Review the CloudFront viewer TLS security policy

Use modern TLS protocols and ciphers that meet client requirements.

Description

An older CloudFront viewer security policy can allow weak protocols such as SSLv3 or outdated ciphers. Connections negotiated with those settings may provide weaker protection between clients and CloudFront.

minimum_protocol_version selects a security policy defining the minimum viewer protocol and available ciphers. Policy selection differs for custom and default CloudFront certificates; the default certificate uses the TLSv1 policy. TLS to the origin and the handling of HTTP requests are separate settings.

Potential impact

  • Connections negotiated with outdated TLS settings may offer weaker confidentiality and integrity.
  • Changing policies without checking compatibility can interrupt existing client connections.

Remediation

Choose a supported policy requiring TLS 1.2 or later for the actual certificate and connection method, and test client compatibility. Configure the custom certificate and required SSL support settings correctly. Require or redirect viewer traffic to HTTPS, and review TLS to the origin separately.

Examples

These excerpts show viewer policies for a distribution using a custom certificate. The certificate ARN, SSL support method and cache behaviors are omitted. Supply the settings supported by the actual distribution and installed module.

Before

yaml
- name: CloudFront 배포 생성
  community.aws.cloudfront_distribution:
    state: present
    caller_reference: unique-test-distribution-id
    origins:
      - id: my-test-origin
        domain_name: www.example.com
    viewer_certificate:
      cloudfront_default_certificate: false
      minimum_protocol_version: SSLv3

SSLv3 is a legacy policy permitting an old protocol. Check whether the certificate and connection method support this configuration and which policy is actually applied.

After

yaml
- name: CloudFront 배포 생성
  community.aws.cloudfront_distribution:
    state: present
    caller_reference: unique-test-distribution-id
    origins:
      - id: my-test-origin
        domain_name: www.example.com
    viewer_certificate:
      cloudfront_default_certificate: false
      minimum_protocol_version: TLSv1.2_2021

TLSv1.2_2021 requires at least TLS 1.2. Review whether a newer policy is suitable and which policies the actual clients support.

References