(This is a generalization/variation on this question based on what I've learned in solving this.)
I use AWS Cloudfront with an S3 origin (i.e. to serve S3 objects).
I want to add server-side encryption to my bucket but continue to be able to access the objects via cloudfront.
I am agnostic about the precise SSE strategy used (so long as it is secure).