The solution is to configure the cache behavior to forward (white list) the header Host:
to the origin from the incoming request.
This does not mean that this is the βcorrectβ configuration in each case, but many times it is desirable or even required.
CloudFront https- , , , ( , , ), , CloudFront.
CloudFront HTTPS , :
& ; , Origin .
& ; CloudFront , .
SSL/TLS " " , , " ". (CloudFront .) , , , CloudFront 502 (Bad Gateway) ,
http://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/SecureConnections.html#SecureConnectionsHowToRequireCustomProcedure
CloudFront , CloudFront , .
, , , , , , , , Host:
( CloudFront " " ), CloudFront, , , .
Host:
, , , , -, . Host:
, CloudFront - , , , , .
( CloudFront HTTPS- ), CloudFront , , , , , , TLS/SSL ( , , ).