Subdomain takeover no longer possible with CloudFront?

I found an unclaimed CloudFront instance on a subdomain I was testing. However when I went to create a new CloudFront distribution with the URL as the CNAME it didn't work. It showed an error explaining how you need to upload a trusted cert from a CA. The cert can't be self-signed.

So is it now impossible to perform this exploit? Or am I just missing something here…

