Description
An API Gateway custom domain that permits old TLS versions or unsuitable cipher suites may provide weaker transport protection than required. SecurityPolicy determines the minimum TLS version and cipher suites; omitting it does not mean HTTPS itself is absent.
Supported policies depend on the endpoint and API types. A custom domain policy does not replace backend authentication or the policies of every other invocation endpoint.
Potential impact
- Continuing to allow old protocols can fail to meet required transport security standards.
- Strengthening a policy without checking client support can break required connections.
Remediation
Select a supported SecurityPolicy that provides a minimum of TLS 1.2 or later and the required cipher suites for the endpoint. Verify certificates and client compatibility, and test actual TLS negotiation. Apply the additional endpoint settings required when choosing an enhanced policy.
Examples
These excerpts compare legacy TLS policies on an EDGE custom domain. Supply an ACM certificate ARN from us-east-1 matching the domain name through CertificateArn. DNS and API mappings are omitted.
Before
Resources:
ApiDomain:
Type: AWS::ApiGateway::DomainName
Properties:
DomainName: api.example.com
CertificateArn: !Ref CertificateArn
EndpointConfiguration:
Types:
- EDGE
SecurityPolicy: TLS_1_0
The TLS_1_0 policy allows connections using TLS 1.0 and 1.1, among other versions. Its name does not mean that only that version is used.
After
Resources:
ApiDomain:
Type: AWS::ApiGateway::DomainName
Properties:
DomainName: api.example.com
CertificateArn: !Ref CertificateArn
EndpointConfiguration:
Types:
- EDGE
SecurityPolicy: TLS_1_2
TLS_1_2 raises the minimum TLS version. Review the need for stronger supported policies and test actual client connections.