Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

AwsCloudFrontDistributionViewerCertificate - AWS Security Hub

AwsCloudFrontDistributionViewerCertificate

Provides information about the TLS/SSL configuration that the CloudFront distribution uses to communicate with viewers.

Contents

AcmCertificateArn

The ARN of the ACM certificate. Used if the certificate is stored in ACM. If you provide an ACM certificate ARN, you must also provide MinimumCertificateVersion and SslSupportMethod.

Type: String

Pattern: .*\S.*

Required: No

Certificate

The identifier of the certificate. Note that in CloudFront, this attribute is deprecated.

Type: String

Pattern: .*\S.*

Required: No

CertificateSource

The source of the certificate identified by Certificate. Note that in CloudFront, this attribute is deprecated.

Type: String

Pattern: .*\S.*

Required: No

CloudFrontDefaultCertificate

Whether the distribution uses the CloudFront domain name. If set to false, then you provide either AcmCertificateArn or IamCertificateId.

Type: Boolean

Required: No

IamCertificateId

The identifier of the IAM certificate. Used if the certificate is stored in IAM. If you provide IamCertificateId, then you also must provide MinimumProtocolVersion and SslSupportMethod.

Type: String

Pattern: .*\S.*

Required: No

MinimumProtocolVersion

The security policy that CloudFront uses for HTTPS connections with viewers. If SslSupportMethod is sni-only, then MinimumProtocolVersion must be TLSv1 or higher.

Type: String

Pattern: .*\S.*

Required: No

SslSupportMethod

The viewers that the distribution accepts HTTPS connections from.

Type: String

Pattern: .*\S.*

Required: No

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following:

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.