Amazon Web Services (AWS) today announced a significant enhancement to its AWS Certificate Manager (ACM) service, integrating native support for the Automatic Certificate Management Environment (ACME) protocol for public TLS certificates. This strategic development directly addresses the escalating challenges faced by organizations in managing the lifecycle of Transport Layer Security (TLS) certificates, particularly in an era of progressively shorter validity periods mandated by industry standards. The introduction of a fully managed ACME server endpoint within ACM promises to revolutionize how enterprises acquire, renew, and revoke public TLS certificates, moving from fragmented, manual processes to a cohesive, automated, and centrally governed system.

The landscape of digital security is constantly evolving, with TLS certificates serving as the foundational element for securing internet communications and establishing trust between users and applications. However, the operational burden associated with their management has long been a pain point for IT and security teams. Certificates, by their very nature, have an expiration date, and their oversight requires meticulous planning and execution. Failure to renew a certificate before its expiration can lead to service outages, inaccessible applications, and severe reputational damage, alongside potential compliance violations. Historically, manual renewal processes have been prone to human error, consuming valuable time and resources.
This challenge is further compounded by recent and impending changes in industry standards. The Certification Authority (CA)/Browser Forum, the governing body for the issuance and management of TLS certificates, has steadily pushed for shorter maximum validity periods to enhance security and agility. A significant milestone is approaching in March 2027, when the maximum validity period for publicly trusted certificates will be reduced to 100 days. This will be followed by a further reduction to just 47 days by 2029. Such abbreviated lifespans render traditional, manual certificate management practices untenable for organizations operating at scale, making robust automation an imperative, not merely a convenience. The need for an efficient, error-proof mechanism for certificate lifecycle management has never been more critical.

The ACME protocol emerges as the industry’s answer to this demand for automation. An open standard, ACME facilitates the automated issuance, renewal, and revocation of TLS certificates between a client and a Certificate Authority (CA) without requiring human intervention. Its efficacy and widespread adoption are best exemplified by its role as the backbone of Let’s Encrypt, which has democratized TLS encryption for millions of websites globally. ACME’s design allows for seamless integration with a myriad of clients across diverse platforms, making it a universal solution for automated certificate management.
With this announcement, AWS Certificate Manager now provides a native ACMEv2-compatible server endpoint. This means that organizations can leverage their existing ACME clients, such as Certbot, cert-manager for Kubernetes, or acme.sh, to request public TLS certificates directly from Amazon Trust Services – AWS’s own trusted Certificate Authority – all managed within the ACM ecosystem. This integration marks a pivotal shift, offering AWS customers a unified platform for their public certificate needs.

Prior to this launch, AWS customers seeking ACME-driven automation for public certificates often found themselves in a bifurcated environment. They would typically rely on external Certificate Authorities (CAs) for ACME-issued certificates, while simultaneously managing other certificates within ACM. This led to a fragmented visibility experience, where some critical certificates resided in ACM’s centralized dashboard, while others were managed externally with no overarching view or unified control. This fragmented approach presented significant governance and security challenges for PKI administrators, who had limited ability to enforce organizational policies, control who could request certificates, or restrict which domains were allowed for issuance. Such an environment often necessitated custom tooling or additional third-party certificate lifecycle management (CLM) solutions, adding complexity and cost.
The new ACME support in ACM directly addresses these pain points by enabling PKI administrators to establish one or more managed ACME endpoints. This functionality allows for centralized management and comprehensive monitoring of ACME certificate usage across an entire organization, bringing all public certificates under a single pane of glass. This unification streamlines operations, enhances security, and provides unprecedented control over certificate issuance.

For PKI administrators, the benefits extend far beyond basic certificate issuance. The ACM integration offers a suite of centralized controls designed for robust governance and compliance. Administrators can now bind AWS Identity and Access Management (IAM) roles to ACME accounts, enabling fine-grained access control over which users or applications can request certificates and for which specific domains. This ensures that only authorized entities can initiate certificate requests, significantly reducing the risk of unauthorized issuance. Furthermore, administrators can define domain scopes at the endpoint level, enforcing organization-wide policies that dictate the types of certificates (e.g., exact domain, subdomains, wildcards) that can be requested for particular domains. This level of policy enforcement is critical for maintaining a strong security posture and adhering to internal compliance requirements.
Beyond control, ACM’s ACME integration delivers enhanced visibility and auditability. Every certificate request made through the ACME endpoint is meticulously logged in AWS CloudTrail, providing an immutable audit trail for security and compliance teams. Operational metrics, such as request volumes and success rates, are tracked in Amazon CloudWatch, offering insights into system performance and potential issues. Moreover, ACM continues to send proactive expiry notifications, ensuring that teams are alerted well in advance when certificates are approaching their renewal date, thereby preventing unexpected outages. The ability to search and manage all certificates – whether issued via the ACM console, an API call, or the new ACME endpoint – from a single, unified interface significantly simplifies PKI management and oversight.

The operational flow for setting up ACME support within ACM is designed for clarity and control. The initial step involves establishing a dedicated ACME endpoint within the ACM console. During this setup, PKI administrators configure critical authorization controls using External Account Binding (EAB) credentials and validate the domains for which the endpoint is authorized to issue certificates. This domain validation step is a crucial differentiator, separating the responsibility of establishing certificate issuance authority from the act of requesting certificates. The PKI administrator performs a one-time domain validation at the endpoint level, typically using DNS credentials that remain securely under their control. This process ensures that the organization genuinely owns and controls the domains for which certificates will be issued.
Application owners or developers who require certificates never need direct access to sensitive DNS keys. Instead, they register with the ACME endpoint using EAB credentials provided by the PKI administrator. The endpoint then strictly enforces the domains and scopes they are permitted to request, based on the policies defined by the administrator. This architecture allows organizations to distribute certificate automation broadly across their development and operations teams without compromising the security of their DNS infrastructure. It eliminates the need to share high-privilege DNS credentials, a common security concern in decentralized certificate management models.

When creating an ACME endpoint, administrators specify key details such as the endpoint name, its public accessibility, and the certificate type (public, issued by Amazon Trust Services). They can also select the desired certificate key type, with options including ECDSA P-256 (the default), RSA 2048, and ECDSA P-384, catering to various client requirements and security postures. Crucially, the domain configuration allows for precise control over the scope of certificates. Administrators can enable requests for exact domains, subdomains, or wildcards, and by leaving certain scopes unchecked, they can enforce stricter security policies, preventing clients from requesting specific types of certificates even if their ACME request would otherwise be valid. For instance, a production endpoint might be configured to allow only exact domains and subdomains, while explicitly disallowing wildcard certificates, thereby minimizing the attack surface.
A significant convenience feature is the integration with Amazon Route 53. If a domain’s hosted zone is managed in Route 53, ACM can automatically create the necessary DNS CNAME records for domain validation, abstracting away manual DNS configuration. For domains hosted outside Route 53, administrators are provided with the CNAME record details to manually configure with their respective DNS providers. This centralized domain authentication, coupled with granular control over certificate types and wildcard issuance, provides built-in governance capabilities that reduce the need for organizations to invest in costly third-party certificate lifecycle management products or develop complex custom policy layers.

Once the endpoint is created and domains are validated, the next step involves generating External Account Binding (EAB) credentials. EAB credentials, consisting of a key identifier (KID) and an HMAC key pair, are essential for ACME clients to register an account with the ACM ACME server. These credentials act as a pre-authorization mechanism, ensuring that only authorized clients can establish an account. After successful registration using EAB, the client generates its own asymmetric key pair, which is subsequently used to authenticate all future certificate requests. PKI administrators can set an expiration time for EAB credentials, ideally limiting their validity to the period required for client registration, further enhancing security.
With the endpoint configured, domains validated, and EAB credentials generated, ACME clients can then be pointed to the new ACM ACME endpoint. AWS provides ready-to-use command examples for popular clients like Certbot and acme.sh, simplifying the integration process. Clients use their EAB credentials (KID and HMAC key) to register and then proceed with standard ACME challenge processes to obtain and renew certificates. Once issued, these certificates are immediately visible and manageable within the ACM console, alongside any certificates issued through traditional ACM console or API methods. This unified view significantly enhances operational clarity and control for PKI teams.

The implications of this launch are far-reaching. By bringing ACME support natively into AWS Certificate Manager, AWS is not only simplifying certificate management but also enhancing the overall security posture for its customers. The centralized controls, fine-grained access management through IAM, and comprehensive auditing via CloudTrail provide a robust framework for governance and compliance, particularly for regulated industries. Organizations can now implement consistent certificate policies across their entire AWS footprint, ensuring that all public TLS certificates adhere to established security standards and internal guidelines.
Furthermore, this integration fosters greater operational efficiency and cost savings. By automating a historically manual and error-prone process, IT teams can reduce the time spent on certificate renewals, freeing up valuable resources to focus on more strategic initiatives. The reduction in potential service outages due to expired certificates translates directly into improved business continuity and customer satisfaction. The ability to manage all public certificates within a single AWS service eliminates the need for separate external CA relationships or additional third-party CLM solutions, leading to potential cost reductions and simplified vendor management.

From a strategic perspective, this move solidifies ACM’s position as a comprehensive certificate management solution within the AWS ecosystem. It bridges the gap between traditional manual and API-driven certificate management and the increasingly prevalent ACME-based automation, catering to a broader range of customer needs and preferences. This allows AWS customers to leverage the benefits of ACME’s open standard while retaining the security, scalability, and integration benefits of AWS services.
ACME support in AWS Certificate Manager is now generally available in all commercial AWS Regions. AWS plans to extend availability to AWS GovCloud (US), the China Regions, and the AWS European Sovereign Cloud partitions at a later date, ensuring global reach and compliance for diverse customer segments. Pricing for ACME-issued certificates is structured per domain included in each certificate at the time of issuance, with distinct pricing for fully qualified domain names and wildcards. Volume tiers are applied based on the total number of domain occurrences across all certificates issued per month within an AWS account, offering scalable cost efficiency for high-volume users.

This new capability in AWS Certificate Manager represents a significant step forward in simplifying and securing the digital infrastructure for enterprises worldwide. By embracing and integrating the ACME protocol, AWS empowers organizations to meet the evolving demands of certificate lifecycle management with automation, centralized control, and enhanced security, ultimately contributing to a more resilient and trustworthy internet. Organizations are encouraged to visit the ACM section on the AWS console or consult the comprehensive documentation to explore this new feature and begin their journey towards fully automated public TLS certificate management.
