AWS Certificate renewal pending due to two removed domains from primary domain

25 Views Asked by At

I have a primary domain certificate *.helio.io with 4 domains issued by AWS and managed by DNS. Two of the domains are not in use any more and I have removed them from route 53 but the certificate is still in pending automatic DNS approval since two domains are not in use. Do I need to request new primary domain certificate for *.helio.io with two remaining domains or they can be deleted somehow?

1

There are 1 best solutions below

0
erik258 On

Every distinct domain in the certificate must be validated independently. So you'll have to request a new certificate with only the domains you want to support.

Alternately if you still control those domains, you can set up some DNS temporarily (doesn't have to be route 53) and create the CNAME approval records. But I don't see as how that would be easier or quicker than rotating the ACM cert out for one with only the correct domains listed.