---
title: >-
  CloudFront distributions should not use deprecated SSL protocols with custom
  origins
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > CloudFront distributions should not use
  deprecated SSL protocols with custom origins
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# CloudFront distributions should not use deprecated SSL protocols with custom origins
 
## Description{% #description %}

Verify that AWS CloudFront distributions do not allow SSLv3 for communication with custom origins. This check matches AWS Security Hub control CloudFront.10.

## Rationale{% #rationale %}

SSLv3 is deprecated and does not provide adequate protection for traffic between CloudFront edge locations and custom origins.

## Remediation{% #remediation %}

### From the console{% #from-the-console %}

Follow the [CloudFront.10 remediation guidance](https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-10) to remove SSLv3 from each custom origin's allowed SSL protocols.

### From the command line{% #from-the-command-line %}

1. Run `get-distribution-config` with your AWS CloudFront distribution ID to retrieve your [distribution's configuration information](https://awscli.amazonaws.com/v2/documentation/api/latest/reference/cloudfront/get-distribution-config.html).

In the `get-distribution-config.sh` file:

   ```bash
       aws cloudfront get-distribution-config
           --id ID000000000000
       
```

1. In a new JSON file, modify the returned configuration. Remove `SSLv3` from `OriginSslProtocols` and save the configuration file.

In the `https-only.sh` file:

   ```json
       {
         "ETag": "ETAG0000000000",
         "DistributionConfig": {
           "Origins": {
             "Items": [
               {
                 "CustomOriginConfig": {
                   "OriginSslProtocols": {
                     "Items": ["TLSv1.2"],
                     "Quantity": 1
                   },
                   ...
                 }
               }
             ]
           }
         }
       }
       
```

1. Run `update-distribution` to [update your distribution](https://awscli.amazonaws.com/v2/documentation/api/latest/reference/cloudfront/update-distribution.html) with your distribution `id`, the path of the configuration file (created in step 2), and your `etag`.

In the `update-distribution.sh` file:

   ```bash
       aws cloudfront update-distribution
           --id ID000000000000
           --distribution-config https-only.json
           --if-match ETAG0000000000
       
```
