AWS Certificate Manager now supports Elliptic Curve Digital Signature Algorithm TLS certificates
Share
Services
You can now use [AWS Certificate Manager](/certificate-manager/) (ACM) to request and use Elliptic Curve Digital Signature Algorithm (ECDSA) P-256 and P-384 Transport Layer Security (TLS) certificates to secure your network traffic. TLS certificates are used to secure network communications and to establish the identity of websites over the internet as well as resources on private networks. ACM lets you easily provision, manage, and deploy public and private TLS certificates. You can learn more about ECDSA security, performance and compatibility in this [AWS Security blog post](https://aws.amazon.com/blogs/security/how-to-evaluate-and-use-ecdsa-certificates-in-aws-certificate-manager/).
You can use either the ACM console or the request-certificate API with the key-algorithm parameter to issue public / private ECDSA P-256 and P-384 TLS certificates. AWS customers who need to use TLS certificates with 120+ bit security strength can now use these ECDSA certificates to help meet their compliance needs. ECDSA certificates have a higher security strength of 128 and 192 bits respectively, when compared to 112 bit RSA 2048 certificates that you can also issue from ACM. Security strength is a measure of resilience against brute force attacks. ACM issued ECDSA public certificates can be used with supported [integrated services](https://docs.aws.amazon.com/acm/latest/userguide/acm-services.html) such as Application Load Balancer (ALB) and Amazon CloudFront. When used with integrated services you also get the benefit of [managed renewals](https://docs.aws.amazon.com/acm/latest/userguide/managed-renewal.html) i.e., ACM will attempt to renew ACM issued, in-use certificates before expiry and automatically bind the renewed certificates with an integrated service.
ECDSA certificates are available in all regions where ACM is available. CloudFormation support will be coming soon. To learn more about this feature, please refer to the [documentation](https://docs.aws.amazon.com/acm/latest/userguide/acm-certificate.html#algorithms). You can learn more about ACM and get started [here](/certificate-manager/getting-started/).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share