Business
Jobs
  • About Us
  • Solutions
    • Job Postings
      Post your job and receive qualified candidates in 48h.
    • Candidate Assessments
      500+ technical and psychological tests, plus anti-fraud.
    • Headhunting
      Tailor-made executive search from start to finish.
    • Payroll + EOR
      Payroll dispersal and EOR across 15+ LATAM countries.
  • Pricing
  • Jobs

0

328
Views
CloudFormation AWS::CertificateManager::Certificate automated certificate validation

According the AWS docs at here and here I should be able to automate a certificate creation and validation using cloudformation. Apparently when you specify a HostedZoneId in the DomainValidationOptions, it is supposed to create the required DNS record to complete the validation (at least that is what it seems from the very vague documentation). My CF template for the cert looks like this:

Resources:
  MyAPICert:
    Type: AWS::CertificateManager::Certificate
    Properties:
      DomainName: xxxx.dev.mydomain.io
      DomainValidationOptions:
        - DomainName: mydomain.io
          HostedZoneId: /hostedzone/Z03XXXXXXXXXXXX
      ValidationMethod: DNS

'mydomain.io' (changed of course) was registered using AWS as registrar as the documents say must be the case for automated validation to work.

This template above is included in a serverless.yml as a resource. However, when I deploy, the stack creation is just stuck waiting for the DNS record - i.e. it does not add the required CNAME entry as I understand it is supposed to do and as such the stack is stuck.

Has anyone gotten this feature to work?

And, yes, I know about the 3rd party custom resources that try to do the same thing, I don't want to use them if CF is supposed to do this natively now.

over 4 years ago · Santiago Trujillo
3 answers
Answer question

0

I hit the same issue. You need to specify the full domain name including the host in the DomainValidationOptions DomainName parameter, and just specify the hosted zone id:

Resources:
  MyAPICert:
    Type: AWS::CertificateManager::Certificate
    Properties:
      DomainName: xxxx.dev.mydomain.io
      DomainValidationOptions:
       - DomainName: xxxx.dev.mydomain.io
         HostedZoneId: Z03XXXXXXXXXXXX
      ValidationMethod: DNS

In my testing, the Route53 validation record was added about a minute after running the stack, and the domain successfully validated itslef after about 15 minutes.

over 4 years ago · Santiago Trujillo Report

0

If this is stuck as in progress for a long time, it could be that you are using a Private Hosted Zone when you need to use the Public one. Probably you don't use a private CA. That process should take 2-3 minutes, not more than that.

over 4 years ago · Santiago Trujillo Report

0

I just deployed the below template to CloudFormation and it successfully created the validation DNS records and authorised the certificate.

If you were to pass the parameters SiteDnsZoneName=mydomain.io. and SiteDnsZoneId=ABCDEFGHIJKLMNOPQRSTU it would create a SAN cert that covers both mydomain.io and *.mydomain.io

{
    "Description": "Deploy wildcard SAN cert inc bare domain. (Must deploy cert to us-east-1 for CloudFront)",
    "Parameters": {
        "SiteDnsZoneName": {
            "Type": "String",
            "MinLength": 4,
            "Description": "DNS Zone",
            "Default": "example.com"
        },
        "SiteDnsZoneId": {
            "Type": "String",
            "MinLength": 8,
            "Description": "DNS Zone Id",
            "Default": "ABCDEFGHIJKLMNOPQRSTU"
        }
    },
    "Resources": {
        "SiteCertificate": {
            "Type": "AWS::CertificateManager::Certificate",
            "Properties": {
                "DomainName": {
                    "Fn::Join": [
                        ".",
                        [
                            "*",
                            {
                                "Ref": "SiteDnsZoneName"
                            }
                        ]
                    ]
                },
                "SubjectAlternativeNames": [
                    {
                        "Ref": "SiteDnsZoneName"
                    }
                ],
                "DomainValidationOptions": [
                    {
                        "DomainName": {
                            "Ref": "SiteDnsZoneName"
                        },
                        "HostedZoneId": {
                            "Ref": "SiteDnsZoneId"
                        }
                    }
                ],
                "ValidationMethod": "DNS"
            }
        }
    }
}

Note: If you want to use a cert in CloudFront you have to deploy the cert in us-east-1.

Note 2: Route53 needs to be hosting your DNS Zone, but theres no requirement on AWS being the registrar. Your domain can be registered with any provider, so long as you use the AWS name servers provided by Route53 when you add the zone.

over 4 years ago · Santiago Trujillo Report
Answer question
Find remote jobs

Discover the new way to find a job!

Top jobs
Top job categories
Business
Post vacancy Pricing Sales
Legal
Terms and conditions Privacy policy
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Show me some job opportunities
There's an error!