AWS Certificate Manager
Certificate Manager
You need to issue and manage TLS certificates for supported services and endpoints.
Reach for it when
- Using managed certificates with a supported load balancer or CloudFront distribution.
- Tracking domain validation and certificate renewal for an HTTPS endpoint.
Do not reach for it when
- Creating DNS records alone: use the DNS provider as part of validation.
- Assuming a certificate can be attached to any server without checking export support.
Alternatives, and how to choose
| Service | Pick it instead when |
|---|---|
| AWS Private CA | Use private certificate authorities for appropriate internal trust requirements. |
| An external certificate authority | Use it when the endpoint or certificate workflow requires another issuer. |
How you pay
- The model
- Pricing depends on certificate type, exportability and associated private certificate authority services.
- The line item that surprises people
- Do not apply one certificate pricing assumption to every ACM offering.
What trips people up
- Validation requires control of the relevant domain or another supported validation method.
- Certificate placement is service-specific; CloudFront viewer certificates have a specific Region requirement.
Verify the live service
This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.