CloudFront minimum TLS version is too low

Apply a suitable TLS security policy to CloudFront connections using a custom domain.

Description

A CloudFront viewer security policy that allows versions below TLS 1.2 permits communication using older protocols.

Potential impact

Weaknesses in older protocols and cipher suites can reduce protection for data in transit.

Remediation

For custom domains, set ViewerCertificate.MinimumProtocolVersion to a security policy requiring at least TLS 1.2 and check client compatibility.

Examples

The examples use SNI and a custom certificate. The ACM certificate must be in us-east-1; replace the example ARN with the actual value. This field cannot change the certificate policy for the default CloudFront domain.

Before

yaml
Resources:
  WebDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        ViewerCertificate:
          AcmCertificateArn: arn:aws:acm:us-east-1:123456789012:certificate/example
          MinimumProtocolVersion: TLSv1.1_2016
          SslSupportMethod: sni-only

After

yaml
Resources:
  WebDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        ViewerCertificate:
          AcmCertificateArn: arn:aws:acm:us-east-1:123456789012:certificate/example
          MinimumProtocolVersion: TLSv1.2_2018
          SslSupportMethod: sni-only

References