balancer (EC2 - > Load Balancers). 2. In the Listeners tab, click "Change" in the Cipher column. 3. Ensure that the radio button for "Predefined Security Policy" is selected 4. In the dropdown, select the "ELBSecurityPolicy-2015-05" policy. 5. Click "Save" to apply the settings to the listener. 6. Repeat these steps for each listener that is using HTTPS or SSL for each load balancer.