[obsolete] CNAME records already present, but ACM still marks the certificate as "Pending validation"

0

We have a certificate generating warnings about its validation status (three common names, three CNAME records required for validation).

The problem is those exact CNAME records were existing all this time (I have re-created the same records, using shorter TTL, but ACM still generates same warning).

How can I handle this without deleting the certificate (which will render related services unusable) and re-creating it anew?

Update of December 25. I had to replace the certificate instead of wasting more time on attempts to understand why ACM fails to conclude the validation (all the CNAME records were valid and in place for weeks, yet ACM refused to conclude the validation).

Honestly, I am very disappointed. ACM could provide the exact problem, so I could look into it, instead of giving vague pieces of advice (of the type "something is wrong").

已提問 2 年前檢視次數 545 次
1 個回答
0

Could be the third case from

https://aws.amazon.com/premiumsupport/knowledge-center/acm-certificate-pending-validation/

"The CNAME record is added to the correct DNS configuration, but the DNS provider automatically adds the bare domain to the end of its DNS records"

profile picture
JaccoPK
已回答 2 年前
  • Thanks for the prompt response.

    The above is unlikely. I have tested every created CNAME record with a command like

    $ dig _4490328cbd8989384cf7fcf77df2f2f2a02.example.com CNAME

    (the CNAME record above is changed to exclude the actual domain name)

    and the response was exactly matching what ACM expects in domain details.

  • Some DNS providers can take 24–48 hours to propagate DNS records. Did you also check for trailing period added by DNS provider?

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南