Concepts
Public and private certificates both ride X.509, but they differ on one axis: who already trusts the issuer. That single difference drives key location, cost, and how clients behave.
Trust models
| Model | Issuer | Client behaviour |
|---|---|---|
| Public ACM | Amazon public CA | Trusted out of the box |
| Private CA | Your CA | Trust only after CA PEM is in the system store |
| Imported | Third-party CA | Trusted if that CA is already public, or if you distributed it |
Private CA does not mean “no trust.” It means you operate trust.
Where the private key lives
| Certificate type | Typical private key location |
|---|---|
| ACM public (classic) | Inside ACM; ALB/CloudFront uses it |
| Private CA leaf (default) | ACM private certificate attached to an internal ALB |
Private CA leaf (nginx_export) |
Issued into Secrets Manager, applied by State Manager on nginx |
| CA trust anchor on clients | Public CA certificate only — never the CA private key |
Exportability
- Public ACM (classic) → bound to integrated services (ALB, CloudFront, API Gateway); the key stays in ACM. This lab’s public path uses this model.
- Public ACM (exportable) → ACM can also issue an exportable public certificate whose encrypted private key you retrieve for use anywhere. Not used here — the ALB path needs no PEM on the instance.
- Private CA → default path (
alb_acm) keeps the leaf in ACM on an internal ALB (HTTP backend only). Optionalnginx_exportputs leaf + key onprivate-webvia Secrets Manager and State Manager.
Cost shape
| Item | Shape |
|---|---|
| ACM public (integrated) | $0 — FQDN or wildcard |
| Private CA | Monthly CA (pro-rated) + per issued certificate |
| ALB / EC2 | Hourly while running |
ACM public adds no charge beyond the AWS resources that use the certificate. Private CA is charged monthly from creation until deletion, plus a fee per issued certificate. Details: Cost.
Destroy the Private CA in the walkthrough teardown (stage 3 creates it; destroy stages 4 → 3 → 2 → 1).
DNS validation vs private issuance
- Public ACM needs proof of domain control
(this lab uses Route 53 DNS validation for
demo.johna.kiwi). The same CNAME that validates the domain also lets ACM renew the certificate automatically. Validation CNAMEs must live in a publicly hosted zone — a private hosted zone alone is not enough. - For a public ACM cert on a name that should not resolve on the internet, use split-horizon DNS: validation CNAME in the public zone; app A/alias only in the private zone. Diagram and comparison: Architecture — split-horizon (not built in this lab).
- Private CA issuance needs no public validation — you already own the CA.
DNS still matters so clients can resolve
app.internal.johna.kiwito the server.
Next: Architecture.