1. https://appdevelopermagazine.com/cloud-services
  2. https://appdevelopermagazine.com/aws-certificate-manager/
7/22/2025 9:50:28 AM
AWS Certificate Manager
AWS Certificate Manager,Exportable Public Certificates,Hybrid Cloud Security,TLS Deployment
/AWS-Certificate-Manager-App-Developer-Magazine_si5umm2m.jpg
App Developer Magazine
AWS Certificate Manager

Cloud Services

AWS Certificate Manager


Tuesday, July 22, 2025

Richard Harris Richard Harris

Organizations can now simplify certificate management and improve security because, with the AWS Certificate Manager, they can seamlessly deploy exportable public certificates across AWS, hybrid, or on-premises workloads without complex contracts or manual renewals.

Amazon Web Services (AWS) recently announced the launch of exportable public certificates through AWS Certificate Manager (ACM), empowering customers to secure any workload, inside or outside of AWS, with ease. This new capability allows organizations to issue public Transport Layer Security (TLS) certificates and access the associated private keys, enabling secure TLS termination across a broad range of environments, including Amazon EC2 instances, containers, and on-premises hosts.

Previously, ACM-issued public certificates were restricted to integrated AWS services such as Amazon CloudFront. With the new exportable option, customers can now mark certificates for use beyond AWS-integrated services during the request process. Once domain validation is complete, certificates can be procured within seconds, providing fast, secure, and affordable access to public certificates for AWS, hybrid, or multicloud workloads.

AWS Certificate Manager introduces exportable public certificates for use across any workload

Exportable public certificates from ACM are valid for 395 days and are priced at $15 per fully qualified domain name (FQDN) and $149 per wildcard name. Customers benefit from simple, one-time pricing with no bulk issuance contracts required. Additionally, administrators can monitor and automate certificate usage through ACM’s lifecycle CloudWatch events.

AWS places security at the forefront of all services. To maintain high standards, export functionality is limited to newly issued certificates; existing public certificates remain non-exportable. Administrators can enforce granular permissions through IAM policies, specifying which roles and users are authorized to request exportable certificates.

The new feature is now available in all AWS regions, including AWS GovCloud (US) and China Regions.

Key benefits of ACM exportable public certificates:

  • Centralized Management: Simplify certificate management across all environments through ACM.
  • Fast Issuance: Obtain certificates rapidly after domain validation.
  • Automated Renewals: Benefit from automatic renewals, with notifications provided via Amazon EventBridge.
  • Cost-Effective Pricing: Pay only for certificates created, with no ongoing contracts.
  • Flexible Deployment: Deploy certificates on any server or application supporting standard SSL/TLS.
     

How it works:

  1. Request an exportable certificate through ACM for the chosen domain.
  2. Validate domain ownership via DNS or email.
  3. Export the certificate, private key, and certificate chain.
  4. Deploy to the desired server or application.
  5. Allow ACM to manage renewals and receive automated notifications when renewed certificates are ready.
     

Security best practices:

AWS advises customers to implement secure storage and access controls for exported private keys, use ACM’s revocation features if compromise is suspected, and follow key rotation procedures when deploying renewed certificates. The exportable certificate feature is available across all supported AWS regions. Additional charges apply for exportable public SSL/TLS certificates.






Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


Spotify and UMG strike landmark AI music licensing deal
Spotify and UMG strike landmark AI music licensing deal Thursday, May 28, 2026


Anthropic investigation opened after Mythos accessed by Discord group
Anthropic investigation opened after Mythos accessed by Discord group Wednesday, May 27, 2026


AI layoffS: What is really behind it all
AI layoffS: What is really behind it all Tuesday, May 26, 2026




The identity system is failing under AI
The identity system is failing under AI Monday, May 25, 2026


The Real World Launches Expert-Verified AI Certification Framework
The Real World Launches Expert-Verified AI Certification Framework Friday, May 22, 2026


Multiple language options when developing apps with Evoke
Multiple language options when developing apps with Evoke Thursday, May 21, 2026


When Social Listening Becomes Social Surveillance
When Social Listening Becomes Social Surveillance Wednesday, May 20, 2026


Medical debt relief custom-built platform moopFi launches
Medical debt relief custom-built platform moopFi launches Tuesday, May 19, 2026


Quant Pros Say AI Is Widening the Skills Gap
Quant Pros Say AI Is Widening the Skills Gap Monday, May 18, 2026


Tether QVAC SDK Powers AI Across Devices and Platforms
Tether QVAC SDK Powers AI Across Devices and Platforms Wednesday, April 22, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>