AWS Application and Network Load Balancers now support RFC 9151 compliant security policies
AWS Application Load Balancer and Network Load Balancer now support new TLS-based security policies compliant with RFC 9151 for CNSA 1.0 requirements, enabling compatibility with both CNSA and non-CNSA clients during transition.
AWS Application Load Balancer (ALB) and Network Load Balancer (NLB) now support new TLS-based security policies that comply with RFC 9151 TLS server requirements for Commercial National Security Algorithm (CNSA) 1.0 suite requirements. These policies implement cryptographic requirements defined by the US National Security Agency (NSA) for secure communications using TLS 1.2 and TLS 1.3 protocols. Customers required to meet CNSA 1.0 TLS security requirements can now use ALB and NLB with RFC 9151 compliant security policies. Broader interoperability policies are also supported, allowing you to implement CNSA by default while maintaining compatibility with non-CNSA clients during their transition to RFC 9151 compliance, minimizing service disruption. This feature is available for ALB and NLB in all AWS Commercial Regions, AWS GovCloud (US) Regions, and the China region at no additional cost. To use this capability, update existing ALB HTTPS listeners or NLB TLS listeners to an RFC 9151 compliant security policy, or select a compliant policy when creating new listeners through the AWS Management Console, CLI, API, or SDK.