AWS Certificate Manager 2027 Expiration: Email-Validated Certificates Renewal Update
AWS Certificate Manager (ACM) will discontinue support for domain validation (DV) certificates by 2027, aligning with the CA/B Forum’s requirements.
Phased Transition Timeline
The AWS Certificate Manager (ACM) will gradually discontinue support for domain validation (DV) certificates, aligning with the Certification Authority/Browser (CA/B) Forum’s requirement to eliminate DV-based validation for publicly trusted certificates by March 15, 2028. This transition will impact certificate issuance and renewals, with specific deadlines outlined for AWS customers to migrate to alternative validation methods.
2027 Deadlines
ACM’s phased approach to ending DV support begins on January 1, 2027, when the method will no longer be available for new AWS Regions. By March 31, 2027, DV validation will be entirely removed from all AWS Regions for new certificate requests. Existing DV-validated certificates will cease to be renewable after September 30, 2027, necessitating immediate action by users to update their certificate configurations.
Migration Steps and Deadlines
AWS recommends migrating affected certificates to DNS validation before the September 30 deadline. Customers can identify DV-validated certificates through the AWS Management Console or AWS Command Line Interface (CLI). In the console, users can filter certificates by selecting “Validation method” as “DNS” and “Type” as “Amazon Issued.” The CLI also offers commands to list Amazon-issued certificates and display their validation methods, enabling users to pinpoint certificates requiring migration.
Updating Validation Methods
To streamline the transition, ACM is updating the UpdateCertificateOptions API to allow customers to switch a certificate’s validation method from DV to DNS without altering the certificate’s Amazon Resource Name (ARN). This ensures existing AWS resources referencing the certificate remain unaffected. Once the migration is initiated, ACM generates a CNAME record that must be added to the domain’s DNS configuration within 72 hours. During this period, the certificate continues to function normally. If the CNAME record is not added within the timeframe, the certificate remains active with DV validation, and the migration can be attempted again.
Tools for Identifying DV Certificates
Customers can identify DV-validated certificates through the AWS Management Console or AWS Command Line Interface (CLI). In the console, users can filter certificates by selecting “Validation method” as “DNS” and “Type” as “Amazon Issued.” The CLI also offers commands to list Amazon-issued certificates and display their validation methods, enabling users to pinpoint certificates requiring migration.
API Updates for Validation Method Changes
The UpdateCertificateOptions API now allows customers to switch a certificate’s validation method from DV to DNS without altering the certificate’s ARN. This ensures existing AWS resources referencing the certificate remain unaffected. Upon successful DNS validation, ACM automatically renews the certificate before its expiration, provided the required DNS records remain in place.
DNS and HTTP Validation Methods
Following the discontinuation of DV validation, ACM will support DNS validation for general certificate requests and HTTP validation for certificates associated with Amazon CloudFront. DNS validation is recommended for most use cases, while HTTP validation requires hosting a unique token at a predefined URL path on the domain. This method is exclusive to CloudFront certificates and eliminates the manual approval step required for DV validation, enabling automatic renewals.
Importance of Proactive Planning
The transition underscores the importance of proactive planning for AWS users to avoid service disruptions. By adhering to the outlined deadlines and leveraging available tools, organizations can ensure continued compliance with industry standards and maintain secure certificate management practices. ACM’s updates reflect broader industry efforts to enhance certificate validation processes, reducing reliance on automated but potentially less secure methods.
Conclusion
As the CA/B Forum’s deadline approaches, stakeholders must prioritize migration to ensure uninterrupted trust and functionality for their digital infrastructure. Organizations can perform this migration via the ACM console by selecting “Update validation method” and entering the CNAME records provided by AWS.
