Skip to content

Conversation

@crungehottman
Copy link
Member

There are currently supported legacy systems that support TLSv1.0, so it is possible that content is fetched using clients which use TLSv1.0. We shouldn't deploy this to production without knowing the implications.

Additionally, it seems like MinimumProtocolVersion [1] is only applicable for distributions which use CNAMEs (our distribution does not):

MinimumProtocolVersion

If the distribution uses Aliases (alternate domain names or CNAMEs), specify the security policy that you want CloudFront to use for HTTPS connections with viewers.

[1] https://docs.aws.amazon.com/cloudfront/latest/APIReference/API_ViewerCertificate.html

@crungehottman crungehottman merged commit 6cc4235 into master Jan 26, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants