Salta al contenuto

Why does CloudFront show my old Amazon-issued SSL certificate after I renewed or reimported the certificate?

1 minuti di lettura
0

I renewed my Amazon-issued SSL certificate on AWS Certificate Manager (ACM), or I reimported my SSL certificate to ACM. However, Amazon CloudFront still shows the previous version of the certificate.

If your certificate renewal or reimport process didn't complete, then CloudFront might still use the previous certificate. CloudFront processes certificate renewals and reimports asynchronously, and it might take up to 24 hours to display those changes.

To avoid certificate expiration issues, renew or reimport your certificate at least 24 hours before the NotAfter value of your current certificate. If you're within 24 hours of the certificate expiration, then request a new certificate from ACM or import a new certificate to ACM. Then, associate the new certificate to the CloudFront distribution.

For more information, see Certificate expiration date and renewal.

Related information

Managed certificate renewal in AWS Certificate Manager

Reimport a certificate

Check a certificate's renewal status

Troubleshooting managed certificate renewal

2 commenti

Need more elaborate on term "several hours". If the max waiting time required is 24 hours before seeking help from AWS support, please address it in this doc. Thanks.

risposta 3 anni fa

Thank you for your comment. We'll review and update the Knowledge Center article as needed.

AWS
MODERATORE
risposta 3 anni fa