Usage guide
Complementary, not rivals. Pick by who must trust the issuer.
Pick a path
Internet endpoint. Trusted by browsers and OSes with zero client setup. Attach to ALB, CloudFront, or API Gateway.
Internal name, your PKI. Only clients you install the CA on will trust it. Certs can live on nginx/EC2.
Public ACM on a name that resolves only inside the VPC. Amazon trust, no fleet CA. Documented, not in the lab.
Decision table
| Situation | Reach for |
|---|---|
| Public website or API; no client setup | ACM public on ALB / CloudFront / API Gateway |
| Internal name; only managed clients trust | Private CA + CA distribution |
| Internal name on an ALB (ACM-integrated) | Private CA → ACM private cert (alb_acm) |
| Internal name, but clients trust Amazon’s CA | Public ACM + split-horizon |
| Cert on nginx / EC2 / appliance | Private CA export / IssueCertificate (nginx_export) |
| You bought a cert elsewhere | Import into ACM for ALB / CloudFront |
| Unmanaged BYOD on the internet | ACM public |
| mTLS between internal services | Private CA |
Do and don’t
DNS-validate ACM public and keep it in use so managed renewal runs. Validation CNAMEs in the public zone only. Cert in the ALB's Region. Treat CA install as fleet config (SSM), not a one-off. Keep leaf keys in Secrets Manager. Rotate CAs with an overlap window; rotate leaves on their own schedule.
No Private CA for a public site — Chrome won't trust it. No classic ACM public key on EC2. No hand-installing the CA host by host. Don't call private TLS "working" off curl --cacert. Don't leave a Private CA ACTIVE after a demo. Never ship a CA or leaf private key to clients.
The fastest way to a bad day: Private CA on a public marketing site, a CA private key shipped to clients, or ACM validation CNAMEs hidden in a private-only zone.
Split-horizon DNS (optional)
Public ACM on a name that resolves only inside the VPC/VPN, with clients trusting TLS without your CA.
| Public zone | Private zone |
|---|---|
| ACM DNS validation CNAMEs | Alias → internal ALB / service |
Standard Route 53 split-view. Prefer Private CA when you own the issuer and only managed clients should trust. Not applied here — diagram: Architecture — split-horizon.