← All stories
● Covered by 1 source · 2 reportsMedium impact2 neutral

AWS Certificate Manager Adds ACME Support, Deprecates Email Validation by September 2027

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • ACM now supports ACME protocol for automated certificate management.
  • ACME support allows use of clients like Certbot, cert-manager, acme.sh, win-acme.
  • Email validation for public certificates will be deprecated by September 30, 2027.
  • Users must migrate to DNS validation before the deprecation date.
  • CA/B Forum mandates reduced certificate validity and deprecates email validation.

Automated Certificate Management with ACME

AWS Certificate Manager (ACM) has introduced support for the Automated Certificate Management Environment (ACME) protocol. This integration allows customers to automate the issuance and renewal of public certificates using existing ACME clients such as Certbot, cert-manager, acme.sh, and win-acme. This update is designed to help manage the increasing operational demands of TLS certificates.

The Certification Authority Browser Forum (CA/Browser Forum) has mandated a phased reduction in the maximum validity period for public certificates. By March 2027, the maximum validity will be 100 days, further decreasing to 47 days by March 2029. For organizations managing a large number of certificates, this change necessitates frequent renewal events that manual processes cannot sustain at scale.

Deprecation of Email Validation

In a separate but related development, AWS Certificate Manager will discontinue support for email-validated public certificates by September 30, 2027. This change aligns with an industry-wide deprecation of email-based domain validation by the CA/B Forum, which takes effect on March 15, 2028.

Users currently relying on email validation for their ACM public certificates are required to migrate to DNS validation before the September 2027 deadline. After the CA/B Forum's March 2028 date, certificates validated through email will no longer be trusted by browsers, regardless of the issuing certificate authority.

Industry Standards and Migration

The CA/B Forum establishes the standards that certificate authorities and browsers must follow for publicly trusted certificates. Their decision in November 2025 to end support for email-based domain validation reflects a move towards more secure and automated validation methods.

ACM's deprecation timeline provides customers with a full year to transition their certificates to DNS validation ahead of the broader industry deadline. This ensures continued compliance and trust for their public certificates.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027, requiring users to migrate to DNS validation. This change aligns with the CA/B Forum's industry-wide deprecation of email-based domain validation, which takes effect in March 2028. The deprecation impacts all ACM users currently relying on email validation for their public certificates.

AWS Certificate Manager (ACM) now supports the Automated Certificate Management Environment (ACME) protocol, allowing customers to automate public certificate issuance and renewal using existing ACME clients. This update addresses the increasing operational burden of managing TLS certificates due to reduced validity periods mandated by the CA/Browser Forum, extending ACM's automation capabilities to customer-managed infrastructure.