Low
CloudFront
CloudFront distributions should use SNI to serve HTTPS requests
NISTHIPAA
Description
Flags CloudFront distributions that use a dedicated IP address for SSL/TLS instead of SNI, which is the recommended and more cost-efficient approach.
Remediation
To configure a CloudFront distribution to use SNI to serve HTTPS requests, refer to the Amazon CloudFront Developer Guide.
Steps
- Open the Amazon CloudFront console.
- Choose the distribution to update.
- Navigate to the 'Distribution Settings' and select the 'SSL Certificate' section.
- Ensure the SSL support method is set to 'SNI-only'.
- Save changes.
Compliance
NISTHIPAA