Describe the feature
in the past few years I quite often have new security compliance guideline to require us to update the SSL policy on load balancer, however the CDK release schedule simply cannot catch up with how the security guideline release speed. (in this case, we are requested to update to use ELBSecurityPolicy-TLS13-1-2-RFC9151-FIPS-2023-07 this month, it was only released 3 weeks ago)
Currently ApplicationListener SslPolicy only accept the enum object, and I can't use latest SslPolicy without some hack around the base class property override.
Use Case
Allow us freely use any SSL policy supported by AWS instead restrict by SslPolicy enum.
Proposed Solution
Allow sslPolicy field accept string
elbv2.ApplicationListener(
self.scope,
"Listener",
ssl_policy='ELBSecurityPolicy-TLS13-1-2-RFC9151-FIPS-2023-07'
)
# instead of
listener.node.default_child.add_property_override('SslPolicy', 'ELBSecurityPolicy-TLS13-1-2-RFC9151-FIPS-2023-07')
Other Information
https://docs.aws.amazon.com/elasticloadbalancing/latest/application/describe-ssl-policies.html#rfc9151-security-policies
https://aws.amazon.com/about-aws/whats-new/2026/08/aws-application-network/
Acknowledgements
AWS CDK Library version (aws-cdk-lib)
2.266.0
AWS CDK CLI version
2.1135.1
Environment details (OS name and version, etc.)
Linux
Describe the feature
in the past few years I quite often have new security compliance guideline to require us to update the SSL policy on load balancer, however the CDK release schedule simply cannot catch up with how the security guideline release speed. (in this case, we are requested to update to use ELBSecurityPolicy-TLS13-1-2-RFC9151-FIPS-2023-07 this month, it was only released 3 weeks ago)
Currently ApplicationListener SslPolicy only accept the enum object, and I can't use latest SslPolicy without some hack around the base class property override.
Use Case
Allow us freely use any SSL policy supported by AWS instead restrict by SslPolicy enum.
Proposed Solution
Allow sslPolicy field accept string
Other Information
https://docs.aws.amazon.com/elasticloadbalancing/latest/application/describe-ssl-policies.html#rfc9151-security-policies
https://aws.amazon.com/about-aws/whats-new/2026/08/aws-application-network/
Acknowledgements
AWS CDK Library version (aws-cdk-lib)
2.266.0
AWS CDK CLI version
2.1135.1
Environment details (OS name and version, etc.)
Linux