説明
CloudFront のビューワーセキュリティポリシーは、クライアント接続に使用する TLS の最低バージョンと暗号スイートを定めます。TLS 1.0 や 1.1 を許可すると古いプロトコルで接続でき、サービスの暗号化要件を満たさない場合があります。
想定される影響
- 古いプロトコルや暗号スイートにより、通信の保護が弱まるおそれがあります。
- TLS 1.2 以上を求めるセキュリティ基準を満たさない場合があります。
対処方法
- カスタム証明書を使うディストリビューションでは、
minimum_protocol_versionに TLS 1.2 以上を要求する対応ポリシーを指定し、必要なクライアントとの互換性を確認してください。 - CloudFront のデフォルト証明書ではセキュリティポリシーが
TLSv1に固定されます。最低バージョンを上げる必要がある場合は、カスタムドメインと証明書を用意してください。 - ビューワーの HTTPS 強制とオリジンへの接続の暗号化は、それぞれ設定してください。
例
カスタム証明書の TLS ポリシーを比較する抜粋です。証明書、ssl_support_method、ドメイン、キャッシュ動作などは省略しています。
変更前
yaml
- name: create a distribution with an origin and logging
community.aws.cloudfront_distribution:
state: present
caller_reference: unique test distribution ID
origins:
- id: my test origin-000111
domain_name: www.example.com
logging:
enabled: true
include_cookies: false
bucket: mylogbucket.s3.amazonaws.com
prefix: myprefix/
viewer_certificate:
minimum_protocol_version: TLSv1
TLSv1 ポリシーは、最低バージョンとして TLS 1.0 を許可します。
変更後
yaml
- name: create a distribution with an origin and logging
community.aws.cloudfront_distribution:
state: present
caller_reference: unique test distribution ID
origins:
- id: my test origin-000111
domain_name: www.example.com
logging:
enabled: true
include_cookies: false
bucket: mylogbucket.s3.amazonaws.com
prefix: myprefix/
viewer_certificate:
minimum_protocol_version: TLSv1.2_2018
TLSv1.2_2018 は TLS 1.2 以上を要求します。適用前に、現在対応しているポリシーからサービスの暗号化要件とクライアントに合うものを選んでください。