AWS Certificate Manager now supports ACME issuance through AWS PrivateLink

AWS Certificate Manager (ACM) Updates
ACM now supports AWS PrivateLink for ACME public certificate issuance, enabling you to request and renew public TLS certificates over a private network path within the AWS network.
To set up, create a VPC interface endpoint to the ACM ACME service and route issuance traffic from any ACMEv2-compatible client through your VPC. No changes are required to your ACME clients if you're already using ACME with ACM.
After creating your managed ACME endpoint in ACM, create a standard VPC interface endpoint using the VPC console, AWS CLI, or AWS CloudFormation. Private DNS resolves your existing ACME directory URL to the interface endpoint inside your VPC automatically, so the same client configuration and directory URL continue to work without reconfiguration.
Issuance operations—account creation, order creation, domain validation, finalization, and certificate retrieval—then flow over PrivateLink. All activity remains visible in the ACM console with AWS CloudTrail logging and Amazon CloudWatch metrics for auditability.
What to do
- Create a VPC interface endpoint to the ACM ACME service.
- Route issuance traffic from any ACMEv2-compatible client through your VPC.
- No changes required to existing ACME clients.
AWS PrivateLink support for ACME certificate issuance is available in all commercial AWS Regions. Standard AWS PrivateLink charges apply for interface endpoints; see the AWS PrivateLink pricing page. For ACM pricing details, see the ACM pricing page. To get started with ACME and PrivateLink, visit the AWS News blog post or read the documentation.
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



