Description
When CloudFront permits obsolete TLS protocols, clients may connect using protection below the organization's encryption requirements. For a distribution using a custom certificate, viewerCertificate.minimumProtocolVersion selects the security policy that defines the minimum TLS version and cipher suites.
This field cannot change the security policy when the CloudFront default certificate is used. Requiring HTTPS from viewers and configuring TLS between CloudFront and the origin are separate settings.
Potential impact
- Negotiating obsolete TLS protocols or weak cryptography can reduce protection in transit.
- Different settings across services can make it harder to enforce consistent TLS requirements.
Remediation
- For a distribution using a custom certificate, choose a supported security policy with a minimum of TLS 1.2 or later. For example,
TLSv1.2_2018requires at least TLS 1.2. - Configure the certificate, domain names and
sslSupportMethodtogether, and test connections from required clients. - Use
viewerProtocolPolicyto require HTTPS or redirect HTTP to HTTPS, and review origin TLS separately.
Examples
These partial examples compare security policies for a distribution using a custom certificate. Other distribution settings, including the certificate and sslSupportMethod, are omitted.
Before
apiVersion: cloudfront.aws.crossplane.io/v1alpha1
kind: Distribution
spec:
forProvider:
distributionConfig:
viewerCertificate:
minimumProtocolVersion: TLSv1.1_2016
TLSv1.1_2016 also allows TLS 1.1 connections.
After
apiVersion: cloudfront.aws.crossplane.io/v1alpha1
kind: Distribution
spec:
forProvider:
distributionConfig:
viewerCertificate:
minimumProtocolVersion: TLSv1.2_2018
TLSv1.2_2018 requires at least TLS 1.2 for viewer TLS connections. This change alone does not block HTTP requests or encrypt the origin connection.