aws-amplify / aws-amplify/amplify-hosting

Notification or email to be sent when an SSL certificate expires for the Amplify Application's Custom domain.

Open
#3,635 1 comment 2 reactions 0 assignees View on GitHub
custom-domain feature-request notifications
Dominant language
Dockerfile
Stars
481
Forks
123
PR merge metrics
No merged PRs in 30d

Description

### Before opening, please confirm:

- [X] I have checked to see if my question is addressed in the [FAQ](https://github.com/aws-amplify/amplify-hosting/blob/master/FAQ.md).
- [X] I have [searched for duplicate or closed issues](https://github.com/aws-amplify/amplify-hosting/issues?q=is%3Aissue+).
- [X] I have read the guide for [submitting questions](https://github.com/aws-amplify/amplify-hosting/blob/master/CONTRIBUTING.md).
- [X] I have removed any sensitive information from my code snippets and submission.

### App Id

NA

### AWS Region

us-east-1

### Amplify Hosting feature

Not Applicable

### Is your feature request related to a problem? Please describe:

SSL certificate expiry notififcation

### Describe how you'd like this feature to work

Hello Team,

When the Certificate Verification DNS Record for the application's custom domain had been deleted or modified during time of renewal , the SSL certificate expires.

In the browser, we see the message like: " 'Certificate for .application.com' is expired"

ACM actually tries 60 days before expiry and notifies 15 days prior as per https://docs.aws.amazon.com/acm/latest/userguide/troubleshooting-renewal.html#troubleshooting-automatic-renewal but since this is Amplify-managed, users do not receive this information.

However, no notification or email is sent which notifies the user(account owner) that the SSL cert for the amplify custom domain is expiring/ or has expired.

Expected outcome: If the Certificate Verification DNS Record is deleted/modified, a notification is sent to the Account owner that this can cause issues. Also, an email/notification to be sent when the certificate expires.

Cheers

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the renewal behavior described in the issue and the linked ACM troubleshooting documentation, then check FAQ.md for existing guidance. Done means defining and implementing notification behavior for deleted or modified verification records and for certificates approaching or reaching expiration.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.