Description
The CloudFront viewer security policy determines the minimum TLS version and cipher suites used for client connections. A policy that permits TLS 1.0 or 1.1 allows older protocols and may fall short of the service’s encryption requirements.
Potential impact
- Older protocols and cipher suites can weaken communication security.
- The distribution may not meet requirements for TLS 1.2 or later.
Remediation
- For a distribution with a custom certificate, select a supported
minimum_protocol_versionpolicy requiring TLS 1.2 or later, and check required client compatibility. - The default CloudFront certificate fixes the security policy at
TLSv1. Prepare a custom domain and certificate if a higher minimum version is required. - Configure HTTPS enforcement for viewers and encryption to the origin separately.
Examples
These excerpts compare TLS policies for a custom certificate. The certificate, ssl_support_method, domain, cache behavior and other settings are omitted.
Before
yaml
- name: create a distribution with an origin and logging
community.aws.cloudfront_distribution:
state: present
caller_reference: unique test distribution ID
origins:
- id: my test origin-000111
domain_name: www.example.com
logging:
enabled: true
include_cookies: false
bucket: mylogbucket.s3.amazonaws.com
prefix: myprefix/
viewer_certificate:
minimum_protocol_version: TLSv1
The TLSv1 policy permits TLS 1.0 as the minimum version.
After
yaml
- name: create a distribution with an origin and logging
community.aws.cloudfront_distribution:
state: present
caller_reference: unique test distribution ID
origins:
- id: my test origin-000111
domain_name: www.example.com
logging:
enabled: true
include_cookies: false
bucket: mylogbucket.s3.amazonaws.com
prefix: myprefix/
viewer_certificate:
minimum_protocol_version: TLSv1.2_2018
TLSv1.2_2018 requires at least TLS 1.2. Before applying it, choose a currently supported policy that fits the service’s encryption requirements and clients.