Glossary

    AWS Certificate Manager

    Data Protection

    AWS Certificate Manager (ACM) handles the complexity of creating, storing, and renewing SSL/TLS certificates. Public certificates are free and auto-renew.

    Certificate Types

    • Public Certificates: free, domain-validated (DV) certificates trusted by browsers; validated via DNS or email
    • Private Certificates: issued by ACM Private CA for internal services; costs apply
    • Imported Certificates: third-party certificates you manage yourself (no auto-renewal)

    Supported Services

    • Elastic Load Balancer (ALB, NLB, CLB)
    • CloudFront distributions
    • API Gateway custom domains
    • App Runner custom domains

    Security Best Practices

    • Use DNS validation for automated certificate issuance and renewal
    • Enable Certificate Transparency logging to detect unauthorized certificates
    • Use ACM Private CA for internal service-to-service mTLS
    • Monitor certificate expiration with Config Rules (acm-certificate-expiration-check)

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.