AWS Certificate Manager supports switching from e-mail to DNS validation
Share
Services
AWS Certificate Manager (ACM) now enables you to change the domain validation method on your existing ACM issued public TLS certificates from e-mail to DNS, without reissuing the certificate or changing its existing Amazon Resource Name (ARN). Due to the [Certification Authority/Browser (CA/B) Forum's](https://cabforum.org/) mandated deprecation of email-based domain validation for publicly trusted certificates, effective March 15, 2028, ACM will phase out its support for email validation throughout 2027\. ACM will no longer issue email-validated certificates starting March 31 2027, and stop renewing email-validated certificates on September 30 2027\. More details on ACM's deprecation of email validation can be found on the [AWS Security Blog](https://aws.amazon.com/blogs/security/aws-certificate-manager-will-discontinue-email-validation-to-prove-domain-validation-for-certificates). By switching to DNS validation now, you can transition ahead of that deadline and enable fully automated renewals through DNS validated certificates. Your certificate ARN remains unchanged after switching from e-mail to DNS validation, so existing ARN references in your CI/CD pipelines, load balancer configurations, and other AWS service integrations continue to work without modification. To switch the validation method, use the ACM console or the [UpdateCertificateOptions](https://docs.aws.amazon.com/acm/latest/APIReference/API%5FUpdateCertificateOptions.html) API. ACM provides a CNAME record for each domain in the certificate (the same mechanism used when provisioning new certificates with DNS validation) and you have up to 72 hours to add the records to your DNS configuration. You can monitor the validation status of each domain via the console or the [ListCertificateDomainValidations](https://docs.aws.amazon.com/acm/latest/APIReference/API%5FListCertificateDomainValidations.html) API. We recommend DNS validation for new certificates, and [HTTP validation](https://docs.aws.amazon.com/acm/latest/userguide/http-validation.html) for Amazon CloudFront distributions.. This feature is available in all AWS Regions where ACM certificates are available. To get started, refer to [Migrating from email to DNS validation](https://docs.aws.amazon.com/acm/latest/userguide/email-to-dns-migration.html) in the _AWS Certificate Manager User Guide._
What else is happening at Amazon Web Services?
AWS Billing and Cost Management introduces Managed Dashboards
about 16 hours ago
Services
Share
Amazon Redshift adds rg.large and rg.12xlarge instance sizes in AWS GovCloud (US) Regions
about 22 hours ago
Services
Share
Read update
Services
Share