http://en.wikipedia.org/wiki/Server_Name_Indication
Essentially, the cloudfront server doesn't know the certificate to present.