Description
The default CloudFront certificate is valid for the default cloudfront.net domain. Serving HTTPS through a custom domain requires an associated certificate covering that name. Using the default certificate does not itself bypass authentication or make content public.
Certificates protect domain identity and encrypted connections; they do not restrict content permissions. Private content needs separate access controls such as signed URLs or signed cookies.
Potential impact
- A mismatch between a custom domain and its certificate can cause HTTPS connections to fail.
- A TLS policy that does not meet service requirements can permit obsolete protocols.
Remediation
Add custom domains to Aliases and specify AcmCertificateArn for a us-east-1 ACM certificate covering those names. Remove the default certificate setting and configure MinimumProtocolVersion and SslSupportMethod. The default certificate remains valid when using the default cloudfront.net domain. Verify domain coverage, certificate validity and client compatibility.
Examples
These excerpts compare certificate settings only. Aliases, origins and cache behavior are omitted. Replace the example ARN with a us-east-1 certificate ARN covering the actual domain.
Before
Resources:
MyDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
ViewerCertificate:
CloudFrontDefaultCertificate: true
This is a valid choice for the default CloudFront domain. It does not authenticate a custom domain, and the default certificate's TLSv1 policy cannot be changed to another minimum version.
After
Resources:
MyDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
ViewerCertificate:
AcmCertificateArn: arn:aws:acm:us-east-1:123456789012:certificate/example
MinimumProtocolVersion: TLSv1.2_2019
SslSupportMethod: sni-only
This specifies a custom certificate and the TLSv1.2_2019 policy, requiring clients to support SNI. It does not replace content access controls or block HTTP requests.