3 ms·
Now just to set up the redirect so your visitors can only view in https.
by martiuk 10y ago
Now just to set up the redirect so your visitors can only view in https.
- willglynn 10y agoCloudFront makes adding redirects easy -- set "Viewer Protocol Policy: Redirect HTTP to HTTPS" and it'll return 301s as appropriate. Done. http://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/using-https-viewers-to-cloudfront.html http://docs.aws.amazon.com/AmazonCloudFront/latest/Developer... Now let's say you want to use HSTS so that browsers automatically rewrite HTTP to HTTPS. HSTS can protect users from agents that manipulate HTTP traffic, and it is therefore complementary to any redirection strategy. S3 lets you specify headers with your objects, like Cache-Control and Content-Type and such, but it doesn't support Strict-Transport-Security. (You can get S3 to use custom headers, but they must start with x-amz-meta-, which doesn't help here.) If the S3 origin can't return Strict-Transport-Security, that leaves CloudFront -- but CloudFront has no specific mechanism for HSTS nor any general mechanism for adding a response header. So... it's trivial to set a policy to redirect HTTP to HTTPS, but it's impossible to get S3->CloudFront to articulate that policy with Strict-Transport-Security headers. Sigh.