Usage guide

AWS Certificate Manager AWS Private Certificate Authority

Complementary, not rivals. Pick by who must trust the issuer.

Pick a path

Public ACM public

Internet endpoint. Trusted by browsers and OSes with zero client setup. Attach to ALB, CloudFront, or API Gateway.

no CA install
Private Private CA

Internal name, your PKI. Only clients you install the CA on will trust it. Certs can live on nginx/EC2.

you operate trust
Hybrid Split-horizon

Public ACM on a name that resolves only inside the VPC. Amazon trust, no fleet CA. Documented, not in the lab.

optional

Decision table

Situation Reach for
Public website or API; no client setup ACM public on ALB / CloudFront / API Gateway
Internal name; only managed clients trust Private CA + CA distribution
Internal name on an ALB (ACM-integrated) Private CA → ACM private cert (alb_acm)
Internal name, but clients trust Amazon’s CA Public ACM + split-horizon
Cert on nginx / EC2 / appliance Private CA export / IssueCertificate (nginx_export)
You bought a cert elsewhere Import into ACM for ALB / CloudFront
Unmanaged BYOD on the internet ACM public
mTLS between internal services Private CA

Do and don’t

Do Separate the two trust paths

DNS-validate ACM public and keep it in use so managed renewal runs. Validation CNAMEs in the public zone only. Cert in the ALB's Region. Treat CA install as fleet config (SSM), not a one-off. Keep leaf keys in Secrets Manager. Rotate CAs with an overlap window; rotate leaves on their own schedule.

Don't Mix or hand-wire trust

No Private CA for a public site — Chrome won't trust it. No classic ACM public key on EC2. No hand-installing the CA host by host. Don't call private TLS "working" off curl --cacert. Don't leave a Private CA ACTIVE after a demo. Never ship a CA or leaf private key to clients.

The fastest way to a bad day: Private CA on a public marketing site, a CA private key shipped to clients, or ACM validation CNAMEs hidden in a private-only zone.

Split-horizon DNS (optional)

Public ACM on a name that resolves only inside the VPC/VPN, with clients trusting TLS without your CA.

Public zone Private zone
ACM DNS validation CNAMEs Alias → internal ALB / service

Standard Route 53 split-view. Prefer Private CA when you own the issuer and only managed clients should trust. Not applied here — diagram: Architecture — split-horizon.


Back to top

Lab repository. Tear down the Private CA when finished — it bills monthly.

ACM + Private CA lab docs