Description
An older CloudFront viewer security policy can allow weak protocols such as SSLv3 or outdated ciphers. Connections negotiated with those settings may provide weaker protection between clients and CloudFront.
minimum_protocol_version selects a security policy defining the minimum viewer protocol and available ciphers. Policy selection differs for custom and default CloudFront certificates; the default certificate uses the TLSv1 policy. TLS to the origin and the handling of HTTP requests are separate settings.
Potential impact
- Connections negotiated with outdated TLS settings may offer weaker confidentiality and integrity.
- Changing policies without checking compatibility can interrupt existing client connections.
Remediation
Choose a supported policy requiring TLS 1.2 or later for the actual certificate and connection method, and test client compatibility. Configure the custom certificate and required SSL support settings correctly. Require or redirect viewer traffic to HTTPS, and review TLS to the origin separately.
Examples
These excerpts show viewer policies for a distribution using a custom certificate. The certificate ARN, SSL support method and cache behaviors are omitted. Supply the settings supported by the actual distribution and installed module.
Before
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
caller_reference: unique-test-distribution-id
origins:
- id: my-test-origin
domain_name: www.example.com
viewer_certificate:
cloudfront_default_certificate: false
minimum_protocol_version: SSLv3
SSLv3 is a legacy policy permitting an old protocol. Check whether the certificate and connection method support this configuration and which policy is actually applied.
After
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
caller_reference: unique-test-distribution-id
origins:
- id: my-test-origin
domain_name: www.example.com
viewer_certificate:
cloudfront_default_certificate: false
minimum_protocol_version: TLSv1.2_2021
TLSv1.2_2021 requires at least TLS 1.2. Review whether a newer policy is suitable and which policies the actual clients support.