Why Perfect Forward Secrecy and ALBs sugests 2016* policy in not right option

TLSv1.0 and TLS1.1 are no longer considered secure. In order to ensure forward secrecy we should select TLSv1.2 security policy with only ECDHE protocols enabled.

