From 4db109bb26d16bdd5860ddd8a49366bf2de1557e Mon Sep 17 00:00:00 2001 From: jonjozwiak Date: Wed, 10 Jun 2020 15:46:34 -0500 Subject: [PATCH] Fixing profile and region settings for check_extra792 - ELB SSL ciphers --- checks/check_extra792 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/checks/check_extra792 b/checks/check_extra792 index 83cf47eb..2a119117 100644 --- a/checks/check_extra792 +++ b/checks/check_extra792 @@ -30,7 +30,7 @@ extra792(){ ELBSECURECIPHERS=("Protocol-TLSv1.2" "Protocol-TLSv1.1" "Protocol-TLSv1" "ECDHE-ECDSA-AES128-GCM-SHA256" "ECDHE-RSA-AES128-GCM-SHA256" "ECDHE-ECDSA-AES128-SHA256" "ECDHE-RSA-AES128-SHA256" "ECDHE-ECDSA-AES128-SHA" "ECDHE-RSA-AES128-SHA" "ECDHE-ECDSA-AES256-GCM-SHA384" "ECDHE-RSA-AES256-GCM-SHA384" "ECDHE-ECDSA-AES256-SHA384" "ECDHE-RSA-AES256-SHA384" "ECDHE-RSA-AES256-SHA" "ECDHE-ECDSA-AES256-SHA" "AES128-GCM-SHA256" "AES128-SHA256" "AES128-SHA" "AES256-GCM-SHA384" "AES256-SHA256" "AES256-SHA" "Server-Defined-Cipher-Order") for elb in $LIST_OF_ELBS; do - ELB_POLICIES=$($AWSCLI elb describe-load-balancers --load-balancer-name $elb --query "LoadBalancerDescriptions[0].ListenerDescriptions[*].PolicyNames" --output text) + ELB_POLICIES=$($AWSCLI elb describe-load-balancers $PROFILE_OPT --region $regx --load-balancer-name $elb --query "LoadBalancerDescriptions[0].ListenerDescriptions[*].PolicyNames" --output text) passed=true for policy in $ELB_POLICIES; do # Check for secure default policy