- Newest
- Most votes
- Most comments
Hi Igor,
The certificates issued by AWS Certificate Manager are provided by Certification Authorities (CAs) controlled by Amazon Trust Services (ATS). At the same time, a Subordinate CA of ATS is operated by DigiCert.
DigiCert comply U.S.-imposed sanctions, DigiCert is legally prohibited or restricted from offering its products and services to specific countries or regions.
Due to this restriction, your certificate with .RU
TLD always got a fail message. I suggest you can buy the certificates from other CAs that are not control by US government.
The list of restricted Russia and Belarus TLDs include:
.by
.moscow
.ru
.ru.com
.ru.net
.su
.tatar
.бел
.москва
.рус
.рф
Hi, I have faced this issue in the past. It usually indicates that AWS needs more information to verify your ownership or control of the domain. This step is crucial for the security and integrity of issuing SSL/TLS certificates. You can validate the ownership as follows:
- DNS Validation: ACM allows you to use DNS validation as a method to prove domain ownership. ACM will provide you with a CNAME record that you need to add to your domain's DNS configuration in Route 53. This method is preferred because it can automatically renew the certificate.
- Email Validation: Alternatively, ACM can send validation emails to the email addresses associated with the domain registrant, as well as the standard addresses (admin@, administrator@, webmaster@, hostmaster@, and postmaster@ your domain name). Ensure you have access to one of these email addresses.
https://docs.aws.amazon.com/acm/latest/userguide/dns-validation.html
Relevant content
- asked a year ago
- AWS OFFICIALUpdated 3 months ago
- AWS OFFICIALUpdated 7 days ago
- AWS OFFICIALUpdated 2 months ago
- AWS OFFICIALUpdated 2 years ago
I request using DNS validation. It doesn't provide me with any DNS challenge, it just fails right after I press "request" button
Please verify below: Domain Name - Double-check the domain name for typos and ensure you control its DNS settings. Service Limits - Verify you haven't exceeded AWS Certificate Manager's limits for certificate requests. IAM Permissions - Make sure your IAM user or role has the necessary permissions for requesting certificates and managing DNS settings. DNS Service Compatibility - If using a DNS provider outside AWS, ensure you can add the required CNAME record for DNS validation.