AWS Certificate Manager | Private Key Protection Flashcards
How can I notify AWS if the information in the certificate changes?
Private Key Protection
AWS Certificate Manager | Security, Identity & Compliance
You notify AWS by sending email to validation-questions[at]amazon.com.
How are the private keys of ACM-provided certificates managed?
Private Key Protection
AWS Certificate Manager | Security, Identity & Compliance
A key pair is created for each certificate provided by ACM. AWS Certificate Manager is designed to protect and manage the private keys used with SSL/TLS certificates. Strong encryption and key management best practices are used when protecting and storing private keys.
Does ACM copy certificates across AWS Regions?
Private Key Protection
AWS Certificate Manager | Security, Identity & Compliance
No. The private key of each ACM certificate is stored in the Region in which you request the certificate. For example, when you obtain a new certificate in the US East (N. Virginia) Region, ACM stores the private key in the N. Virginia Region. ACM certificates are only copied across Regions if the certificate is associated with a CloudFront distribution. In that case, CloudFront distributes the ACM certificate to the geographic locations configured for your distribution.