Lesson 175 · AWS Learning Path

AWS 175: AWS Certificate Manager and CloudHSM

· Published · 9 min read

Labelled process diagram for AWS 175: Certificate or key requirement to ACM validation or HSM cluster to TLS or cryptographic consumer to Renewal, audit, and availability evidence, with decision, proof and rejection...

Why this lesson matters

Separate managed public or private certificate lifecycle from dedicated single-tenant hardware security modules and PKI key-control requirements.

What you will be able to do

By the end, you can:

  • explain aws certificate manager and cloudhsm in plain language;
  • locate the current service controls in the AWS Management Console;
  • run the matching CloudShell or AWS CLI queries and explain every important field;
  • draw the identity, network, data, failure, and monitoring path;
  • choose the service from requirements and reject it when those requirements are absent;
  • diagnose a failed or misleading result from evidence;
  • state the cost owner and prove cleanup or a no-create result.

Before you start

  • Use a personal AWS account only when its owner has approved the lesson. Do not use the root user for daily work.
  • CloudShell is the default command environment. AWS028 explains CloudShell; AWS029 and AWS030 explain local AWS CLI installation and profiles.
  • The course example Region is ap-south-1. Global services and services with a required control Region are called out in their commands.
  • Run aws sts get-caller-identity privately. Redact the account number before sharing evidence.
  • Never paste access keys, passwords, secret values, private object data, presigned URLs, or full account-specific ARNs into a submission.
  • This is a no-create lesson. Every Console action and AWS CLI command is read-only. Create the practical artifact locally.
  • Console wording can change. Use the Console service search if a menu label has moved, then confirm the current field in the official documentation.

The core model

QuestionWhat it means in this lesson
PurposeSeparate managed public or private certificate lifecycle from dedicated single-tenant hardware security modules and PKI key-control requirements.
Scope and boundaryThe learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS Certificate Manager and CloudHSM.
Evidence of successSuccess means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS Certificate Manager and CloudHSM.
Cost modelCloudHSM is a significant hourly service. ACM public certificates used with integrated AWS services and Private CA have different pricing; use evidence only.
Safe rejection ruleAvoid exporting keys when integration does not require it or building CloudHSM in a personal training account.

How the request flows

+----------------------------------+
|  Certificate or key requirement  |
+----------------------------------+
                 |
                 v
+---------------------------------+
|  ACM validation or HSM cluster  |
+---------------------------------+
                |
                v
+---------------------------------+
|  TLS or cryptographic consumer  |
+---------------------------------+
                |
                v
+---------------------------------------------+
|  Renewal, audit, and availability evidence  |
+---------------------------------------------+

Separate certificates, keys and hardware control

TLS authenticates an endpoint and protects data in transit. A certificate binds identities such as DNS names to a public key and issuer signature. The private key proves possession; it must not be copied into lessons, logs, repositories or shared evidence. TLS termination location determines where plaintext starts, which security group receives traffic, which certificates renew there, and whether a second TLS connection protects the backend hop.

RequirementAppropriate direction
Public certificate on ALB, NLB TLS listener, CloudFront or API GatewayACM public certificate in the Region/scope required by that service
Private identities for internal services/devicesAWS Private CA plus ACM-issued private certificates, with CA lifecycle and cost ownership
Certificate needed on EC2, Kubernetes or on-premises softwareACM exportable public certificate or another managed PKI path; protect and redeploy exported private keys
General encryption keys for AWS servicesAWS KMS, not CloudHSM
Single-tenant HSM control, PKCS#11/JCE/CNG integration or regulatory key custodyMulti-AZ CloudHSM cluster with customer-operated users, backup and client availability
KMS API plus key material in customer-controlled HSMsKMS custom key store backed by CloudHSM, accepting combined service dependencies

ACM lifecycle, scope and renewal

Public ACM issuance requires domain control validation. DNS validation is preferred for automation: ACM supplies CNAME records that must remain present and publicly resolvable. Email validation depends on human action and can break renewal. A certificate in ISSUED state is not proof that clients use it - inspect the ALB listener, CloudFront distribution, API custom domain or other association and test the served chain/SNI name.

Regional services generally need the certificate in their Region. CloudFront viewer certificates are managed in us-east-1. Certificates and their ARNs are regional; they do not automatically replicate. Subject alternative names must cover every hostname, and *.example.com covers one label such as api.example.com, not example.com or v1.api.example.com.

ACM-managed renewal requires continued eligibility, validation and use with a supported integrated service. Monitor renewal status and EventBridge/health notifications before expiry. Current ACM also offers exportable public certificates for customer-managed infrastructure. Exportability is an issuance property; public certificates created before the documented feature cutoff cannot be exported. Exported certificates add a charge and make you responsible for securely deploying every renewed certificate and private key. Never place an export passphrase directly in shell history.

Imported certificates do not receive the same ACM-managed renewal: obtain, validate and re-import replacements before expiry. A replacement ARN or changed chain may require service updates. Test full trust chain, hostname, SNI and TLS policy from an independent client.

CloudHSM operating model

A CloudHSM cluster spans HSMs in multiple Availability Zones. The customer initializes the cluster, manages crypto users and application credentials, installs/configures clients, creates keys, controls quorum operations and maintains enough HSMs for availability and throughput. AWS operates the hardware and service plane but cannot recover forgotten crypto-user credentials. Backups are encrypted and cluster deletion/restore procedures must be tested.

One HSM is a failure and maintenance risk; production clusters normally require multiple AZs. Applications need network routes, security groups, DNS, client configuration and retry/failover behavior to healthy HSMs. CloudHSM charges per HSM-hour, so an abandoned cluster is not a small lab artifact. A KMS custom key store additionally depends on KMS connectivity to the cluster and can become disconnected; KMS operations then fail even though application IAM policy looks correct.

TLS troubleshooting path

Follow the connection in order: DNS answer → network reachability → listener and SNI selection → certificate dates/SAN/issuer/chain → client trust → negotiated protocol/cipher → backend TLS, if used. Browser success alone is weak evidence because caches and trust stores differ.

host="replace.example.com"
openssl s_client -connect "${host}:443" -servername "$host" -showcerts </dev/null 2>/dev/null \
  | openssl x509 -noout -subject -issuer -serial -dates -ext subjectAltName
curl --fail --show-error --verbose "https://${host}/health" -o /dev/null

Do not use curl -k as acceptance evidence; it disables certificate verification and can hide the defect being tested.

Architecture decision table

SituationDirectionReason
Requirement matchesUse ACM for supported managed certificate integrations and CloudHSM only when dedicated HSM control is a real requirement.Select only after scope, behavior, security, recovery, operations, and price evidence agree.
Requirement does not matchAvoid exporting keys when integration does not require it or building CloudHSM in a personal training account.Rejecting an attractive service is a valid architecture result.
No create permission or cost approvalUse supplied evidence and local design workLearning does not depend on creating an hourly resource.
Existing resource is unknown or unownedInspect only, then stopNever change or delete a resource merely because it resembles a course example.

AWS Management Console, step by step

Sign in with the normal non-root learning identity. Write the expected starting state before opening the service.

  1. Use the Console service search and open Certificate Manager, Certificates and CloudHSM, Clusters; confirm the account and Region before reading the page.
  2. Inspect the supplied or owned resource's status, configuration, permissions, networking, encryption, monitoring, tags, and dependencies without changing it.
  3. Open the related metrics, logs, events, or history view and record one timestamped signal that would prove or disprove the expected behavior.
  4. Return to the resource list, clear filters, and record the final inventory. On the read-only track, do not choose Create, Save, or Delete.

CloudShell and AWS CLI, step by step

Start with a known caller and Region:

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list

Redact the account part of the ARN in shared evidence. Now run the topic queries:

aws acm list-certificates --query 'CertificateSummaryList[].{Domain:DomainName,Status:Status,Type:Type,InUse:InUse}' --output table
aws cloudhsmv2 describe-clusters --query 'Clusters[].{Id:ClusterId,State:State,HSMs:Hsms[].HsmId,Vpc:VpcId}' --output json

Expected interpretation

ACM certificate status and attachment must be read in the resource's required Region. A CloudHSM cluster also needs initialized users, client connectivity, quorum, backup, and application integration.

Practical work

Choose certificate and key custody for an ALB website, CloudFront domain, internal mTLS service, code-signing key, and regulatory single-tenant HSM requirement. Define renewal and outage ownership.

Diagnose this topic from its own evidence

  • PENDING_VALIDATION: inspect exact DNS CNAME name/value, authoritative public DNS, CAA policy and Region/account.
  • ISSUED but wrong certificate served: inspect listener certificate list, SNI hostname, default certificate, distribution deployment and DNS target.
  • Renewal pending: prove the validation record remains, certificate is eligible/in use, and ownership contacts/alerts are active.
  • CloudHSM client disconnected: check HSM state in each AZ, routes, SG rules, client configuration, crypto-user authentication and time/DNS before recreating anything.
  • KMS custom key store unavailable: inspect custom-key-store connection state and CloudHSM cluster health; IAM changes do not repair a disconnected store.

Cost and cleanup

CloudHSM is a significant hourly service. ACM public certificates used with integrated AWS services and Private CA have different pricing; use evidence only.

Knowledge check

  1. What operational purpose is this lesson solving?

Expected direction: Separate managed public or private certificate lifecycle from dedicated single-tenant hardware security modules and PKI key-control requirements.

  1. Which scope or ownership boundary must be proved first?

Expected direction: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS Certificate Manager and CloudHSM.

  1. What evidence is strong enough to accept the result?

Expected direction: Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS Certificate Manager and CloudHSM.

  1. Which tempting design or shortcut must be rejected?

Expected direction: Avoid exporting keys when integration does not require it or building CloudHSM in a personal training account.

  1. Which cost dimensions and retained resources need an owner?

Expected direction: CloudHSM is a significant hourly service. ACM public certificates used with integrated AWS services and Private CA have different pricing; use evidence only.

Lesson acceptance

  • Explain certificate, public key, private key, trust chain, SAN, SNI and TLS termination in plain language.
  • Select ACM public, exportable public, imported, Private CA, KMS or CloudHSM from requirements.
  • State regional certificate placement, including CloudFront's us-east-1 requirement.
  • Prove the certificate actually served to a client and reject curl -k as success evidence.
  • Design renewal monitoring and CloudHSM multi-AZ/client/credential/backup operations with explicit cost ownership.

Official sources

Advertisement