Description
With viewer_protocol_policy: allow-all, CloudFront accepts both HTTP and HTTPS requests for content. HTTP traffic can be intercepted or modified in transit. This setting covers viewers’ connections to CloudFront; connections to the origin need separate protection.
Potential impact
- Request parameters and response content sent over HTTP may be exposed or altered.
- Unprotected credentials or session information sent over HTTP may be abused to access accounts.
Remediation
- Set
viewer_protocol_policytohttps-onlyorredirect-to-httpsfor each cache behavior. - The initial HTTP request before a redirect is unencrypted, so configure clients to use HTTPS from the start.
- Check default and additional cache behaviors, certificates and TLS policy, and protect the origin connection as required.
Examples
These excerpts compare the viewer protocol for the default cache behavior. Other required settings, including cache policy configuration, are omitted.
Before
yaml
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
caller_reference: unique-test-distribution-id
origins:
- id: my-test-origin
domain_name: www.example.com
default_cache_behavior:
target_origin_id: my-test-origin
viewer_protocol_policy: allow-all
allow-all accepts HTTP requests. Offering HTTPS does not protect a request that uses HTTP.
After
yaml
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
caller_reference: unique-test-distribution-id
origins:
- id: my-test-origin
domain_name: www.example.com
default_cache_behavior:
target_origin_id: my-test-origin
viewer_protocol_policy: https-only
https-only rejects HTTP requests. Verify that legitimate clients connect using HTTPS.