CloudFront viewer certificate settings need review

A CloudFront certificate must cover the domain in use and be paired with the required TLS policy.

Description

The default CloudFront certificate is a valid certificate for the default CloudFront domain. Serving HTTPS on a custom domain requires a custom certificate that covers that name. A certificate provides an encrypted connection for the domain; it does not replace access controls on who may view content.

Potential impact

  • A mismatch between the service domain and certificate can cause HTTPS connections to fail.
  • An unsuitable TLS policy may allow older protocols.

Remediation

  • Choose a certificate for the actual service domain. ACM certificates associated with CloudFront must be in us-east-1.
  • For a custom certificate, set ssl_support_method: sni-only and a minimum_protocol_version policy that meets the service requirements.
  • Check whether the default certificate meets those requirements. Restrict content access separately with features such as signed URLs or cookies.

Examples

These excerpts compare a certificate for the default domain with a custom certificate. Custom domain and DNS configuration are omitted. Replace the example ARN with an actual certificate covering a domain you control.

Before

yaml
- name: CloudFront 배포 생성
  community.aws.cloudfront_distribution:
    state: present
    default_origin_domain_name: www.my-cloudfront-origin.com
    viewer_certificate:
      cloudfront_default_certificate: true

This certificate setting is appropriate for the default CloudFront domain. A custom domain or a higher minimum TLS version requires a different configuration.

After

yaml
- name: CloudFront 배포 생성
  community.aws.cloudfront_distribution:
    state: present
    default_origin_domain_name: www.my-cloudfront-origin.com
    viewer_certificate:
      acm_certificate_arn: arn:aws:acm:us-east-1:123456789012:certificate/12345678-1234-1234-1234-123456789012
      ssl_support_method: sni-only
      minimum_protocol_version: TLSv1.2_2018

This specifies an ACM certificate, SNI and a TLS 1.2 policy. Verify that the certificate names match the domain clients use.

References