acm:UpdateCertificateOptions permission to be added to the Lambda execution role.
Ensure your CustomAcmCertificateLambdaExecutionRole is up to date with the example in cloudformation.[yaml|json].
Added
Missing certificate property compared to AWS::CertificateManager::Certificate:
CertificateTransparencyLoggingPreferencehas been added to control certificate transparency logging.
New enhancements over AWS::CertificateManager::Certificate:
- A new
KeyAlgorithmcertificate property has been added to specify the key algorithm to use.
The default isRSA_2048, which is the same asAWS::CertificateManager::Certificate. Not all algorithms are supported by all clients, AWS Services or regions.
Changed
-
A DomainValidationOption is no longer required for all domains in the certificate. If a DomainValidationOption is not specified for a domain, no validation record will be created for that domain.
The validation records will need to be created through some other means. The certificate resource will be in theCREATE_IN_PROGRESSstate until the validation records are created. -
The certificate resource will not necessarily be replaced on changes to the
DomainValidationOptionsproperty.
Only changes toDomainNameorHostedZoneIdinDomainValidationOptionswill cause the certificate to be replaced.
Fixed
- Failures that could occur when creating or updating large numbers of certificates in parallel.