Review the minimum TLS version for CloudFront viewers

Restrict obsolete TLS protocols on CloudFront viewer connections and apply a security policy appropriate for the certificate type.

Description

When CloudFront permits obsolete TLS protocols, clients may connect using protection below the organization's encryption requirements. For a distribution using a custom certificate, viewerCertificate.minimumProtocolVersion selects the security policy that defines the minimum TLS version and cipher suites.

This field cannot change the security policy when the CloudFront default certificate is used. Requiring HTTPS from viewers and configuring TLS between CloudFront and the origin are separate settings.

Potential impact

  • Negotiating obsolete TLS protocols or weak cryptography can reduce protection in transit.
  • Different settings across services can make it harder to enforce consistent TLS requirements.

Remediation

  • For a distribution using a custom certificate, choose a supported security policy with a minimum of TLS 1.2 or later. For example, TLSv1.2_2018 requires at least TLS 1.2.
  • Configure the certificate, domain names and sslSupportMethod together, and test connections from required clients.
  • Use viewerProtocolPolicy to require HTTPS or redirect HTTP to HTTPS, and review origin TLS separately.

Examples

These partial examples compare security policies for a distribution using a custom certificate. Other distribution settings, including the certificate and sslSupportMethod, are omitted.

Before

yaml
apiVersion: cloudfront.aws.crossplane.io/v1alpha1
kind: Distribution
spec:
  forProvider:
    distributionConfig:
      viewerCertificate:
        minimumProtocolVersion: TLSv1.1_2016

TLSv1.1_2016 also allows TLS 1.1 connections.

After

yaml
apiVersion: cloudfront.aws.crossplane.io/v1alpha1
kind: Distribution
spec:
  forProvider:
    distributionConfig:
      viewerCertificate:
        minimumProtocolVersion: TLSv1.2_2018

TLSv1.2_2018 requires at least TLS 1.2 for viewer TLS connections. This change alone does not block HTTP requests or encrypt the origin connection.

References