Classification:
compliance
Set up the cloudfront integration.
Verify that AWS CloudFront distributions have a security policy of TLS v1.1 or greater.
TLS v1.1, the minimum protocol recommended for AWS CloudFront, and the cipher used to encrypt this content, improve application security.
Run get-distribution-config
with your AWS CloudFront distribution ID to retrieve your distribution’s configuration information.
get-distribution-config.sh
aws cloudfront get-distribution-config
--id ID000000000000
In a new JSON file, modify the returned configuration by setting the minimum protocol version to TLC v1.1 (2016) or v1.2 (2018).
tls-version.sh
{
"ETag": "ETAG0000000000",
"DistributionConfig": {
...
"ViewerCertificate": {
...
"MinimumProtocolVersion": "TLSv1.1_2016",
},
...
}
}
Run update-distribution
to update your distribution with your distribution id
, the path of the configuration file (created in step 2), and your etag
.
update-distribution.sh
aws cloudfront update-distribution
--id ID000000000000
--distribution-config tls-version.json
--if-match ETAG0000000000
このページ