AWS证书续期失败:Route53 apex域添加CNAME报错,能否删除SOA记录?
Hey there, let’s walk through this issue step by step— I’ve seen this exact problem a bunch of times with AWS ACM and Route53. Here’s what’s going on and how to fix it:
Why You’re Seeing That Error
This boils down to a core DNS rule: you can’t use a CNAME record on an apex domain (like example.kr, the root of your DNS zone). CNAME records make one entire domain alias another, which would clash with the mandatory SOA and NS records that every apex domain must have to function. Route53 strictly enforces this DNS standard, hence the error message you’re getting.
Don’t Delete That SOA Record— Ever!
Your SOA (Start of Authority) record is the foundation of your DNS zone. It holds critical info like your primary DNS server, admin contact, and refresh timings for your domain. Delete it, and your entire example.kr domain will stop resolving— this is non-negotiable. Leave that SOA record right where it is.
The Correct Way to Validate Your ACM Certificate
It sounds like you might have mixed up which DNS record ACM needs for validation. Let’s fix that:
- Head back to the ACM console for ap-northeast-2, and pull up the validation details for your certificate. For the
example.krdomain, the required CNAME won’t be for the apex itself— it’ll be for a subdomain like_acme-challenge.example.kr. - In Route53, create a new CNAME record with:
- Name: Copy the exact subdomain from ACM (should start with
_acme-challenge.) - Type: CNAME
- Value: Paste the target domain ACM provides you
- Name: Copy the exact subdomain from ACM (should start with
- Your existing A record for
example.kr(pointing to your ELB) is totally fine— this validation record won’t interfere with it at all.
Quick Note on Apex Domain Validation
If your certificate includes the apex example.kr (which it probably does), that _acme-challenge.example.kr CNAME is exactly what ACM needs to confirm you own the domain. You don’t need to modify your apex A record at all for this renewal.
Once you set up that correct CNAME, ACM will detect it within a few minutes, and your certificate renewal will go through without a hitch.
内容的提问来源于stack exchange,提问作者eugene

