Certificate for DNS name of Global Accelerator in Application Load Balance

0

Hey,

Is it possible to request a certificate from AWS Certificate Manager (ACM) for the DNS name of a Global Accelerator?

I have created a HostedZone with the DNS name (e.g., XXXXXXXXXXXXXXXXX.awsglobalaccelerator.com), and the respective CNAME record that ACM requires:

CNAME name:

YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY.XXXXXXXXXXXXXXXXX.awsglobalaccelerator.com.

that has a value

YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY.XXXXXXXXXX.acm-validations.aws.

Using the Route53 tester, reveals that everything is fine with the record, at least. However, even after more than an hour, the Certificate is still pending validation.

My goal is to use Application Load Balancer (ALB) with an HTTPS listener as a target for the Global Accelerator, but also would like to use Static IPs to enable access from clients, which are behind a firewall.

Thanks!

2개 답변
0

Hello.
The domain "awsglobalaccelerator.com" is a domain managed by AWS, so an SSL certificate cannot be issued.
You will need to issue a certificate for the domain you manage.

profile picture
전문가
답변함 9달 전
profile picture
전문가
Steve_M
검토됨 9달 전
profile picture
전문가
검토됨 9달 전
0

Global Accelerator does not perform SSL termination and you cannot install HTTPS cert on it. You SSL cert is to be installed on the ALB.

For the domain you manage, either create a DNS A record that resolves to AGA IP, or a DNS CNAME to AGA FQDN. If you do not have a domain, you can purchase one from Amazon Route 53, and use it to request free SSL cert for your ALB.

AWS
전문가
Mike_L
답변함 9달 전
profile picture
전문가
Steve_M
검토됨 9달 전
profile picture
전문가
검토됨 9달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인