Concepts

AWS Certificate Manager AWS Private Certificate Authority

Public and private certificates both ride X.509, but they differ on one axis: who already trusts the issuer. That single difference drives key location, cost, and how clients behave.

Trust models

Model Issuer Client behaviour
Public ACM Amazon public CA Trusted out of the box
Private CA Your CA Trust only after CA PEM is in the system store
Imported Third-party CA Trusted if that CA is already public, or if you distributed it

Private CA does not mean “no trust.” It means you operate trust.

Where the private key lives

Certificate type Typical private key location
ACM public (classic) Inside ACM; ALB/CloudFront uses it
Private CA leaf (default) ACM private certificate attached to an internal ALB
Private CA leaf (nginx_export) Issued into Secrets Manager, applied by State Manager on nginx
CA trust anchor on clients Public CA certificate only — never the CA private key

Exportability

  • Public ACM (classic) → bound to integrated services (ALB, CloudFront, API Gateway); the key stays in ACM. This lab’s public path uses this model.
  • Public ACM (exportable) → ACM can also issue an exportable public certificate whose encrypted private key you retrieve for use anywhere. Not used here — the ALB path needs no PEM on the instance.
  • Private CA → default path (alb_acm) keeps the leaf in ACM on an internal ALB (HTTP backend only). Optional nginx_export puts leaf + key on private-web via Secrets Manager and State Manager.

Cost shape

Item Shape
ACM public (integrated) $0 — FQDN or wildcard
Private CA Monthly CA (pro-rated) + per issued certificate
ALB / EC2 Hourly while running

ACM public adds no charge beyond the AWS resources that use the certificate. Private CA is charged monthly from creation until deletion, plus a fee per issued certificate. Details: Cost.

Destroy the Private CA in the walkthrough teardown (stage 3 creates it; destroy stages 4 → 3 → 2 → 1).

DNS validation vs private issuance

  • Public ACM needs proof of domain control (this lab uses Route 53 DNS validation for demo.johna.kiwi). The same CNAME that validates the domain also lets ACM renew the certificate automatically. Validation CNAMEs must live in a publicly hosted zone — a private hosted zone alone is not enough.
  • For a public ACM cert on a name that should not resolve on the internet, use split-horizon DNS: validation CNAME in the public zone; app A/alias only in the private zone. Diagram and comparison: Architecture — split-horizon (not built in this lab).
  • Private CA issuance needs no public validation — you already own the CA. DNS still matters so clients can resolve app.internal.johna.kiwi to the server.

Next: Architecture.


Back to top

Lab repository. Tear down the Private CA when finished — it bills monthly.

ACM + Private CA lab docs