I'm using a tool to do security checks and this tool marked the following ciphers as weak:
TLS_RSA_WITH_AES_128_CBC_SHA256 (0x003C)
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xC027)
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xC028)
I'm using the latest CloudFront Security Policy which is TLSv1.2_2018 and the Minimum Origin SSL Protocol set to TLSv1.2.
But even with these settings the weak ciphers is still allowed.
Is it possible to disable some specific ciphers on CloudFront?