Invalid ACM certificate domain name

Specify a valid domain and the required certificate scope.

Description

A bare * is not a valid ACM certificate DomainName. Wildcards such as *.example.com are supported, but cover only one subdomain level and do not include example.com itself.

Potential impact

Invalid names cause certificate requests to fail. Unnecessarily broad valid wildcards can also increase certificate-sharing and replacement scope.

Remediation

Specify the required exact domain or approved wildcard scope. Match the DNS-validation domain and hosted zone to the certificate request.

Examples

The examples replace an invalid * with the DomainName input. api.example.com is illustrative; supply a domain you control and its public Route 53 HostedZoneId.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  DomainName:
    Description: "Domain for the certificate request"
    Type: String
    Default: api.example.com
  HostedZoneId:
    Description: "Public hosted zone ID for the DNS validation record"
    Type: String

Resources:
  Certificate:
    Type: AWS::CertificateManager::Certificate
    Properties:
      DomainName: "*"
      DomainValidationOptions:
        - DomainName: !Ref DomainName
          HostedZoneId: !Ref HostedZoneId
      ValidationMethod: DNS

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  DomainName:
    Description: "Domain for the certificate request"
    Type: String
    Default: api.example.com
  HostedZoneId:
    Description: "Public hosted zone ID for the DNS validation record"
    Type: String

Resources:
  Certificate:
    Type: AWS::CertificateManager::Certificate
    Properties:
      DomainName: !Ref DomainName
      DomainValidationOptions:
        - DomainName: !Ref DomainName
          HostedZoneId: !Ref HostedZoneId
      ValidationMethod: DNS

References