Introduction
TLS certificates prove identity and encrypt traffic. On AWS you usually meet two managed pieces: AWS Certificate Manager (ACM) and AWS Private CA. Both issue X.509 certificates. They solve different problems.
AWS Certificate Manager (public certificates)
ACM issues publicly trusted certificates for names you prove you control (this lab: DNS validation).
- Attach them to ACM-integrated services: Application Load Balancer, CloudFront, API Gateway, and others.
- Browsers and OSes trust them by default.
- Non-exportable public certificates for those integrated services are $0 (ACM pricing).
- The private key stays in ACM. TLS terminates on the load balancer (or CloudFront), not on an EC2 nginx process.
- Managed renewal: for DNS-validated public certs, ACM renews when the cert is in use by an AWS service and the validation CNAMEs remain in public DNS (docs). Imported certificates are not renewed by ACM.
Use ACM public when the endpoint is on the public internet and clients should get a normal padlock with no CA install.
AWS Private CA
Private CA is a managed private certificate authority. You create a CA and issue certificates for internal hostnames and services.
- Certificates are not in public trust stores. Clients trust them only after you install the CA (this lab: Linux + SSM).
- Prefer ACM private certificates on ALB (or other ACM-integrated services) when you can — this lab’s default private path.
- You can also put leaves on servers that are not ACM-integrated (nginx, custom
apps) — this lab’s optional
nginx_exportmode. - You pay a monthly CA fee (pro-rated) plus per issued certificate when the key is accessible (Private CA pricing). ACM private certs used only on integrated services typically have no issuance charge.
Use Private CA for intranet names, custom PKI policy, or certs on hosts ACM cannot terminate for.
How they work together
- Public website / API → ACM public on ALB or CloudFront.
- Internal apps → Private CA leaves, CA distributed to managed Linux fleets.
- Third-party public cert → import into ACM for ALB/CloudFront (no ACM managed renewal).
Same domain family (johna.kiwi) can appear in both paths. The difference is
who trusts the issuer.
What this lab proves
| Path | Name | Trust |
|---|---|---|
| Public | demo.johna.kiwi |
Default browser / OS trust |
| Private | app.internal.johna.kiwi |
Only after CA install on the client |
| Managed Linux client | SSM installs CA from S3 | curl succeeds without --cacert |
| Unmanaged Linux client | No CA install | curl fails (untrusted issuer) |
Next: Concepts.