설명
CloudFront의 viewer_protocol_policy가 allow-all이면 사용자가 HTTP와 HTTPS로 콘텐츠에 접근할 수 있습니다. HTTP 요청과 응답은 전송 중 도청이나 변조에 노출될 수 있습니다. 이 설정은 뷰어와 CloudFront 사이에 적용되며 오리진 연결은 별도로 보호해야 합니다.
잠재적 영향
- HTTP로 전송한 요청 파라미터와 응답 내용이 노출되거나 변조될 수 있습니다.
- 보호되지 않은 인증 정보나 세션 정보가 전송되면 계정 접근에 악용될 수 있습니다.
해결 방법
- 각 캐시 동작의
viewer_protocol_policy를https-only또는redirect-to-https로 설정하세요. - 리디렉션 전 최초 HTTP 요청은 암호화되지 않으므로 클라이언트가 처음부터 HTTPS를 사용하도록 하세요.
- 기본·추가 캐시 동작, 인증서와 TLS 정책을 확인하고 오리진 구간도 필요한 암호화를 적용하세요.
예시
기본 캐시 동작의 뷰어 프로토콜을 비교하는 부분 예제입니다. 캐시 정책 등 나머지 필수 설정은 생략했습니다.
변경 전
yaml
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
caller_reference: unique-test-distribution-id
origins:
- id: my-test-origin
domain_name: www.example.com
default_cache_behavior:
target_origin_id: my-test-origin
viewer_protocol_policy: allow-all
allow-all은 HTTP 요청도 허용합니다. HTTPS를 사용할 수 있다는 사실만으로 HTTP 요청이 보호되는 것은 아닙니다.
변경 후
yaml
- name: CloudFront 배포 생성
community.aws.cloudfront_distribution:
state: present
caller_reference: unique-test-distribution-id
origins:
- id: my-test-origin
domain_name: www.example.com
default_cache_behavior:
target_origin_id: my-test-origin
viewer_protocol_policy: https-only
https-only는 HTTP 요청을 거부합니다. 정상 클라이언트가 HTTPS로 연결되는지 확인하세요.