AI Briefing
KO

AWS Certificate Manager Automates Public TLS Certificate Issuance with ACME Support

·2026.07.01 05:15

Key point

AWS Certificate Manager (ACM) now supports the ACME protocol, enabling automatic issuance and management of public TLS certificates.

1 / 2

Details

As certificate validity periods continue to shrink, manual renewal methods have reached their limits. In response, AWS Certificate Manager (ACM) has announced support for the ACME (Automatic Certificate Management Environment) protocol, providing an environment where users can request, renew, and revoke TLS certificates without manual intervention.

Previously, using the ACME protocol required separately managing an external certificate authority, but now integrated management is possible within ACM itself. This allows organizations to centrally monitor and control certificate usage across their entire organization.

Key Features and Benefits:

  • Centralized Control: IAM roles can be bound to ACME accounts, allowing fine-grained access permissions to be set per domain.
  • Enhanced Security: External Account Binding (EAB) allows separation of certificate issuance permissions from DNS management permissions, enabling automation without sharing DNS keys with application owners.
  • Integrated Monitoring: Provides audit logs via AWS CloudTrail, operational metrics via Amazon CloudWatch, and notifications when certificates are nearing expiration.
  • Universality: Existing ACMEv2-compatible clients such as Certbot, cert-manager for Kubernetes, and acme.sh can be used as-is.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.