Review the TLS policy for an API Gateway custom domain

Restrict old protocols with a supported TLS policy and verify client compatibility.

Description

An API Gateway custom domain that permits old TLS versions or unsuitable cipher suites may provide weaker transport protection than required. SecurityPolicy determines the minimum TLS version and cipher suites; omitting it does not mean HTTPS itself is absent.

Supported policies depend on the endpoint and API types. A custom domain policy does not replace backend authentication or the policies of every other invocation endpoint.

Potential impact

  • Continuing to allow old protocols can fail to meet required transport security standards.
  • Strengthening a policy without checking client support can break required connections.

Remediation

Select a supported SecurityPolicy that provides a minimum of TLS 1.2 or later and the required cipher suites for the endpoint. Verify certificates and client compatibility, and test actual TLS negotiation. Apply the additional endpoint settings required when choosing an enhanced policy.

Examples

These excerpts compare legacy TLS policies on an EDGE custom domain. Supply an ACM certificate ARN from us-east-1 matching the domain name through CertificateArn. DNS and API mappings are omitted.

Before

yaml
Resources:
  ApiDomain:
    Type: AWS::ApiGateway::DomainName
    Properties:
      DomainName: api.example.com
      CertificateArn: !Ref CertificateArn
      EndpointConfiguration:
        Types:
          - EDGE
      SecurityPolicy: TLS_1_0

The TLS_1_0 policy allows connections using TLS 1.0 and 1.1, among other versions. Its name does not mean that only that version is used.

After

yaml
Resources:
  ApiDomain:
    Type: AWS::ApiGateway::DomainName
    Properties:
      DomainName: api.example.com
      CertificateArn: !Ref CertificateArn
      EndpointConfiguration:
        Types:
          - EDGE
      SecurityPolicy: TLS_1_2

TLS_1_2 raises the minimum TLS version. Review the need for stronger supported policies and test actual client connections.

References