AWS Application and Network Load Balancers now support RFC 9151 compliant security policies

AWS Application Load Balancer and Network Load Balancer Updates
AWS Application Load Balancer (ALB) and Network Load Balancer (NLB) now support new TLS-based security policies that comply with RFC 9151 TLS server requirements for Commercial National Security Algorithm (CNSA) 1.0 suite requirements. These policies implement the cryptographic requirements defined by the US National Security Agency (NSA) for secure communications using TLS 1.2 and TLS 1.3 protocols.
Customers who are required to meet CNSA 1.0 TLS security requirements can now use ALB and NLB with RFC 9151 compliant security policies. Broader interoperability policies are also supported, allowing you to implement CNSA by default while maintaining compatibility with non-CNSA clients during their transition to RFC 9151 compliance, minimizing service disruption.
This feature is available for ALB and NLB in all AWS Commercial Regions, the AWS GovCloud (US) Regions, and the China region at no additional cost. To use this capability, update your existing ALB HTTPS listeners or NLB TLS listeners to a RFC 9151 compliant security policy, or select a compliant policy when creating new listeners through the AWS Management Console, CLI, API, or SDK.
What to do
- Update existing ALB HTTPS listeners or NLB TLS listeners to a RFC 9151 compliant security policy.
- Select a compliant policy when creating new listeners through the AWS Management Console, CLI, API, or SDK.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



