AWS Certificate Manager (ACM) has introduced support for the Automated Certificate Management Environment (ACME) protocol. This integration allows customers to automate the issuance and renewal of public certificates using existing ACME clients such as Certbot, cert-manager, acme.sh, and win-acme. This update is designed to help manage the increasing operational demands of TLS certificates.
The Certification Authority Browser Forum (CA/Browser Forum) has mandated a phased reduction in the maximum validity period for public certificates. By March 2027, the maximum validity will be 100 days, further decreasing to 47 days by March 2029. For organizations managing a large number of certificates, this change necessitates frequent renewal events that manual processes cannot sustain at scale.
In a separate but related development, AWS Certificate Manager will discontinue support for email-validated public certificates by September 30, 2027. This change aligns with an industry-wide deprecation of email-based domain validation by the CA/B Forum, which takes effect on March 15, 2028.
Users currently relying on email validation for their ACM public certificates are required to migrate to DNS validation before the September 2027 deadline. After the CA/B Forum's March 2028 date, certificates validated through email will no longer be trusted by browsers, regardless of the issuing certificate authority.
The CA/B Forum establishes the standards that certificate authorities and browsers must follow for publicly trusted certificates. Their decision in November 2025 to end support for email-based domain validation reflects a move towards more secure and automated validation methods.
ACM's deprecation timeline provides customers with a full year to transition their certificates to DNS validation ahead of the broader industry deadline. This ensures continued compliance and trust for their public certificates.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027, requiring users to migrate to DNS validation. This change aligns with the CA/B Forum's industry-wide deprecation of email-based domain validation, which takes effect in March 2028. The deprecation impacts all ACM users currently relying on email validation for their public certificates.
AWS Certificate Manager (ACM) now supports the Automated Certificate Management Environment (ACME) protocol, allowing customers to automate public certificate issuance and renewal using existing ACME clients. This update addresses the increasing operational burden of managing TLS certificates due to reduced validity periods mandated by the CA/Browser Forum, extending ACM's automation capabilities to customer-managed infrastructure.