AWS Certificate Manager (ACM)
AWS Certificate Manager (ACM) provisions and manages SSL/TLS certificates for AWS services. Public certificates issued by ACM are free and are renewed automatically, which removes the manual work and the outages caused by expired certificates.
Key concepts #
- Integrated services: a certificate can be used with Elastic Load Balancing, CloudFront, API Gateway, AppSync and others. Public certificates cannot be exported to install them on an EC2 instance.
- Validation: ACM checks that you own the domain by a DNS record (recommended, it also allows automatic renewal) or by e-mail. With Route 53, the DNS record can be created automatically.
- Wildcard certificates (
*.example.com) and several names per certificate are supported. - A certificate belongs to a Region. Certificates used with CloudFront must be requested in us-east-1.
- ACM Private CA is a separate, paid service to issue private certificates for internal use.
Pricing #
Public certificates are free. AWS Private CA has a monthly charge per CA and per certificate.
With Terraform #
The resources are aws_acm_certificate, aws_route53_record (for the validation records) and aws_acm_certificate_validation, which waits until the certificate is issued.
See tutorials:
- AWS with Terraform: The Essential Guide (16/21) – AWS Load Balancers: HTTPS with ACM and Route 53 validation