Description
A bare * is not a valid ACM certificate DomainName. Wildcards such as *.example.com are supported, but cover only one subdomain level and do not include example.com itself.
Potential impact
Invalid names cause certificate requests to fail. Unnecessarily broad valid wildcards can also increase certificate-sharing and replacement scope.
Remediation
Specify the required exact domain or approved wildcard scope. Match the DNS-validation domain and hosted zone to the certificate request.
Examples
The examples replace an invalid * with the DomainName input. api.example.com is illustrative; supply a domain you control and its public Route 53 HostedZoneId.
Before
yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
DomainName:
Description: "Domain for the certificate request"
Type: String
Default: api.example.com
HostedZoneId:
Description: "Public hosted zone ID for the DNS validation record"
Type: String
Resources:
Certificate:
Type: AWS::CertificateManager::Certificate
Properties:
DomainName: "*"
DomainValidationOptions:
- DomainName: !Ref DomainName
HostedZoneId: !Ref HostedZoneId
ValidationMethod: DNS
After
yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
DomainName:
Description: "Domain for the certificate request"
Type: String
Default: api.example.com
HostedZoneId:
Description: "Public hosted zone ID for the DNS validation record"
Type: String
Resources:
Certificate:
Type: AWS::CertificateManager::Certificate
Properties:
DomainName: !Ref DomainName
DomainValidationOptions:
- DomainName: !Ref DomainName
HostedZoneId: !Ref HostedZoneId
ValidationMethod: DNS