Amazon_Cloudfront_6

Ensure AWS CloudFront web distributions use custom (and not default) SSL certificates

Description

Custom SSL certificates give you full control over your CloudFront content. Custom certificates allow your users to access content by using alternate domain name. You can store custom certificates in AWS Certificate Manager (ACM) or in IAM. It recommended to use custom SSL Certificate to access CloudFront content to have more control over your data.

Remediation

1. Sign in to the AWS console
2. Select the region, from the region drop-down, in which the issue is generated
3. Navigate to CloudFront Distributions Dashboard
4. Click the reported distribution
5. On the ‘General’ tab, click the ‘Edit’ button
6. On ‘Edit Distribution’ page set ‘SSL Certificate’ to ‘Custom SSL Certificate (example.com):’, select a certificate or type your certificate ARN in the field and other parameters as per your requirement.
7. Click Save Changes

Service

Cloudfront

Severity

High

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!