Amazon CloudFront now supports TLS 1.3 for origin connections

Published
November 20, 2025
https://aws.amazon.com/about-aws/whats-new/2025/11/amazon-cloudfront-tls13-origin

Amazon CloudFront TLS 1.3 Support

Amazon CloudFront now supports TLS 1.3 when connecting to your origins, providing enhanced security and improved performance for origin communications. This upgrade offers stronger encryption algorithms, reduced handshake latency, and better overall security posture for data transmission between CloudFront edge locations and your origin servers.

TLS 1.3 provides faster connection establishment through a reduced number of round trips during the handshake process, delivering up to 30% improvement in connection performance when your origin supports it. CloudFront will automatically negotiate TLS 1.3 when your origin supports it, while maintaining backward compatibility with lower TLS versions for origins that haven't yet upgraded.

What to do

  • No configuration changes are required on your part as TLS 1.3 support is automatically enabled for all origin types.
  • Ensure your origin servers support TLS 1.3 to maximize the benefits of this enhancement.

Source: AWS release notes




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.