Description
The default CloudFront certificate is a valid certificate for the default CloudFront domain. Serving HTTPS on a custom domain requires a custom certificate that covers that name. A certificate provides an encrypted connection for the domain; it does not replace access controls on who may view content.
Potential impact
- A mismatch between the service domain and certificate can cause HTTPS connections to fail.
- An unsuitable TLS policy may allow older protocols.
Remediation
- Choose a certificate for the actual service domain. ACM certificates associated with CloudFront must be in
us-east-1. - For a custom certificate, set
ssl_support_method: sni-onlyand aminimum_protocol_versionpolicy that meets the service requirements. - Check whether the default certificate meets those requirements. Restrict content access separately with features such as signed URLs or cookies.
Examples
These excerpts compare a certificate for the default domain with a custom certificate. Custom domain and DNS configuration are omitted. Replace the example ARN with an actual certificate covering a domain you control.
Before
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
default_origin_domain_name: www.my-cloudfront-origin.com
viewer_certificate:
cloudfront_default_certificate: true
This certificate setting is appropriate for the default CloudFront domain. A custom domain or a higher minimum TLS version requires a different configuration.
After
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
default_origin_domain_name: www.my-cloudfront-origin.com
viewer_certificate:
acm_certificate_arn: arn:aws:acm:us-east-1:123456789012:certificate/12345678-1234-1234-1234-123456789012
ssl_support_method: sni-only
minimum_protocol_version: TLSv1.2_2018
This specifies an ACM certificate, SNI and a TLS 1.2 policy. Verify that the certificate names match the domain clients use.