Introduction

TLS certificates prove identity and encrypt traffic. On AWS you usually meet two managed pieces: AWS Certificate Manager (ACM) and AWS Private CA. Both issue X.509 certificates. They solve different problems.

AWS Certificate Manager (public certificates)

AWS Certificate Manager

ACM issues publicly trusted certificates for names you prove you control (this lab: DNS validation).

  • Attach them to ACM-integrated services: Application Load Balancer, CloudFront, API Gateway, and others.
  • Browsers and OSes trust them by default.
  • Non-exportable public certificates for those integrated services are $0 (ACM pricing).
  • The private key stays in ACM. TLS terminates on the load balancer (or CloudFront), not on an EC2 nginx process.
  • Managed renewal: for DNS-validated public certs, ACM renews when the cert is in use by an AWS service and the validation CNAMEs remain in public DNS (docs). Imported certificates are not renewed by ACM.

Use ACM public when the endpoint is on the public internet and clients should get a normal padlock with no CA install.

AWS Private CA

AWS Private Certificate Authority

Private CA is a managed private certificate authority. You create a CA and issue certificates for internal hostnames and services.

  • Certificates are not in public trust stores. Clients trust them only after you install the CA (this lab: Linux + SSM).
  • Prefer ACM private certificates on ALB (or other ACM-integrated services) when you can — this lab’s default private path.
  • You can also put leaves on servers that are not ACM-integrated (nginx, custom apps) — this lab’s optional nginx_export mode.
  • You pay a monthly CA fee (pro-rated) plus per issued certificate when the key is accessible (Private CA pricing). ACM private certs used only on integrated services typically have no issuance charge.

Use Private CA for intranet names, custom PKI policy, or certs on hosts ACM cannot terminate for.

How they work together

AWS Certificate Manager Application Load Balancer · AWS Private Certificate Authority Amazon EC2 running nginx · Amazon S3 bucket AWS Systems Manager State Manager
  1. Public website / API → ACM public on ALB or CloudFront.
  2. Internal apps → Private CA leaves, CA distributed to managed Linux fleets.
  3. Third-party public cert → import into ACM for ALB/CloudFront (no ACM managed renewal).

Same domain family (johna.kiwi) can appear in both paths. The difference is who trusts the issuer.

What this lab proves

Path Name Trust
Public demo.johna.kiwi Default browser / OS trust
Private app.internal.johna.kiwi Only after CA install on the client
Managed Linux client SSM installs CA from S3 curl succeeds without --cacert
Unmanaged Linux client No CA install curl fails (untrusted issuer)

Next: Concepts.


Back to top

Lab repository. Tear down the Private CA when finished — it bills monthly.

ACM + Private CA lab docs