关于ACM续期SSL证书及CloudFront证书交付机制的技术问询
Hey John, great questions—let’s break this down clearly for you:
ACM Renewed Certificates & CloudFront/ELB Integration
- Yes, ACM automatically syncs renewed certificates to associated CloudFront distributions and Elastic Load Balancers (ALB/NLB).
When your ACM certificate is already linked to a CloudFront distribution (note: CloudFront only uses certificates stored in theus-east-1AWS region) or an ELB, ACM handles the entire renewal and sync process for you. As long as your certificate meets renewal criteria (like valid domain validation records), once it’s renewed successfully, the updated certificate is automatically propagated to the linked service. You don’t need to manually download, upload, or reconfigure anything—ACM and the AWS service handle the integration natively.
CloudFront’s Certificate Delivery Behavior
- New requests get the renewed certificate immediately; existing sessions keep the old one until expiration
CloudFront doesn’t "push" updated certificates to active TLS sessions. When a client initiates a new TLS handshake (either a first-time request or a request where the existing session has timed out), CloudFront will use the renewed certificate. Already established TLS sessions will continue using the old certificate until the session expires (CloudFront’s default TLS session timeout is around 24 hours).
You also don’t need to invalidate your CloudFront cache or restart the distribution—once the renewed certificate is synced from ACM, new incoming requests will automatically use the updated certificate without any manual intervention.
内容的提问来源于stack exchange,提问作者John Smith
相关产品推荐
相关产品推荐

