CloudFront minimum TLS version needs review

A CloudFront viewer TLS policy that permits older protocols can weaken protection in transit.

Description

The CloudFront viewer security policy determines the minimum TLS version and cipher suites used for client connections. A policy that permits TLS 1.0 or 1.1 allows older protocols and may fall short of the service’s encryption requirements.

Potential impact

  • Older protocols and cipher suites can weaken communication security.
  • The distribution may not meet requirements for TLS 1.2 or later.

Remediation

  • For a distribution with a custom certificate, select a supported minimum_protocol_version policy requiring TLS 1.2 or later, and check required client compatibility.
  • The default CloudFront certificate fixes the security policy at TLSv1. Prepare a custom domain and certificate if a higher minimum version is required.
  • Configure HTTPS enforcement for viewers and encryption to the origin separately.

Examples

These excerpts compare TLS policies for a custom certificate. The certificate, ssl_support_method, domain, cache behavior and other settings are omitted.

Before

yaml
- name: create a distribution with an origin and logging
  community.aws.cloudfront_distribution:
    state: present
    caller_reference: unique test distribution ID
    origins:
      - id: my test origin-000111
        domain_name: www.example.com
    logging:
      enabled: true
      include_cookies: false
      bucket: mylogbucket.s3.amazonaws.com
      prefix: myprefix/
    viewer_certificate:
      minimum_protocol_version: TLSv1

The TLSv1 policy permits TLS 1.0 as the minimum version.

After

yaml
- name: create a distribution with an origin and logging
  community.aws.cloudfront_distribution:
    state: present
    caller_reference: unique test distribution ID
    origins:
      - id: my test origin-000111
        domain_name: www.example.com
    logging:
      enabled: true
      include_cookies: false
      bucket: mylogbucket.s3.amazonaws.com
      prefix: myprefix/
    viewer_certificate:
      minimum_protocol_version: TLSv1.2_2018

TLSv1.2_2018 requires at least TLS 1.2. Before applying it, choose a currently supported policy that fits the service’s encryption requirements and clients.

References