Review the API Gateway custom domain TLS policy

Choose a policy that provides the minimum TLS version and cipher suites required for the API Gateway custom domain.

Description

The security_policy of an API Gateway custom domain determines its minimum TLS version and cipher suites. Omitting it does not remove HTTPS, but the actual default policy must meet your requirements.

Custom domains are entry points for clients. Allowing old TLS protocols can weaken transport protection.

Potential impact

  • Clients using old TLS versions may remain able to connect.
  • Transport confidentiality and integrity may be weaker than required.
  • The configuration may fall short of transport security standards.

Remediation

  • Choose a policy supported by the endpoint and provider that offers TLS 1.2 or later and the required cipher suites. security_policy = "TLS_1_2" is an example of a legacy policy with a TLS 1.2 minimum.
  • Verify the effective policy after deployment, including on existing domains.
  • Test certificates, client compatibility and actual TLS negotiation. Apply any additional endpoint settings needed for enhanced policies.

Examples

These are custom-domain TLS setting excerpts. Configure the certificate appropriate for the endpoint type, DNS and API mappings separately.

Before

hcl
resource "aws_api_gateway_domain_name" "example" {
  domain_name = "api.example.com"
}

After

hcl
resource "aws_api_gateway_domain_name" "example" {
  domain_name     = "api.example.com"
  security_policy = "TLS_1_2"
}

Explanation:

  • Before: No policy is explicit, so check which default actually applies.
  • After: TLS_1_2 sets a TLS 1.2 minimum. Review stronger supported policies where needed and test client connections.

References