Description
A CloudFront viewer security policy that allows versions below TLS 1.2 permits older protocol connections. The default CloudFront certificate has a fixed TLSv1 minimum; enforcing a higher minimum requires a custom certificate.
Potential impact
Allowing older protocols can expose connections to outdated cryptography and fail transport-security requirements.
Remediation
Configure a custom certificate covering the service domain and a security policy with a minimum of TLS 1.2 or later. Check client compatibility before changing the policy.
Examples
These excerpts show the certificate settings. Supply an ACM certificate issued or imported in us-east-1 through the certificate ARN variable.
Before
hcl
resource "aws_cloudfront_distribution" "example" {
origin {
domain_name = aws_s3_bucket.b.bucket_regional_domain_name
origin_id = local.s3_origin_id
s3_origin_config {
origin_access_identity = "origin-access-identity/cloudfront/ABCDEFG1234567"
}
}
enabled = true
comment = "Some comment"
default_root_object = "index.html"
viewer_certificate {
cloudfront_default_certificate = false
acm_certificate_arn = var.acm_certificate_arn
ssl_support_method = "sni-only"
minimum_protocol_version = "TLSv1_2016"
}
}
After
hcl
resource "aws_cloudfront_distribution" "example" {
origin {
domain_name = aws_s3_bucket.b.bucket_regional_domain_name
origin_id = local.s3_origin_id
s3_origin_config {
origin_access_identity = "origin-access-identity/cloudfront/ABCDEFG1234567"
}
}
enabled = true
comment = "Some comment"
default_root_object = "index.html"
viewer_certificate {
cloudfront_default_certificate = false
acm_certificate_arn = var.acm_certificate_arn
ssl_support_method = "sni-only"
minimum_protocol_version = "TLSv1.2_2021"
}
}