Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

AWS Certificate Manager Announces ACME Support for Automated TLS Certificate Management

Clara Cecillia, July 8, 2026

Amazon Web Services (AWS) has announced the integration of Automatic Certificate Management Environment (ACME) protocol support into AWS Certificate Manager (ACM), a move poised to significantly streamline the issuance, renewal, and revocation of public TLS certificates for applications hosted on the cloud platform. This enhancement directly addresses the escalating challenges faced by organizations in managing the lifecycle of TLS certificates, particularly as industry standards mandate increasingly shorter validity periods, making manual processes unsustainable and prone to error.

The Evolving Challenge of TLS Certificates and the Imperative for Automation

Automate public TLS certificate issuance with ACME support in AWS Certificate Manager | Amazon Web Services

For years, managing Transport Layer Security (TLS) certificates, critical for encrypting internet communications and verifying website identity, has been a significant operational burden for IT and security teams. The process typically involves manual generation of Certificate Signing Requests (CSRs), submission to a Certificate Authority (CA), manual installation, and crucially, vigilant tracking of expiration dates to prevent service interruptions. A lapsed certificate can lead to immediate service outages, customer trust erosion due to browser security warnings, and potential data breaches if traffic reverts to unencrypted HTTP.

The urgency for robust automation has intensified with new mandates from the CA/Browser Forum, the industry body that sets standards for SSL/TLS certificates. These mandates are progressively shortening the maximum validity period for certificates. Starting March 2027, the maximum validity will be reduced to 100 days, further decreasing to a mere 47 days by 2029. This drastic reduction means that certificates will need to be renewed approximately every three months (and eventually every month and a half), transforming what was once an annual or biennial task into a continuous, high-frequency operation. Without automated systems, the administrative overhead becomes prohibitive, and the risk of human error leading to expirations skyrockets. Industry reports frequently cite certificate expiration as a leading cause of unplanned downtime, with studies indicating that a significant percentage of outages are attributable to this oversight, often costing organizations millions in lost revenue and reputational damage.

The Rise of ACME: A Standard for Certificate Automation

Automate public TLS certificate issuance with ACME support in AWS Certificate Manager | Amazon Web Services

The Automatic Certificate Management Environment (ACME) protocol emerged as a beacon of hope in this landscape. Developed by the Internet Security Research Group (ISRG) and standardized by the Internet Engineering Task Force (IETF), ACME provides an open, extensible, and automated way for servers to interact with Certificate Authorities to obtain, renew, and revoke certificates. It eliminates the need for manual intervention, making it possible to manage certificates at scale with high reliability.

The most prominent example of ACME’s success is Let’s Encrypt, a free, automated, and open Certificate Authority that has leveraged the protocol to issue billions of certificates, significantly contributing to the widespread adoption of HTTPS across the internet. The ACME ecosystem has matured rapidly, with dozens of compatible clients available across various platforms and programming languages, including popular tools like Certbot, cert-manager for Kubernetes environments, and acme.sh. These clients handle the intricacies of domain validation (proving ownership of a domain to the CA) and certificate issuance, all through an API-driven, scriptable interface.

AWS’s Strategic Integration: Bridging the Gap for Cloud-Native Certificate Management

Automate public TLS certificate issuance with ACME support in AWS Certificate Manager | Amazon Web Services

Prior to this announcement, AWS customers seeking ACME-driven automation for public certificates often had to rely on external Certificate Authorities and their associated ACME servers. While ACM itself has long offered managed TLS certificates for AWS services (like Elastic Load Balancing, CloudFront, and API Gateway), and supported private CA functionality, it lacked a native ACME endpoint for public certificates. This created a fragmented certificate management experience. Some certificates would be managed natively within ACM, benefiting from its integration with other AWS services, while others—particularly those managed by ACME clients—resided externally. This often led to "shadow IT" scenarios for certificate management, where PKI administrators lacked a centralized view, consistent control, and comprehensive auditing capabilities for all public certificates across their organization.

The new ACME support in ACM directly addresses this fragmentation. AWS Certificate Manager now provides a fully managed ACME server endpoint, allowing customers to issue public TLS certificates from Amazon Trust Services (ATS), AWS’s own Certificate Authority, directly through the standard ACME protocol. This means that existing ACMEv2-compatible clients can now point to an AWS-native endpoint, consolidating certificate management within the AWS ecosystem.

Key Features and Benefits for PKI Administrators

Automate public TLS certificate issuance with ACME support in AWS Certificate Manager | Amazon Web Services

This integration offers significant advantages, particularly for PKI administrators and security teams grappling with enterprise-scale certificate management:

  1. Centralized Control and Visibility: PKI administrators gain a single pane of glass within the AWS Management Console to oversee all public certificates, regardless of whether they were issued via the ACM console, an API call, or an ACME endpoint. This eliminates the blind spots and disparate dashboards that previously complicated auditing and compliance efforts. AWS CloudTrail automatically logs every certificate request, providing an immutable audit trail, while Amazon CloudWatch tracks operational metrics, and ACM sends expiry notifications, ensuring proactive management.

  2. Fine-Grained Access Control with IAM Integration: A critical enhancement is the ability to bind AWS Identity and Access Management (IAM) roles to ACME accounts. This allows administrators to implement granular access policies, dictating precisely which domains each ACME client or application team can request certificates for. This capability moves beyond basic certificate issuance, enabling organizations to enforce least privilege principles and prevent unauthorized certificate requests.

    Automate public TLS certificate issuance with ACME support in AWS Certificate Manager | Amazon Web Services
  3. Domain Scoping and Policy Enforcement: ACM’s ACME endpoints allow administrators to define specific domain scopes at the endpoint level. This means an administrator can pre-authorize domains and control the types of certificates clients can request for them. For instance, an endpoint can be configured to allow only exact domain names (e.g., www.example.com), subdomains (e.g., api.example.com, dev.example.com), or wildcards (e.g., *.example.com). By strategically disabling certain scopes (e.g., disallowing wildcards for sensitive production endpoints), organizations can enforce stricter security postures and prevent potential misuse. This built-in governance capability reduces the need for costly third-party certificate lifecycle management (CLM) solutions or custom-built policy layers.

  4. Simplified Domain Validation: The integration with Amazon Route 53, AWS’s highly available and scalable cloud Domain Name System (DNS) web service, streamlines the crucial domain validation step. When a domain is hosted in Route 53, ACM can automatically create the necessary DNS CNAME records required for ACME’s DNS-01 challenge, removing manual steps and potential errors. This is a significant departure from traditional ACME setups where each client often handles its own domain verification, sometimes requiring access to sensitive DNS credentials. With ACM, PKI administrators validate domains once at the endpoint level, retaining control over DNS credentials, while application owners only interact with the EAB credentials to request certificates within their authorized scope. This separation of concerns enhances security and simplifies the developer experience.

  5. Support for Key Types: The service supports various certificate key types, including the default ECDSA P-256, as well as RSA 2048 and ECDSA P-384, catering to diverse client requirements and security policies.

    Automate public TLS certificate issuance with ACME support in AWS Certificate Manager | Amazon Web Services

A Detailed Look at the Implementation Process

Setting up ACME support in ACM involves a series of straightforward steps designed to balance automation with centralized control.

The process begins in the AWS Certificate Manager console, navigating to the "ACME certificates" section. From there, an administrator selects "Create ACME endpoint." During endpoint creation, essential parameters are defined:

Automate public TLS certificate issuance with ACME support in AWS Certificate Manager | Amazon Web Services
  • Endpoint Name: A descriptive identifier for the endpoint.
  • Endpoint Type: Currently, only "Public" is available, meaning clients connect over the public internet.
  • Certificate Type: "Public," indicating certificates issued by Amazon Trust Services, trusted by browsers globally.
  • Certificate Key Type: The cryptographic algorithm and key size for the certificates issued by this endpoint (e.g., ECDSA P-256, RSA 2048, ECDSA P-384).

The crucial next step is configuring the domain(s) for which the endpoint can issue certificates. The administrator enters the domain name (e.g., example.com) and meticulously selects the domain scope: "Exact domain," "Subdomains," and/or "Wildcards." This granular control is vital for security, allowing organizations to restrict wildcard issuance for specific environments or applications. If the domain’s DNS is managed by Amazon Route 53, the administrator can select the corresponding hosted zone, enabling ACM to automatically manage the CNAME records for domain validation. For domains hosted externally, the administrator is provided with the necessary CNAME records to manually create with their DNS provider. This centralized domain validation by the PKI administrator, rather than individual clients, is a core security advantage.

Once the endpoint is created, its status will show "Validating" for the domain. If Route 53 integration was chosen, a simple click on "Create records in Route 53" completes the DNS validation within seconds, changing the status to "Success." This validation step confirms that AWS ACM has verified ownership of the domain.

The final administrative step is creating External Account Binding (EAB) credentials. EAB is a mechanism within the ACME protocol that allows a CA to bind an ACME account to an external account (in this case, an AWS IAM role). The administrator generates an EAB credential, which consists of a "Key ID" and an "HMAC Key." These are provided to the ACME client for its initial registration with the ACM ACME server. The EAB credentials act as a one-time registration token; once the client registers, it generates its own persistent key pair for subsequent authentication of certificate requests. Administrators can optionally set an expiration time for EAB credentials, further enhancing security by limiting their validity.

Automate public TLS certificate issuance with ACME support in AWS Certificate Manager | Amazon Web Services

With the endpoint configured and EAB credentials generated, application developers or automated systems can then use their preferred ACMEv2-compatible client (e.g., Certbot, acme.sh) to request certificates. The ACM console provides ready-to-use CLI examples for common clients, detailing how to include the endpoint URL, EAB Key ID, and HMAC Key in the request. For example, a Certbot command would look like:

certbot certonly --standalone --non-interactive --agree-tos 
    --email <EMAIL> 
    --server https://acm-acme-enroll.<REGION>.api.aws/<ENDPOINT_ID>/directory 
    --eab-kid <EAB_KID> 
    --eab-hmac-key <EAB_HMAC_KEY> 
    --issuance-timeout <ISSUANCE_TIMEOUT> 
    -d <DOMAIN>

Upon successful execution, the ACME client communicates with the ACM ACME endpoint, which, after validating the request against the pre-configured domain scopes and EAB credentials, issues a valid TLS certificate signed by Amazon Trust Services. The newly issued certificate immediately becomes visible in the ACM console, alongside any other certificates managed by the service, providing complete centralized visibility.

Enhanced Security, Governance, and Operational Efficiency

Automate public TLS certificate issuance with ACME support in AWS Certificate Manager | Amazon Web Services

This new capability represents a significant leap forward in security and operational governance for AWS customers. By centralizing ACME certificate issuance within ACM, organizations can:

  • Improve Security Posture: By enforcing domain scopes, controlling key types, and leveraging IAM for granular access, the risk of misconfigured or unauthorized certificates is drastically reduced. The separation of DNS control from certificate requestors means sensitive DNS credentials are not distributed widely.
  • Ensure Compliance: Centralized logging via CloudTrail provides an undeniable audit trail for all certificate activities, crucial for meeting regulatory compliance requirements (e.g., PCI DSS, HIPAA, GDPR). Consistent policies can be applied across all ACME-issued certificates.
  • Boost Operational Efficiency: Automated renewals eliminate manual toil, reduce human error, and prevent costly outages due to expired certificates. The integration with Route 53 further streamlines the process. This frees up valuable security and operations team time to focus on higher-value tasks.
  • Reduce Costs: By providing a fully managed ACME server and built-in governance capabilities, AWS ACM potentially eliminates the need for organizations to invest in separate, expensive certificate lifecycle management (CLM) products or to build and maintain custom solutions.

Availability and Pricing

ACME support in AWS Certificate Manager is now generally available across all commercial AWS Regions. AWS has indicated that availability in AWS GovCloud (US), the China Regions, and the AWS European Sovereign Cloud partitions will follow at a later date, catering to specific regulatory and sovereignty requirements.

Automate public TLS certificate issuance with ACME support in AWS Certificate Manager | Amazon Web Services

Pricing for ACME-issued certificates in ACM is based on the number of domains included in each certificate at the time of issuance, with distinct pricing for fully qualified domain names (FQDNs) and wildcard domains. Volume tiers are applied based on the total number of domain occurrences across all certificates issued per month within an AWS account. This tiered pricing model aims to scale with organizational usage, making it cost-effective for both small and large deployments. Detailed pricing information is available on the AWS Certificate Manager pricing page.

To begin leveraging this new capability, AWS customers can visit the ACM section of the AWS console or consult the updated ACM documentation for comprehensive guidance and tutorials. This launch underscores AWS’s commitment to providing robust, integrated, and automated solutions for critical security infrastructure components, enabling organizations to manage their digital certificates with greater ease, security, and efficiency in an increasingly complex threat landscape.

Cloud Computing & Edge Tech acmeannouncesautomatedAWSAzurecertificateCloudEdgemanagementmanagerSaaSsupport

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes