Description
If CloudFront connects to a custom origin over HTTP, that connection is unencrypted even when viewers use HTTPS to reach CloudFront.
Potential impact
An actor able to intercept the origin connection can read or alter request or response data.
Remediation
Prepare a certificate so the origin supports HTTPS and set CustomOriginConfig.OriginProtocolPolicy to https-only. Verify the certificate name and successful origin connections.
Examples
The examples are custom origin configuration excerpts. Replace app.example.com with the actual reachable origin host. S3 website endpoints do not support HTTPS and require a different origin configuration.
Before
yaml
Resources:
WebDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Origins:
- DomainName: app.example.com
Id: app-origin
CustomOriginConfig:
OriginProtocolPolicy: http-only
After
yaml
Resources:
WebDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Origins:
- DomainName: app.example.com
Id: app-origin
CustomOriginConfig:
OriginProtocolPolicy: https-only