Skip to content

Files

Latest commit

 

History

History
33 lines (24 loc) · 724 Bytes

aws-cloudfront-use-secure-tls-policy.md

File metadata and controls

33 lines (24 loc) · 724 Bytes

Pattern: Use of insecure TLS/SSL policy for AWS CloudFront

Issue: -

Description

You should not use outdated/insecure TLS versions for encryption. You should be using TLS v1.2+.

Resolution: Use the most modern TLS/SSL policies available.

Examples

Example of incorrect code:

resource "aws_cloudfront_distribution" "bad_example" {
  viewer_certificate {
    cloudfront_default_certificate = true
	minimum_protocol_version = "TLSv1.0"
  }
}

Example of correct code:

resource "aws_cloudfront_distribution" "good_example" {
  viewer_certificate {
    cloudfront_default_certificate = true
	minimum_protocol_version = "TLSv1.2_2021"
  }
}