AwsCloudFrontDistributionViewerCertificate - AWS Security Hub


Provides information about the TLS/SSL configuration that the CloudFront distribution uses to communicate with viewers.



The ARN of the ACM certificate. Used if the certificate is stored in ACM. If you provide an ACM certificate ARN, you must also provide MinimumCertificateVersion and SslSupportMethod.

Type: String

Pattern: .*\S.*

Required: No


The identifier of the certificate. Note that in CloudFront, this attribute is deprecated.

Type: String

Pattern: .*\S.*

Required: No


The source of the certificate identified by Certificate. Note that in CloudFront, this attribute is deprecated.

Type: String

Pattern: .*\S.*

Required: No


Whether the distribution uses the CloudFront domain name. If set to false, then you provide either AcmCertificateArn or IamCertificateId.

Type: Boolean

Required: No


The identifier of the IAM certificate. Used if the certificate is stored in IAM. If you provide IamCertificateId, then you also must provide MinimumProtocolVersion and SslSupportMethod.

Type: String

Pattern: .*\S.*

Required: No


The security policy that CloudFront uses for HTTPS connections with viewers. If SslSupportMethod is sni-only, then MinimumProtocolVersion must be TLSv1 or higher.

Type: String

Pattern: .*\S.*

Required: No


The viewers that the distribution accepts HTTPS connections from.

Type: String

Pattern: .*\S.*

Required: No

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: