Review the CloudFront TLS security policy

Review the minimum TLS version and ciphers used for CloudFront viewer connections.

Description

Allowing obsolete TLS versions or weak ciphers can weaken protection between viewers and CloudFront. Outdated protocols such as SSLv3 should not be used in production.

For a custom domain, ViewerCertificate.MinimumProtocolVersion selects the security policy defining the minimum protocol and permitted ciphers. With the default CloudFront certificate, the policy is fixed at TLSv1, so that certificate alone cannot enforce TLS 1.2 or higher.

Potential impact

  • Connections negotiating obsolete protocols or weak ciphers may be exposed to known weaknesses.
  • Raising the minimum version can prevent older clients from connecting, so check compatibility.

Remediation

Select a security policy requiring TLS 1.2 or higher that meets your requirements, and associate a certificate covering the custom domain. Prepare an ACM certificate for CloudFront in us-east-1 and configure SslSupportMethod appropriately. Verify actual client negotiation, and configure HTTPS enforcement and origin connection encryption separately.

Examples

These excerpts compare only certificate settings within DistributionConfig. Domain aliases, origins and cache behavior are omitted. The before configuration also needs a certificate and support method. For the after configuration, supply a us-east-1 ACM certificate ARN covering the domain through ViewerCertificateArn.

Before

yaml
Resources:
  CloudFrontDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        ViewerCertificate:
          MinimumProtocolVersion: SSLv3

This historical configuration sets SSLv3 as the minimum. Even after supplying the omitted certificate settings, do not retain a policy permitting obsolete protocols.

After

yaml
Resources:
  CloudFrontDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        ViewerCertificate:
          AcmCertificateArn: !Ref ViewerCertificateArn
          MinimumProtocolVersion: TLSv1.2_2021
          SslSupportMethod: sni-only

This uses a custom certificate and the TLSv1.2_2021 policy. Clients must support SNI, and this setting alone does not reject HTTP requests.

References