Traffic between CloudFront and the origin is not encrypted

Use HTTPS between CloudFront and custom origin servers as well.

Description

If CloudFront connects to a custom origin over HTTP, that connection is unencrypted even when viewers use HTTPS to reach CloudFront.

Potential impact

An actor able to intercept the origin connection can read or alter request or response data.

Remediation

Prepare a certificate so the origin supports HTTPS and set CustomOriginConfig.OriginProtocolPolicy to https-only. Verify the certificate name and successful origin connections.

Examples

The examples are custom origin configuration excerpts. Replace app.example.com with the actual reachable origin host. S3 website endpoints do not support HTTPS and require a different origin configuration.

Before

yaml
Resources:
  WebDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        Origins:
          - DomainName: app.example.com
            Id: app-origin
            CustomOriginConfig:
              OriginProtocolPolicy: http-only

After

yaml
Resources:
  WebDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        Origins:
          - DomainName: app.example.com
            Id: app-origin
            CustomOriginConfig:
              OriginProtocolPolicy: https-only

References