AWS Certificate Manager adds ACME support as 45-day lifetimes loom
AWS Certificate Manager has added support for the ACME protocol, enabling automated management of 45-day TLS certificates. This update simplifies certificate lifecycle automation for Kubernetes and external workloads, helping streaming infrastructure teams prepare for stricter industry certificate lifetime requirements.
Key Takeaways
- AWS Certificate Manager (ACM) now provides a fully managed ACME endpoint for public TLS certificates from Amazon Trust Services.
- New certificates carry a 45-day validity period to align with the CA/Browser Forum’s move toward a 47-day maximum by 2029.
- The update supports any ACMEv2-compatible client, including cert-manager for Kubernetes, Certbot for servers, and acme.sh for lightweight setups.
- ACM certificates can now be deployed on non-AWS workloads, allowing for centralized management of both internal and external endpoints.
Why It Matters
The shift makes manual certificate management technically and operationally unsustainable for streaming platforms. By providing a standard ACME interface, AWS removes the friction of managing public and private certificates across fragmented infrastructure. This consolidation reduces the risk of service outages caused by expired certificates, which become approximately eight times more frequent under the new 45-day renewal cycle. For the broader ecosystem, it signals that automated certificate lifecycle management (CLM) is no longer an optimization but a requirement for maintaining trust in public-facing APIs and delivery nodes. Watch for whether other major cloud providers accelerate the sunsetting of manual renewal tools in favor of mandatory ACME automation.
Additional Context
The transition to shorter certificate lifespans follows the CA/Browser Forum's approval of Ballot SC-081v3 in April 2025. This measure, proposed by Apple and endorsed by Google, established a phased reduction of maximum TLS certificate validity from 398 days to 47 days. Per Sectigo and DigiCert, the first major milestone of this mandate began on March 15, 2026, which capped public certificate validity at 200 days and significantly reduced reuse periods for Domain Control Validation (DCV). By March 2027, the industry maximum will decrease further to 100 days before reaching the final 47-day target in 2029. This aggressive timeline represents a strategic push by browser vendors to minimize the window of exposure for compromised private keys and improve 'crypto-agility' ahead of the transition to post-quantum cryptography. According to reporting from Accutive Security in late 2024, organizations managing 1,000 certificates will see their annual renewal volume jump from roughly 900 to over 7,700 once the 47-day limit is fully implemented. The parallel reduction of the DCV reuse window to just 10 days by 2029 means that domain ownership must also be re-verified almost weekly, further necessitating the standardized automation provided by ACME-compliant services like the new ACM endpoint.
Read full article at cloudmagazin.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source