← Integrations

AWS Certificate Manager ACME, deployed beyond AWS

Validate your domain once in AWS. Never touch DNS for a renewal again.

AWS Certificate Manager now issues public certificates over ACME, to any client, for use anywhere. You validate each domain once on your ACM ACME endpoint, including its subdomains and wildcards if you choose, and every certificate after that is issued without a challenge. No token to publish, no DNS change at renewal.

That solves validation. It doesn't get a certificate onto the EC2 instances, on-premises servers, and appliances that present it, and with 45-day certificates that work repeats about twelve times a year. CertKit registers against your ACM endpoint once, renews every certificate centrally, and the CertKit Agent installs each renewal and confirms it's being served.

Start free trial Watch demo

Validation lives in AWS, not on your servers

Most ACME CAs make your client prove control of every name, every time, by publishing a fresh DNS token or serving a file. ACM moves that proof out of the protocol. You add the CNAME record ACM gives you for each domain, and ACM keeps the domain validated for as long as that record stays in place. Orders from your endpoint arrive already authorized.

It's the model DNS-PERSIST-01 promises for everyone, available today. We wrote about why the standard is taking so long. For CertKit it means one less moving part. There's no delegated CNAME to CertKit and no DNS credentials anywhere. CertKit asks for the certificate, and AWS issues it.

You buy the certificates from AWS

CertKit doesn't resell ACM certificates or add a fee to them. AWS bills your account directly, per domain name, every time a certificate is issued or renewed. Today that's $1 per name and $5 per wildcard, with lower rates above 1,000 names a month.

ACME certificates from ACM last 45 days, so a name renewed on schedule is charged about twelve times a year. A certificate with three names costs three times as much as one with a single name. Plan your SANs with that in mind.

What ACM's ACME endpoint still leaves on your plate

The do-it-yourself version, once your domains are validated:

  1. Register a client on every host. Each ACME client needs its own external account binding from the endpoint, and each host you rebuild later needs another.
  2. Install and maintain a client per host. The usual rollout, version drift, and per-machine configuration, now on a 45-day clock.
  3. Ship the full chain, every time. A hook that writes only the leaf, or that hardcodes an intermediate from an older certificate, works in a desktop browser and fails for API clients and mobile apps.
  4. Write the post-deploy hooks. Convert, place, reference, reload, once per platform, run only at renewal.
  5. Cover the appliances. Load balancers and gateways outside AWS import certificates through an API. No ACME client does that.
  6. Add monitoring and an audit record. Proof that the new certificate is being served, and a log of which certificate went where. Neither is part of an ACME client's job.

ACM took the hardest part of ACME off your plate. What's left is the part where a certificate has to land on a specific machine and take effect, and shorter lifetimes turn that into a permanent workload.

How it works

      AWS                  CertKit              Your systems
┌──────────────┐   ┌─────────────────┐   ┌──────────────────┐
│ ACM ACME     │   │  register once  │   │                  │
│ endpoint ◄───────── with EAB key   │   │  ┌─────────────┐ │
│              │   │  + HMAC         │   │  │CertKit Agent│ │
│ domains      │   │                 │   │  └──────┬──────┘ │
│ validated    │   │  no challenge,  │   │         │        │
│ once ────────────►│  no DNS change │   │         ▼        │
│              │   │       │         │   │  EC2      [x]    │
│              │   │       ▼         │   │  nginx    [x]    │
│              │   │  Deploy ───────────►│  F5       [x]    │
└──────────────┘   └─────────────────┘   └──────────────────┘
  validate in the     renews every          deployed and
  AWS console         45 days               verified

After registration the ACME account persists, and the domain validation stays in AWS. CertKit never needs your DNS or your AWS credentials to renew.

CertKit has transformed how Belden manages SSL certificate issuance, delivering a streamlined process that dramatically reduced both cost and complexity. Their solution has been a clear win for our organization.

Ryan Buckner, IT Infrastructure Analyst, Belden

What CertKit handles

Setup takes about ten minutes

  1. Create an ACME endpoint and validate your domains in ACM. In the ACM console, open ACME › Endpoints, create an endpoint, and add a domain validation for each domain. Choose whether it covers subdomains and wildcards, then add the CNAME record ACM gives you.
  2. Create an external account binding. On the endpoint's External account bindings tab, create a binding. Copy the Key ID, the MAC key, and the endpoint's directory URL.
  3. Add AWS Certificate Manager as an issuer in CertKit. The Key ID is the EAB Key ID and the MAC key is the EAB HMAC. Paste the directory URL, add a name and contact address, and the issuer is live once it registers.
  4. Put the agent on each target. One install command per system, then choose that platform's deployment template. Use an ECDSA P-256, ECDSA P-384, or RSA 2048 key, the types the endpoint accepts.

See the issuer documentation →

Why not use ACM's built-in certificates?

If everything you secure sits behind an AWS load balancer, CloudFront, or API Gateway, ACM's integrated certificates are the simplest choice. AWS renews them and attaches them for you, and the private key never leaves AWS.

That stops at the edge of those services. An EC2 instance terminating its own TLS, a server in your data center, a firewall, or a workload in another cloud needs the certificate and its key on the machine. The ACME endpoint exists for exactly those cases, and it hands the deployment problem back to you.

CertKit is the piece that closes it. AWS validates and issues, CertKit renews and deploys, and the integration is configuration rather than scripts you have to maintain.

AWS is one issuer among several

CertKit issues from AWS Certificate Manager alongside DigiCert, Sectigo, Google Trust Services, and Let's Encrypt, and from a private CA for internal hostnames, IP address certificates, and mTLS client certificates that no public CA will sign. Monitoring covers every certificate regardless of which authority signed it.

See all integrations

Start automating AWS Certificate Manager certificates today

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing