Skip to main content

Configure sslTrus CaaS for AWS ACM

Prerequisites

Before you start configuration, make sure you have completed the following preparations:

  1. Purchase the sslTrus CaaS service: Complete the CaaS subscription purchase first. For detailed purchase instructions, refer to sslTrus CaaS Purchase Guide.
  2. Apply for an SSL certificate: Make sure you have successfully requested and had the certificate issued. For the detailed request process, refer to sslTrus CaaS Certificate Request.

Configure Installation Point — Certificate Update (AWS ACM)

Configure the AWS ACM Management Interface

Prerequisite

Prepare the AK/SK of the AWS account used to manage ACM in advance.

  1. Go to the console backend > Asset Management > Vendor Management, select Amazon Web Services, and click Manage.

Vendor Management

  1. Click Add Account.

Add Account

  1. Enter the account name and the AccessKey and SecretKey of the AWS ACM management account, then click Save.

Enter AK/SK

Permission Description

The AK/SK for AWS ACM must have the following permissions enabled:

  • GetCertificate
  • ImportCertificate
  • ListCertificates
  1. Go to Asset Management and click Add Asset.

Add Asset

  1. Enter the asset name, select Amazon ACM, select the account you just created, enter the Region ID (obtained from AWS), and click Confirm to save.

Asset Configuration

Configure CaaS

  1. Go to Console > sslTrus CaaS Service, select the corresponding service, and click Details to enter the CaaS management backend.

CaaS List

  1. Switch to the Installation Point tab, click Add Installation Node, enter the node name, select Amazon ACM for Service Type, select the asset created in the previous step for Asset Name, enter the Certificate ARN (obtained from AWS), and click Confirm to save.

安装节点

  1. After configuration, you can manage the node. Click Scan Now to start monitoring the node.

立即扫描

  1. After a new certificate is issued, click Push Certificate, and the system will push the new certificate to AWS ACM. You can see the certificate is updated to the latest version in backend monitoring.

推送证书