A company is hosting a web application on EC2 instances behind an Application Load Balancer. The security team requires that all data in transit between the client and the ALB be encrypted using TLS. Which service should the architect use to manage the SSL/TLS certificates for the ALB?
Trap 1: AWS Secrets Manager
Secrets Manager is designed to manage database credentials, API keys, and other sensitive configuration strings. It does not provide the specialized infrastructure required to serve SSL/TLS certificates for public-facing load balancers. While you could store certificates here, it lacks the integration to automatically attach them to an ALB.
Trap 2: AWS Key Management Service (KMS)
KMS is primarily used for creating and controlling cryptographic keys used to encrypt data at rest within various AWS services. It is not intended for managing public SSL/TLS certificates used for identity verification and encryption in transit for web traffic, as it lacks public certificate authority trust.
Trap 3: IAM Server Certificate Upload
Uploading certificates to IAM is a legacy method used primarily for specific AWS services that do not support ACM integration. It requires manual tracking of certificate expiration dates and manual replacement, making it an operationally inefficient and insecure practice for modern ALB deployments when ACM is available.
- A
AWS Secrets Manager
Why it fails: Secrets Manager is designed to manage database credentials, API keys, and other sensitive configuration strings. It does not provide the specialized infrastructure required to serve SSL/TLS certificates for public-facing load balancers. While you could store certificates here, it lacks the integration to automatically attach them to an ALB.
- B
AWS Certificate Manager (ACM)
ACM provides a managed service to generate or import SSL/TLS certificates and associate them directly with an ALB. It handles the complexities of certificate lifecycle management, including automated renewals, ensuring that the web application maintains continuous, encrypted communication with clients without manual intervention or certificate expiration risks.
- C
AWS Key Management Service (KMS)
Why it fails: KMS is primarily used for creating and controlling cryptographic keys used to encrypt data at rest within various AWS services. It is not intended for managing public SSL/TLS certificates used for identity verification and encryption in transit for web traffic, as it lacks public certificate authority trust.
- D
IAM Server Certificate Upload
Why it fails: Uploading certificates to IAM is a legacy method used primarily for specific AWS services that do not support ACM integration. It requires manual tracking of certificate expiration dates and manual replacement, making it an operationally inefficient and insecure practice for modern ALB deployments when ACM is available.