Description
Allowing obsolete TLS versions or weak ciphers can weaken protection between viewers and CloudFront. Outdated protocols such as SSLv3 should not be used in production.
For a custom domain, ViewerCertificate.MinimumProtocolVersion selects the security policy defining the minimum protocol and permitted ciphers. With the default CloudFront certificate, the policy is fixed at TLSv1, so that certificate alone cannot enforce TLS 1.2 or higher.
Potential impact
- Connections negotiating obsolete protocols or weak ciphers may be exposed to known weaknesses.
- Raising the minimum version can prevent older clients from connecting, so check compatibility.
Remediation
Select a security policy requiring TLS 1.2 or higher that meets your requirements, and associate a certificate covering the custom domain. Prepare an ACM certificate for CloudFront in us-east-1 and configure SslSupportMethod appropriately. Verify actual client negotiation, and configure HTTPS enforcement and origin connection encryption separately.
Examples
These excerpts compare only certificate settings within DistributionConfig. Domain aliases, origins and cache behavior are omitted. The before configuration also needs a certificate and support method. For the after configuration, supply a us-east-1 ACM certificate ARN covering the domain through ViewerCertificateArn.
Before
Resources:
CloudFrontDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
ViewerCertificate:
MinimumProtocolVersion: SSLv3
This historical configuration sets SSLv3 as the minimum. Even after supplying the omitted certificate settings, do not retain a policy permitting obsolete protocols.
After
Resources:
CloudFrontDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
ViewerCertificate:
AcmCertificateArn: !Ref ViewerCertificateArn
MinimumProtocolVersion: TLSv1.2_2021
SslSupportMethod: sni-only
This uses a custom certificate and the TLSv1.2_2021 policy. Clients must support SNI, and this setting alone does not reject HTTP requests.