You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

向Lightsail负载均衡器证书添加覆盖域名的相关疑问

Answers to Your Lightsail SSL Certificate Questions

1. Is your assumption correct?

Absolutely right. AWS Lightsail Load Balancers only support one SSL certificate at a time tied to the load balancer. Since you need to add a new subdomain (like amp.mydomain.com) alongside your existing ones (blog.mydomain.com, admin.mydomain.com, etc.), you can't just append the new subdomain to your existing certificate.

Instead, you'll need to:

  • Hold off on deleting the old certificate until your new one is fully validated (to avoid downtime)
  • Create a new SAN (Subject Alternative Name) certificate that includes all your existing subdomains plus the new AMP-specific subdomain
  • Once the new certificate is issued and validated, bind it to your Lightsail Load Balancer to replace the old one

Just make sure you list every single domain/subdomain you need to cover when creating the new certificate—miss one, and that subdomain will throw SSL errors once you switch over.

2. Will the new certificate's CNAME records match the old ones, and do you need to reconfigure DNS?

Nope, the CNAME records for certificate validation will not be the same as your old certificate. Every time you request a new SSL certificate through Lightsail (which uses Let's Encrypt under the hood), the ACME challenge generates unique CNAME values for each domain in the certificate.

Here's what you need to do:

  • When you create the new SAN certificate, Lightsail will provide a set of CNAME records (one for each domain/subdomain in the certificate)
  • Head to your DNS provider (whether it's Lightsail DNS or another service) and add these new CNAME records. You can delete or overwrite the old validation records from your previous certificate—they're no longer needed once the old certificate is replaced.
  • Wait for DNS propagation and Lightsail to validate the certificate (this usually takes a few minutes, but can stretch to an hour in rare cases)
  • Only once the new certificate shows as "Validated" should you bind it to your load balancer and remove the old certificate

This step is critical—skip updating the DNS records, and the new certificate won't be issued. You could end up with downtime if you've already removed the old one.

内容的提问来源于stack exchange,提问作者Lee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:54:49