

As traduções são geradas por tradução automática. Em caso de conflito entre o conteúdo da tradução e da versão original em inglês, a versão em inglês prevalecerá.

# Políticas de segurança para o Network Load Balancer
<a name="describe-ssl-policies"></a>

Ao criar um listener TLS, é necessário selecionar uma política de segurança. Uma política de segurança determina quais cifras e protocolos são aceitos nas negociações SSL entre seu balanceador de carga e um cliente. A política de segurança do seu balanceador de carga poderá ser atualizada se seus requisitos mudarem ou quando lançarmos uma nova política de segurança. Para obter mais informações, consulte [Atualizar a política de segurança](listener-update-certificates.md#update-security-policy).

**Considerações**
+ Um receptor TLS exige uma política de segurança. Caso você não especifique uma política de segurança ao criar o receptor, usaremos a política de segurança padrão. A política de segurança padrão depende de como você criou o receptor TLS:
  + **Console**: A política de segurança padrão é `ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09`.
  + **Outros métodos** (por exemplo, o AWS CLI AWS CloudFormation, e o AWS CDK) — A política de segurança padrão é`ELBSecurityPolicy-2016-08`.
+ Políticas de segurança com PQ em seus nomes oferecem troca híbrida de chaves pós-quânticas. Para compatibilidade, eles suportam algoritmos de troca de chaves ML-KEM clássicos e pós-quânticos. Os clientes devem oferecer suporte à troca de chaves ML-KEM para usar TLS híbrido pós-quântico para troca de chaves. As políticas híbridas pós-quânticas oferecem suporte aos algoritmos SeCP256R1, SeCP384R1 e MLKEM768 X25519. MLKEM1024 MLKEM768 Para obter mais informações, consulte [Criptografia pós-quântica](https://aws.amazon.com/security/post-quantum-cryptography/).
+ A AWS recomenda implementar a nova política de segurança baseada em TLS pós-quântico (PQ-TLS) ou. `ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09` `ELBSecurityPolicy-TLS13-1-2-FIPS-PQ-2025-09` Essa política garante compatibilidade com versões anteriores ao oferecer suporte a clientes capazes de negociar PQ-TLS híbrido, somente TLS 1.3 ou somente TLS 1.2, minimizando assim a interrupção do serviço durante a transição para a criptografia pós-quântica. Você pode migrar progressivamente para políticas de segurança mais restritivas à medida que seus aplicativos cliente desenvolvem a capacidade de negociar PQ-TLS para operações de troca de chaves.
+ Você pode habilitar logs de acesso para obter informações sobre as solicitações de TLS enviadas ao Network Load Balancer, analisar padrões de tráfego TLS para gerenciar atualizações de políticas de segurança e solucionar problemas. Ative o registro de acesso para seu balanceador de carga e examine as entradas correspondentes do log de acesso. Para obter mais informações, consulte [Logs de acesso](load-balancer-access-logs.md) e [Consultas de exemplo do Network Load Balancer](https://docs.aws.amazon.com/athena/latest/ug/networkloadbalancer-classic-logs.html#query-nlb-example).
+ Para visualizar a versão do protocolo TLS (posição 5 do campo de registro) e a troca de chaves (posição 13 do campo de registro) para solicitações de acesso ao seu balanceador de carga, ative o registro de acesso e examine as entradas de registro correspondentes. Para obter mais informações, consulte [Logs de acesso](load-balancer-access-logs.md).
+ Você pode restringir quais políticas de segurança estão disponíveis para os usuários em todo o seu Contas da AWS e AWS Organizations usando as [chaves de condição do Elastic Load Balancing](https://docs.aws.amazon.com/elasticloadbalancing/latest/userguide/security_iam_service-with-iam.html) em suas políticas de IAM e controle de serviço (SCPs), respectivamente. Para obter mais informações, consulte [Políticas de controle de serviço (SCPs)](https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html) no *Guia AWS Organizations do usuário*.
+ As políticas que oferecem suporte somente ao TLS 1.3 oferecem suporte ao Forward Secrecy (FS). As políticas que oferecem suporte a TLS 1.3 e TLS 1.2 que têm somente cifras no formato TLS\$1\$1 e ECDHE\$1\$1 também fornecem FS.
+ Os Network Load Balancers oferecem suporte à extensão Extended Master Secret (EMS) para TLS 1.2.

**Conexões de back-end**

Você pode escolher a política de segurança usada para conexões front-end, mas não para conexões backend. A política de segurança para conexões de back-end depende da política de segurança do ouvinte. Se algum de seus ouvintes estiver usando:
+ Política de **TLS pós-quântico FIPS - Uso de conexões de back-end** `ELBSecurityPolicy-TLS13-1-0-FIPS-PQ-2025-09`
+ **Política FIPS - Uso de** conexões de back-end `ELBSecurityPolicy-TLS13-1-0-FIPS-2023-04`
+ **Política de TLS pós-quântico - Uso de conexões de** back-end `ELBSecurityPolicy-TLS13-1-0-PQ-2025-09`
+ **Política TLS 1.3 - Uso de** conexões de back-end `ELBSecurityPolicy-TLS13-1-0-2021-06`
+ Todas as outras políticas TLS que as conexões de back-end usam `ELBSecurityPolicy-2016-08`

Você pode descrever os protocolos e as cifras usando o [describe-ssl-policies](https://docs.aws.amazon.com/cli/latest/reference/elbv2/describe-ssl-policies.html) AWS CLI comando ou consultar as tabelas abaixo.

**Contents**
+ [Políticas de segurança de TLS](#tls-security-policies)
  + [Protocolos por política](#tls-protocols)
  + [Cifras por política](#tls-policy-ciphers)
  + [Políticas por cifra](#tls-cipher-policies)
+ [Políticas de segurança FIPS](#fips-security-policies)
  + [Protocolos por política](#fips-protocols)
  + [Cifras por política](#fips-policy-ciphers)
  + [Políticas por cifra](#fips-cipher-policies)
+ [Políticas de segurança compatíveis com FS](#fs-security-policies)
  + [Protocolos por política](#fs-protocols)
  + [Cifras por política](#fs-policy-ciphers)
  + [Políticas por cifra](#fs-cipher-policies)

## Políticas de segurança de TLS
<a name="tls-security-policies"></a>

Você pode usar as políticas de segurança do TLS para atender aos requisitos de conformidade e padrões de segurança que exigem a desativação de determinadas versões do protocolo TLS ou para oferecer suporte a clientes legados que exigem cifras descontinuadas.

As políticas que oferecem suporte somente ao TLS 1.3 oferecem suporte ao Forward Secrecy (FS). As políticas que oferecem suporte a TLS 1.3 e TLS 1.2 que têm somente cifras no formato TLS\$1\$1 e ECDHE\$1\$1 também fornecem FS.

**Topics**
+ [Protocolos por política](#tls-protocols)
+ [Cifras por política](#tls-policy-ciphers)
+ [Políticas por cifra](#tls-cipher-policies)

### Protocolos por política
<a name="tls-protocols"></a>

A tabela a seguir descreve os protocolos compatíveis com cada política de segurança do TLS.


| Políticas de segurança | TLS 1.3 | TLS 1.2 | TLS 1.1 | TLS 1.0 | 
| --- | --- | --- | --- | --- | 
| ELBSecurityPolítica- TLS13 -1-3-2021-06 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Sim | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-3-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Sim | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-2021-06 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-Res-2021-06 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-Res-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-Ext2-2021-06 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-ext2-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-Ext1-2021-06 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-ext1-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-1-2021-06 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | 
| ELBSecurityPolítica- TLS13 -1-0-2021-06 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | 
| ELBSecurityPolítica- TLS13 -1-0-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | 
| ELBSecurityPolítica-TLS-1-2-EXT-2018-06 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Sim | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica-TLS-1-2-2017-01 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Sim | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica-TLS-1-1-2017-01 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | 
| ELBSecurityPolítica-2016-08 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | 
| ELBSecurityPolítica-2015-05 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | 

### Cifras por política
<a name="tls-policy-ciphers"></a>

A tabela a seguir descreve as cifras compatíveis com cada política de segurança do TLS.


| Política de segurança | Cifras | 
| --- | --- | 
|  ELBSecurityPolítica- TLS13 -1-3-2021-06 ELBSecurityPolítica- TLS13 -1-3-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-2-2021-06 ELBSecurityPolítica- TLS13 -1-2-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-2-Res-2021-06 ELBSecurityPolítica- TLS13 -1-2-Res-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-2-Ext2-2021-06 ELBSecurityPolítica- TLS13 -1-2-ext2-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-2-Ext1-2021-06 ELBSecurityPolítica- TLS13 -1-2-ext1-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica- TLS13 -1-1-2021-06 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-0-2021-06 ELBSecurityPolítica- TLS13 -1-0-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica-TLS-1-2-EXT-2018-06 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica-TLS-1-2-2017-01 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica-TLS-1-1-2017-01 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica-2016-08 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica-2015-05 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 

### Políticas por cifra
<a name="tls-cipher-policies"></a>

A tabela a seguir descreve as políticas de segurança do TLS compatíveis com cada cifra.


| Nome da cifra | Políticas de segurança | Pacote de cifras | 
| --- | --- | --- | 
|  **OpenSSL** — TLS\$1AES\$1128\$1GCM\$1 SHA256 **IANA** — TLS\$1AES\$1128\$1GCM\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 1301 | 
|  **OpenSSL** — TLS\$1AES\$1256\$1GCM\$1 SHA384 **IANA** — TLS\$1AES\$1256\$1GCM\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 1302 | 
|  **OpenSSL** — TLS\$1 \$1 \$1 CHACHA20 POLY1305 SHA256 **IANA** — TLS\$1 \$1 \$1 CHACHA20 POLY1305 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 1303 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 128 GCM- SHA256 **IANA** — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1128\$1GCM\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c02b | 
|  ** ECDHE-RSA-AESOpenSSL** — 128 GCM- SHA256 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1128\$1GCM\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c02f | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 128- SHA256 **IANA — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1128\$1CBC\$1** SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c023 | 
|  ** ECDHE-RSA-AESOpenSSL** — 128- SHA256 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1128\$1CBC\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c027 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 128 SHA **IANA**: TLS\$1ECDHE\$1ECDSA\$1WITH\$1AES\$1128\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c009 | 
|  ** ECDHE-RSA-AESOpenSSL** — 128 SHA **IANA**: TLS\$1ECDHE\$1RSA\$1WITH\$1AES\$1128\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c013 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 256 GCM- SHA384 **IANA** — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1256\$1GCM\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c02c | 
|  ** ECDHE-RSA-AESOpenSSL** — 256 GCM- SHA384 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1256\$1GCM\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c030 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 256- SHA384 **IANA — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1256\$1CBC\$1** SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c024 | 
|  ** ECDHE-RSA-AESOpenSSL** — 256- SHA384 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1256\$1CBC\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c028 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 256 SHA **IANA**: TLS\$1ECDHE\$1ECDSA\$1WITH\$1AES\$1256\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c00a | 
|  ** ECDHE-RSA-AESOpenSSL** — 256 SHA **IANA**: TLS\$1ECDHE\$1RSA\$1WITH\$1AES\$1256\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c014 | 
|  ** AES128OpenSSL** — -GCM- SHA256 **IANA** — TLS\$1RSA\$1COM\$1AES\$1128\$1GCM\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 9c | 
|  ** AES128OpenSSL** — - SHA256 **IANA — TLS\$1RSA\$1COM\$1AES\$1128\$1CBC\$1** SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 3c | 
|  ** AES128OpenSSL** — -SHA **IANA**: TLS\$1RSA\$1WITH\$1AES\$1128\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 2f | 
|  ** AES256OpenSSL** — -GCM- SHA384 **IANA** — TLS\$1RSA\$1COM\$1AES\$1256\$1GCM\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 9d | 
|  ** AES256OpenSSL** — - SHA256 **IANA — TLS\$1RSA\$1COM\$1AES\$1256\$1CBC\$1** SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 3d | 
|  ** AES256OpenSSL** — -SHA **IANA**: TLS\$1RSA\$1WITH\$1AES\$1256\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 35 | 

## Políticas de segurança FIPS
<a name="fips-security-policies"></a>

O Federal Information Processing Standard (FIPS, Padrão de processamento de informações federal) é um padrão de segurança dos governos dos Estados Unidos e do Canadá que especifica os requisitos de segurança para módulos de criptografia que protegem informações confidenciais. Para saber mais, consulte [Federal Information Processing Standard (FIPS) 140](https://aws.amazon.com/compliance/fips/) na página *AWS Cloud Security Compliance*.

Todas as políticas do FIPS utilizam o módulo criptográfico AWS-LC validado pelo FIPS. Para saber mais, consulte a página [AWS-LC Cryptographic Module](https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4631) no site *NIST Cryptographic Module Validation Program*.

**Importante**  
As políticas `ELBSecurityPolicy-TLS13-1-1-FIPS-2023-04` e `ELBSecurityPolicy-TLS13-1-0-FIPS-2023-04` são fornecidas somente para compatibilidade legada. Embora utilizem a criptografia FIPS usando o FIPS140 módulo, eles podem não estar em conformidade com as diretrizes mais recentes do NIST para configuração de TLS.

**Topics**
+ [Protocolos por política](#fips-protocols)
+ [Cifras por política](#fips-policy-ciphers)
+ [Políticas por cifra](#fips-cipher-policies)

### Protocolos por política
<a name="fips-protocols"></a>

A tabela a seguir descreve os protocolos compatíveis com cada política de segurança do FIPS.


| Políticas de segurança | TLS 1.3 | TLS 1.2 | TLS 1.1 | TLS 1.0 | 
| --- | --- | --- | --- | --- | 
| ELBSecurityPolítica- TLS13 -1-3-FIPS-2023-04 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Sim | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-3-FIPS-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Sim | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-FIPS-2023-04 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-FIPS-PQ-2025-09  | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-RES-FIPS-2023-04 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-RES-FIPS-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-ext2-FIPS-2023-04 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-ext2-FIPS-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-ext1-FIPS-2023-04 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-ext1-FIPS-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-EXT0-FIPS-2023-04 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-2-EXT0-FIPS-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica- TLS13 -1-1-FIPS-2023-04 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | 
| ELBSecurityPolítica- TLS13 -1-0-FIPS-2023-04 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | 
| ELBSecurityPolítica- TLS13 -1-0-FIPS-PQ-2025-09 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | 

### Cifras por política
<a name="fips-policy-ciphers"></a>

A tabela a seguir descreve as cifras compatíveis com cada política de segurança do FIPS.


| Política de segurança | Cifras | 
| --- | --- | 
|  ELBSecurityPolítica- TLS13 -1-3-FIPS-2023-04 ELBSecurityPolítica- TLS13 -1-3-FIPS-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-2-FIPS-2023-04 ELBSecurityPolítica- TLS13 -1-2-FIPS-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-2-RES-FIPS-2023-04 ELBSecurityPolítica- TLS13 -1-2-RES-FIPS-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-2-ext2-FIPS-2023-04 ELBSecurityPolítica- TLS13 -1-2-ext2-FIPS-PQ-2025-09   |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-2-ext1-FIPS-2023-04 ELBSecurityPolítica- TLS13 -1-2-ext1-FIPS-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-2-EXT0-FIPS-2023-04 ELBSecurityPolítica- TLS13 -1-2-EXT0-FIPS-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica- TLS13 -1-1-FIPS-2023-04 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
|  ELBSecurityPolítica- TLS13 -1-0-FIPS-2023-04 ELBSecurityPolítica- TLS13 -1-0-FIPS-PQ-2025-09  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 

### Políticas por cifra
<a name="fips-cipher-policies"></a>

A tabela a seguir descreve as políticas de segurança do FIPS compatíveis com cada cifra.


| Nome da cifra | Políticas de segurança | Pacote de cifras | 
| --- | --- | --- | 
|  **OpenSSL** — TLS\$1AES\$1128\$1GCM\$1 SHA256 **IANA** — TLS\$1AES\$1128\$1GCM\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 1301 | 
|  **OpenSSL** — TLS\$1AES\$1256\$1GCM\$1 SHA384 **IANA** — TLS\$1AES\$1256\$1GCM\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 1302 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 128 GCM- SHA256 **IANA** — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1128\$1GCM\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c02b | 
|  ** ECDHE-RSA-AESOpenSSL** — 128 GCM- SHA256 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1128\$1GCM\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c02f | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 128- SHA256 **IANA — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1128\$1CBC\$1** SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c023 | 
|  ** ECDHE-RSA-AESOpenSSL** — 128- SHA256 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1128\$1CBC\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c027 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 128 SHA **IANA**: TLS\$1ECDHE\$1ECDSA\$1WITH\$1AES\$1128\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c009 | 
|  ** ECDHE-RSA-AESOpenSSL** — 128 SHA **IANA**: TLS\$1ECDHE\$1RSA\$1WITH\$1AES\$1128\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c013 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 256 GCM- SHA384 **IANA** — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1256\$1GCM\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c02c | 
|  ** ECDHE-RSA-AESOpenSSL** — 256 GCM- SHA384 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1256\$1GCM\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c030 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 256- SHA384 **IANA — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1256\$1CBC\$1** SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c024 | 
|  ** ECDHE-RSA-AESOpenSSL** — 256- SHA384 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1256\$1CBC\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c028 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 256 SHA **IANA**: TLS\$1ECDHE\$1ECDSA\$1WITH\$1AES\$1256\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c00a | 
|  ** ECDHE-RSA-AESOpenSSL** — 256 SHA **IANA**: TLS\$1ECDHE\$1RSA\$1WITH\$1AES\$1256\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c014 | 
|  ** AES128OpenSSL** — -GCM- SHA256 **IANA** — TLS\$1RSA\$1COM\$1AES\$1128\$1GCM\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 9c | 
|  ** AES128OpenSSL** — - SHA256 **IANA — TLS\$1RSA\$1COM\$1AES\$1128\$1CBC\$1** SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 3c | 
|  ** AES128OpenSSL** — -SHA **IANA**: TLS\$1RSA\$1WITH\$1AES\$1128\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 2f | 
|  ** AES256OpenSSL** — -GCM- SHA384 **IANA** — TLS\$1RSA\$1COM\$1AES\$1256\$1GCM\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 9d | 
|  ** AES256OpenSSL** — - SHA256 **IANA — TLS\$1RSA\$1COM\$1AES\$1256\$1CBC\$1** SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 3d | 
|  ** AES256OpenSSL** — -SHA **IANA**: TLS\$1RSA\$1WITH\$1AES\$1256\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 35 | 

## Políticas de segurança compatíveis com FS
<a name="fs-security-policies"></a>

As políticas de segurança compatíveis com FS (Forward Secrecy) fornecem proteções adicionais contra a espionagem de dados criptografados por meio do uso de uma chave de sessão aleatória exclusiva. Isso evita a decodificação dos dados capturados, mesmo que a chave secreta de longo prazo seja comprometida.

As políticas nesta seção oferecem suporte ao FS, e “FS” está incluído em seus nomes. Entretanto, essas não são as únicas políticas que oferecem suporte ao FS. As políticas que oferecem suporte somente ao TLS 1.3 oferecem suporte ao FS. As políticas que oferecem suporte a TLS 1.3 e TLS 1.2 que têm somente cifras no formato TLS\$1\$1 e ECDHE\$1\$1 também fornecem FS.

**Topics**
+ [Protocolos por política](#fs-protocols)
+ [Cifras por política](#fs-policy-ciphers)
+ [Políticas por cifra](#fs-cipher-policies)

### Protocolos por política
<a name="fs-protocols"></a>

A tabela a seguir descreve os protocolos compatíveis com cada política de segurança com suporte do FS.


| Políticas de segurança | TLS 1.3 | TLS 1.2 | TLS 1.1 | TLS 1.0 | 
| --- | --- | --- | --- | --- | 
| ELBSecurityPolítica-FS-1-2-RES-2020-10 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Sim | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica-FS-1-2-RES-2019-08 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Sim | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica-FS-1-2-2019-08 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Sim | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Nº | 
| ELBSecurityPolítica-FS-1-1-2019-08 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | 
| ELBSecurityPolítica-FS-2018-06 | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/negative_icon.svg) Não | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | ![\[alt text not found\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/images/success_icon.svg) Yes (Sim) | 

### Cifras por política
<a name="fs-policy-ciphers"></a>

A tabela a seguir descreve as cifras para as quais cada política de segurança compatível com FS oferece suporte.


| Política de segurança | Cifras | 
| --- | --- | 
| ELBSecurityPolítica-FS-1-2-RES-2020-10 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica-FS-1-2-RES-2019-08 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica-FS-1-2-2019-08 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica-FS-1-1-2019-08 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 
| ELBSecurityPolítica-FS-2018-06 |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | 

### Políticas por cifra
<a name="fs-cipher-policies"></a>

A tabela a seguir descreve as políticas de segurança com suporte do FS, compatíveis com cada cifra.


| Nome da cifra | Políticas de segurança | Pacote de cifras | 
| --- | --- | --- | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 128 GCM- SHA256 **IANA** — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1128\$1GCM\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c02b | 
|  ** ECDHE-RSA-AESOpenSSL** — 128 GCM- SHA256 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1128\$1GCM\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c02f | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 128- SHA256 **IANA — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1128\$1CBC\$1** SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c023 | 
|  ** ECDHE-RSA-AESOpenSSL** — 128- SHA256 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1128\$1CBC\$1 SHA256  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c027 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 128 SHA **IANA**: TLS\$1ECDHE\$1ECDSA\$1WITH\$1AES\$1128\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c009 | 
|  ** ECDHE-RSA-AESOpenSSL** — 128 SHA **IANA**: TLS\$1ECDHE\$1RSA\$1WITH\$1AES\$1128\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c013 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 256 GCM- SHA384 **IANA** — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1256\$1GCM\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c02c | 
|  ** ECDHE-RSA-AESOpenSSL** — 256 GCM- SHA384 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1256\$1GCM\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c030 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 256- SHA384 **IANA — TLS\$1ECDHE\$1ECDSA\$1COM\$1AES\$1256\$1CBC\$1** SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c024 | 
|  ** ECDHE-RSA-AESOpenSSL** — 256- SHA384 **IANA** — TLS\$1ECDHE\$1RSA\$1COM\$1AES\$1256\$1CBC\$1 SHA384  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c028 | 
|  ** ECDHE-ECDSA-AESOpenSSL** — 256 SHA **IANA**: TLS\$1ECDHE\$1ECDSA\$1WITH\$1AES\$1256\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c00a | 
|  ** ECDHE-RSA-AESOpenSSL** — 256 SHA **IANA**: TLS\$1ECDHE\$1RSA\$1WITH\$1AES\$1256\$1CBC\$1SHA  |  [\[See the AWS documentation website for more details\]](http://docs.aws.amazon.com/pt_br/elasticloadbalancing/latest/network/describe-ssl-policies.html)  | c014 | 