2026-08-15 · aws-security
AWS has announced that Certificate Manager will discontinue support for email-validated public certificates by September 30, 2027, ahead of the broader browser-industry deadline. The change pushes teams toward DNS-based validation and forces a review of how certificate ownership, renewal records, and domain control are documented. That may sound like a routine PKI update, but certificate transitions are exactly the kind of operational change that exposes weak backup habits. If domain, DNS, and recovery records live only in active systems, a bad migration or account compromise can lock teams out of trusted recovery paths.
AWS said customers using email validation for ACM public certificates need to migrate to DNS validation before support ends. The move aligns with the CA/B Forum's industry-wide deprecation of email-based domain validation for publicly trusted certificates.
When certificate inventories, DNS ownership records, and escalation contacts are incomplete or lost, outages can stretch from minutes into days. Losing the authoritative trail for PKI assets can also delay incident recovery, break encrypted services, and create expensive manual reissuance work across production environments.
Cold storage helps by preserving offline copies of certificate inventories, DNS validation procedures, registrar recovery details, and emergency runbooks that are independent of live control planes. If an account is compromised or a migration goes sideways, teams can rebuild trust chains from clean offline records instead of guessing under pressure.
Read Original Post →