AgentCore Gateway supports private TLS certificates for VPC endpoints

Amazon Bedrock AgentCore Gateway Updates
Amazon Bedrock AgentCore Gateway now supports TLS certificates signed by private certificate authorities (CAs) on MCP, OpenAPI, and HTTP proxy targets. This feature allows secure connections to gateway targets using TLS certificates issued by your own private certificate authority, enabling native connections to private endpoints in your VPC without needing an intermediate Application Load Balancer.
You can register a private CA certificate with gateway targets using private endpoints powered by Amazon VPC Lattice. The gateway fetches your PEM-encoded CA certificate from Amazon S3 or AWS Secrets Manager and uses it as the trust anchor for outbound TLS connections. This support is available for MCP server targets, OpenAPI targets, and HTTP proxy (passthrough) targets.
Private CA support on AgentCore Gateway is available in all Regions where both AgentCore Gateway and Amazon VPC Lattice are available. For more information, see the AgentCore Developer Guide.
What to do
- Register your private CA certificate with your gateway targets.
- Configure your gateway to fetch the CA certificate from Amazon S3 or AWS Secrets Manager.
- Update your connection settings to use the new private CA certificates.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



