Automate certificates with ACME support in AWS Certificate Manager
Security Blog
AWS Certificate Manager now supports the ACME protocol, enabling automated certificate issuance and renewal using standard ACME clients across any infrastructure.
- Create ACME endpoints with pre-approved domains and IAM-based access controls for certificate automation
- Use existing ACME clients (certbot, cert-manager, acme.sh, win-acme) without reconfiguration
- Segment endpoints by organizational or environment boundaries for security isolation
- Manage EAB credentials securely with expiration policies and least-privilege IAM roles
- Centralized certificate visibility with CloudTrail audit logging and EventBridge alerting
- Supports shortened certificate validity periods mandated by CA/Browser Forum (100 days by March 2027)
ACME support in ACM enables organizations to automate certificate management at scale while maintaining governance controls and security boundaries across development, staging, and production environments.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2026
2026
2026
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.