Amazon CloudFront now supports SHA-256 as a hash algorithm for signed URLs and signed cookies, replacing the previous SHA-1 exclusive support. To use it, add the Hash-Algorithm=SHA256 query parameter to signed URLs or the CloudFront-Hash-Algorithm=SHA256 cookie attribute for signed cookies. The change is fully backwards compatible — existing signed URLs and cookies without a specified algorithm continue using SHA-1. This update helps meet security and compliance requirements mandating SHA-256 for digital signatures and is available at no additional cost across all CloudFront edge locations.

1m read timeFrom aws.amazon.com
Post cover image

Sort: