Low CloudFront

CloudFront distributions should use SNI to serve HTTPS requests

NISTHIPAA

Description

Flags CloudFront distributions that use a dedicated IP address for SSL/TLS instead of SNI, which is the recommended and more cost-efficient approach.


Remediation

To configure a CloudFront distribution to use SNI to serve HTTPS requests, refer to the Amazon CloudFront Developer Guide.

Steps

  1. Open the Amazon CloudFront console.
  2. Choose the distribution to update.
  3. Navigate to the 'Distribution Settings' and select the 'SSL Certificate' section.
  4. Ensure the SSL support method is set to 'SNI-only'.
  5. Save changes.

Compliance

NISTHIPAA