Yes, this is exactly the idea.
The step you skipped is that you also need an ssl certificate for your primary domain, which you will โinstallโ in the CloudFront distribution.
, ( , SAN UCC), ), - - CloudFront - ( - , CloudFront - ).
, CloudFront , CloudFront .
CloudFront AWS Certificate manager. CloudFront, ELB, EC2, , ELB.
Gandi EC2 $16, CloudFront. , , , CloudFront - . LetsEncrypt StartSSL , , , . , , , CloudFront, , CloudFront, , , , . CloudFront SSL, CA, ( 502, StartSSL CloudFront)... , .