Description
A CloudFront viewer security policy that allows versions below TLS 1.2 permits communication using older protocols.
Potential impact
Weaknesses in older protocols and cipher suites can reduce protection for data in transit.
Remediation
For custom domains, set ViewerCertificate.MinimumProtocolVersion to a security policy requiring at least TLS 1.2 and check client compatibility.
Examples
The examples use SNI and a custom certificate. The ACM certificate must be in us-east-1; replace the example ARN with the actual value. This field cannot change the certificate policy for the default CloudFront domain.
Before
yaml
Resources:
WebDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
ViewerCertificate:
AcmCertificateArn: arn:aws:acm:us-east-1:123456789012:certificate/example
MinimumProtocolVersion: TLSv1.1_2016
SslSupportMethod: sni-only
After
yaml
Resources:
WebDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
ViewerCertificate:
AcmCertificateArn: arn:aws:acm:us-east-1:123456789012:certificate/example
MinimumProtocolVersion: TLSv1.2_2018
SslSupportMethod: sni-only